Attachment 1 - PWS DC3 CTA_Follow-On.pdf

PDF 858 KB Posted

Attached to
DC3 Cyber Academy Training (CTA) Follow-On Federal contract opportunity
Solicitation number
FY25DC3CTA
Issued by
Department of the Air Force Headquarters District Washington

About this file

This Performance Work Statement (PWS) details requirements for the Defense Cyber Crime Center (DC3) Cyber Training Academy (CTA) contract, which aims to provide specialized cyber investigative training for Department of Defense (DoD) personnel across multiple organizations. The contract will support training for various cyber-related roles including cyber investigations, counterintelligence, defensive cyber operations, and cyber workforce development for entities such as US Cyber Command, Service Cyber Components, and federal law enforcement agencies.

Key contract specifications include a five-year performance period from July 2025 to July 2030, with a contractor-controlled facility located within 20 miles of Elkridge, Maryland. The contractor will be responsible for developing and delivering cyber training courses across multiple levels, managing a learning management system, supporting accreditation requirements, providing mobile training teams, and maintaining comprehensive training platforms. The training will cover disciplines including hardware analysis, incident response, digital forensics, network intrusions, dark web activities, and malware analysis, with courses designed to be hands-on, practical, and aligned with DoD cyber workforce frameworks. The contract emphasizes continuous curriculum adaptation to meet evolving cyber domain challenges and mission partner training needs.

View the file

Other files for this federal contract opportunity

Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

FOR

Defense Cyber Crime Center (DC3) Cyber Training Academy (CTA)

18 April 2025

Contents

1.0 DESCRIPTION OF SERVICES

1.0.1 OBJECTIVE

1.0.2 MISSION

1.0.3 BACKGROUND

1.0.4 SCOPE

1.0.5 CTA OVERVIEW

1.0.6 TASKS

1.1 TASK 1 – CTA OPERATIONS AND ADMINISTRATION

1.1.1 SUBTASK 1 – CONTRACT ADMINISTRATION and MANAGEMENT

1.1.2 SUBTASK 2 – ACADEMY CERTIFICATION and ACCREDITATION

SUPPORT

1.1.3 SUBTASK 3 – STUDENT SERVICE SUPPORT

1.1.4 SUBTASK 4 – GRAPHIC ARTS, MULTIMEDIA, AND DOCUMENT

PRINTING SERVICES SUPPORT

1.1.5 SUBTASK 5 – CTA WEBSITE DEVELOPMENT AND MAINTENANCE

1.2 TASK 2 – CYBER TRAINING COURSES AND CURRICULUM

1.2.1 SUBTASK 1 – CYBER TRAINING REQUIREMENTS GATHERING

1.2.2 SUBTASK 2 – DEVELOPMENT PROJECT PLANNING

1.2.3 SUBTASK 3 – COURSE DEVELOPMENT

1.2.4 SUBTASK 3 – TRAINING CONTENT TECHINCAL INTERGRATION

1.2.5 SUBTASK 4 – COURSE EVALUATION and MAINTENANCE

1.2.6 SUBTASK 5 – INFORMATIONAL and EDUCATIONAL RESOURCES

1.2.7 SUBTASK 6 – COURSE CATALOG

1.2.8 SUBTASK 7 – COURSE CALENDAR

1.3 TASK 3 – CYBER TRAINING ENVIRONMENT AND CAPABILITIES

1.3.1 SUBTASK 1 – CYBER TRAINING CLASSROOM

1.3.2 SUBTASK 2 – TECHNICAL TRAINING SOLUTION CAPABILITY

REQUIREMENTS

1.3.3 SUBTASK 3 – ONLINE TRAINING CAPABILITIES

1.3.4 SUBTASK 4 – STUDENT HELP DESK SUPPORT

1.3.5 SUBTASK 5 – CYBER TRAINING PLATFORM

1.3.6 SUBTASK 6 – PLANNING, IMPLEMENTATION, MIGRATION,

OPERATIONS AND MAINTENANCE

1.3.7 SUBTASK 7 – SECURITY

1.3.8 SUBTASK 8 – LIFE CYCLE MANAGEMENT

1.4 TASK 4 – CYBER TRAINING DELIVERY

1.4.1 SUBTASK 1 – CYBER TRAINING CLASSROOM

1.4.2 SUBTASK 1 – IN RESIDENCE TRAINING

1.4.3 SUBTASK 2 – INSTRUCTOR LED VIRTUAL TRAINING

1.4.4 SUBTASK 3 – ONLINE TRAINING

1.4.5 SUBTASK 5 – COURSE DELIVERY REPORTING

1.4.6 SUBTASK 6 – STUDENT SURVEYS

1.5 TASK 5 – MOBILE TRAINING TEAMS (MTTs)

1.6 TASK 6 – PROGRAM MANAGEMENT

1.6.1 SUBTASK 1 – PROGRAM OVERSIGHT

1.6.2 SUBTASK 2 – PROGRAM MANAGEMENT PLAN (PMP)

1.6.3 SUBTASK 3 – RISK MANAGEMENT

1.6.4 SUBTASK 4 – COMMUNICATION and MEETINGS

1.6.5 SUBTASK 5 – CONDUCT KICKOFF MEETING

1.6.6 SUBTASK 6 – MONTHLY STATUS REPORT (MSR)

1.6.7 SUBTASK 7 – OPERATIONAL/TECHNICAL STATUS MEETING

1.6.8 SUBTASK 8 – PROGRAM BASELINE REVIEW

1.6.9 SUBTASK 9 – ASSET MANAGEMENT SERVICES

1.6.10 SUBTASK 10 – GOVERNMENT REQUIRED TRAINING

1.6.11 SUBTASK 11 – KEY PERSONNEL

1.6.12 SUBTASK 12 – TRANSITION

1.7 TASK 7 – ADDITIONAL CYBER TRAINING CLASSROOM (OPTIONAL)

2.0 SERVICE AND DELIVERY SUMMARY

2.1 SERVICE SUMMARY

2.2 DELIVERABLES SUMMARY

2.3 DELIVERABLES MEDIA

2.4 PLACE(S) OF DELIVERY

2.5 BASIS OF ACCEPTANCE

2.4 DRAFT DELIVERABLES

2.5 WRITTEN ACCEPTANCE/REJECTION BY THE GOVERNMENT

2.6 MARKINGS

2.7 NON-CONFORMING PRODUCTS OR SERVICES

2.8 NOTICE REGARDING LATE DELIVERY/PROBLEM NOTIFICATION REPORT

(PNR) 57

3.0 GOVERNMENT-FURNISHED PROPERTY/EQUIPMENT (GFE/GFI)

4.0 GENERAL INFORMATION

4.1 PERIOD OF PERFORMANCE

4.2 PLACE OF PERFORMANCE

4.2.1 CONTRACTOR SITE(S)

4.3 PERFORMANCE SCHEDULE

4.3.1 RECOGNIZED HOLIDAYS

4.3.2 HOURS OF OPERATION

4.3.3 OVERTIME

4.3.4 INCLEMENT WEATHER

4.4 TRAVEL

4.4.1 TRAVEL

4.4.2 HARDWARE AND/OR SOFTWARE

4.5 SECURITY REQUIREMENTS

4.5.1 INFORMATION ASSURANCE

4.5.2 SECURITY CLEARANCES

4.5.3 INTERNATIONAL TRAFFIC IN ARMS REGULATIONS (ITAR)

4.5.4 CYBERSECURITY WORKFORCE MANAGEMENT PROGRAM

4.6 ORGANZIATIONAL CONFLICT OF INTEREST AND NON-DISCLOSURE

REQUIREMENTS

4.6.1 ORGANIZATIONAL CONFLICT OF INTEREST

4.6.2 NON-DISCLOSURE REQUIREMENTS

4.7 SECTION 508 COMPLIANCE REQUIREMENTS

4.8 CONTRACTOR IDENTIFICATION

4.9 CONTRACT CLOSEOUT

4.10 PRESS/NEWS RELEASE

4.11 QUALITY

4.12 EMERGENCY OPERATIONS/MISSION ESSENTIAL PERSONNEL

4.13 SYSTEM FOR AWARD MANAGEMENT (formerly CMRA)

4.14 MISCELLANEOUS PARAGRAPHS

1.0 DESCRIPTION OF SERVICES

1.0.1 OBJECTIVE

This performance work statement (PWS) establishes the requirements for contractor services in support of the DC3 Cyber Training Academy (CTA). This contract provides subject matter expertise (SME) and other essential capabilities to augment and support CTA’s mission in support of the Defense Criminal Investigative Organizations (DCIOs), Military Defense Counterintelligence Organizations (MDCOs), US Cyber Command (USCYBERCOM), Office of the DAF Chief Information Officer (SAF/CN), Service Cyber Components (SCCs), DoD CIO, OUSD I&S, DoD cyberspace workforce, federal law enforcement agencies and selected foreign partners.

The objectives of this PWS must be achieved within the constraints of the highly contested and rapidly evolving cyberspace domain.

1.0.2 MISSION

The mission of the DC3 Cyber Training Academy is to provide highly specialized cyber investigative training to all DoD personnel whose duties include ensuring “DoD and DIB information systems are secure from unauthorized use, criminal and fraudulent activities, and foreign intelligence service exploitation; and/or the exploitation of digital media for intelligence and CI objectives” (DoDI 5505.13e 2(c)). The course offerings (elucidated below) currently include disciplines that span hardware, incident response, digital forensics, drone forensics, network intrusions, dark-web activities, managed attribution, and malware analysis.

1.0.3 BACKGROUND

In recognition of the burgeoning use of digital devices as instrumentalities in/of crime; the DoD, via the 1998, Defense Reform Initiative Directive #23, established the Defense Cyber Crime Center (DC3) as the DoD center for digital / multimedia forensics and cyber training. In 2010, DoDI 5505.13e designated the Secretary of the Air Force as Executive Agency (EA) for DC3 and established the DC3 Cyber Training Academy (CTA) as the central focal point for cyber investigative training within the Department of Defense; charged with providing “specialized cyber investigations training for DoD and non-DoD personnel, as authorized”. On January 15, 2021, DC3 became a Field Operating Activity (FOA) directly subordinate to the United States Air Force Inspector General.

CTA is not an Air Force Specialty Code (AFSC) or Military Occupational Series (MOS) awarding activity. CTA is not affiliated with the Community College of the Air Force nor is it subordinate or accountable to the USAF Air Education and Training Command (AETC).

CTA is best understood within the context of continuing professional education and cyber career development for all DoD personnel whose duties include ensuring “DoD and DIB information systems are secure from unauthorized use, criminal and fraudulent activities, and foreign intelligence service exploitation; and/or the exploitation of digital media for intelligence and CI objectives” (DoDI 5505.13e 2(c)). CTA’s customer base spans the entire Department of Defense, federal law enforcement agencies and foreign partners. Accordingly, demand for courses (frequency / type / training location) is widely variant and continuously evolving.

In addition to the training support CTA provides to the Department of Defense, CTA also provides unclassified CONUS and OCONUS cyber investigative training to the nation’s FVEY partners, North Atlantic Treaty Organization (NATO) allies, and many other international partners via FMS cases (e.g., International Cyber Forensics Course).

The cyber domain is highly contested, fluid, dynamic and rapidly evolving. Threats, common one moment, become obsolescent (at pace) to new and increasingly sophisticated methods, tools, and threat actors. Similarly, the technologies upon which the entire domain is dependent are also evolving, maturing, and changing at pace. Since CTA supports the entire DoD cyber-workforce operating within this domain; it must remain agile and adaptable to customer needs to ensure their mission success.

To accomplish its mission CTA works closely with the Defense Criminal Investigative Organizations (DCIOs), Military Counter Intelligence Organizations (MDCOs), Service Cyber Components (SCCs), Combatant Commands (CCMDs), DoD CIO, OUSD (I&S), US Cyber Command (USCC) and other DoD organizations to:

• Define specialized cyber investigative training requirements for mission partners.

• Develop specialized cyber investigative training deliberately focused to these requirements.

• Continuously refine, update, modernize and improve extant CTA cyber investigative training offerings to ensure relevancy and efficacy to partner mission requirements.

• Deliver this training to anyone within the DoD, via a variety of modalities, whose duties are those described above (Paragraph 1.0.3).

All CTA courseware must be developed in accordance with (IAW) Air Force Instructional Systems Development (ISD) processes and procedures as set forth in Air Force Handbook (DAFH) 36-2675, Information for Designers of Instructional Systems, Air Force Instruction (AFI) 16-1007, Management of Air Force Operational Training Systems, and Department of the Air Force Policy Directive (DAFPD) 36-26, Total Force Development & Management. Other guiding references will include DC3/CTA Operating Instructions and Standard Operating Procedures. CTA utilizes the ISD method: Analyze, Design, Develop, Implement, & Evaluate (ADDIE) to design, develop, and implement its courses and curriculum.

1.0.4 SCOPE

The contractor shall provide highly qualified subject matter experts (SMEs) to support cyber investigative training development and delivery for CTA. The contractor shall provide support to

CTA to include but not limited to;

• Course Planning

• Course Instruction

• Course and Curriculum Development

• Administrative Support

• Technical Writing / Editing

• Project Management

• Training Systems Management and Administration (LMS)

• Training Support Solution Design, Development and Management (VMs, range, etc.…)

• Help Desk Support

1.0.5 CTA OVERVIEW

1.0.5.1 PRIMARY OPERATIONAL ENVIROMENT

As set forth later in this PWS, CTA is accredited by numerous accreditation bodies, each of which is focused upon a particular area of importance. Once such accreditation is the Council on Occupational Education (COE) which requires (at a minimum) “an institution must utilize a campus-based instructional delivery system with at least 25 percent of the institution’s total full-time education being derived from enrollment in traditional (bricks and mortar) programs”.

For this contract, the contractor shall provide training using their own contractor controlled and operated facility. The contractor owned and contractor operated facility shall be sufficient for the following:

A training environment consistent with industry best practices for technical training of the type described in this PWS.

In a single location:

Classroom and contractor administrative spaces to meet the Government’s baseline and surge training requirements, with a capacity to support 260 one-week (5 business days) training sessions annually and the development of up to three

(3) courses, and also which are, as later described in this contract, suitable for supporting contractor’s training delivery to up to 20 students per classroom space at any one given time.

A lab environment suitable for conducting course development and activity-based training for up to 20 students with instructors to include the following:

functionality: digital media repair (chip-off); physical and practical analysis of IoT devices; physical and practical analysis of SCADA/ICS devices; and wireless devices/network exploitation and analysis.

Space sufficient to support the Pearson-Vue test center operations capable of accreditation testing for up to 10 students at any given time

SCIF / Optional

At present all of CTA’s cyber investigative training is UNCLASS. However, the nature of the operational domain and corresponding, evolving requirements of CTA’s broad customer base may, during the term of this PWS, give rise to the need for classified cyber investigative training. SCIF may be applicable under Task Order 5 or 7.

Accordingly, within 90 calendar days of a request by the Contracting Officer (CO), the contactor shall provide a plan to gain access to at least one (1) Sensitive Compartmentalized Information Facility (SCIF) that is suitable for supporting course development efforts, providing training, and the contractor’s instructional delivery of courses for up to 30 students at any given time. The SCIF shall also provide access to NIPR, SIPR and JWIC networks. The location of the SCIF need not be co-located with other classrooms and staff spaces; however, the SCIF is desired to be located within a 15-mile radius of the contractor’s proposed location for CTA’s course development and other in-residence training.

1.0.5.2 TRAINING COURSES AND CURRICULUM

CTA’s current curriculum is differentiated into various, complementary domains:

DCIO cyber investigative training, MDCO cyber counter-intelligence training, CMF/CPT defensive cyber operations training, foreign partner training, and other specialty areas described in the Defense Cyber Workforce Framework (DCWF).

The curriculum focus areas are largely relational to the primary work role functions of each but not singularly exclusive to each; they are, in most cases, complementary.

Succinctly, competencies gained in one course have relevance across multiple DCIO, MDCO, CMF and DCWF positions.

CTA’s current offerings are shown in the graphic below. However, as set out above, due to the dynamic nature of the domain and the evolving mission requirements of our customers it should be expected for new courses to be added to and obsolete courses removed from this inventory during the term of this PWS. Detailed descriptions of these courses in the form of course design plans will be made available via attachment or reading room (as deemed most appropriate by the contracting officer).

GRAPHIC 1 – CURRENT CTA CURRICULUM

As shown above CTA’s training follows a continuum of skills progression from Level I through III. The curriculum is purposely designed as modular and adaptable to the variant needs of mission partners. The contractor should expect the course calendar / schedule of classes to frequently and routinely change to align with evolving/emerging customer training demands and requirements.

1.0.5.2.1 CTA Support to Cyber Mission Forces (CMF) and Cyber Protection Teams (CPTs)

In partnership with the Service Cyber Components and USCYBERCOM, CTA developed the initial baseline Cyber Protection Team (CPT) defensive cyber operations (DCO) training for USCYBERCOM. This training made possible the attainment of Full Operational Capability (FOC) for all CPTs, across all Service Cyber Components on or about May 17, 2018.

Since FOC, CPT DCO training has matured and is now the primary responsibility of the USN (CIWT Pensacola). However, CTA still provides significant training support to the SCCs CPTs particularly ARCYBER, MARFORCYBER and NAVIFOR. The contractor should expect frequent, ad-hoc requests for CPT training delivery (and potentially course development and modernization) during this PWS. Training delivery support can take the form of Instructor Led Virtual (ILV), Resident and/or Mobile Training Teams as dictated by the needs of the customer.

1.0.5.2.2 CTA International Training

Consistent with national defense strategy as expressed in the 2023 DoD Cyber Strategy (and other documents); it is the goal of CTA to continue to expand the availability of CTA’s courses to the widest audience of foreign partners possible.

Consequently, during the term of this PWS the contractor should expect continued increases in both the number of courses available to foreign partners and corresponding demand for delivery of these courses. During the performance of this contract the contractor shall provide training development and delivery support for these efforts, to include OCONUS delivery via MTT. Evolving demand will dictate scheduled offerings and delivery locations.

Currently, CTA offers foreign partners (via FMS case) the International Cyber Forensics Course (ICFC). ICFC itself is the logical grouping of INCH, CIRC, WFE and FIWE into one training offering. This course can be delivered resident and via MTT. During the performance of this contract the contractor shall provide training development and delivery support for these efforts, to include OCONUS delivery via MTT. Evolving demand for this course will dictate scheduled offerings and delivery locations.

1.0.5.2.3 Cyber Forensic Challenge

Working in partnership with DoD components CTA has developed a deployable Cyber Forensic Challenge for delivery to DoD personnel and selected foreign countries at CONUS and OCONUS locations as required / requested by DoD mission partners. During the performance of this contract the contractor shall provide development and delivery support for this effort, to include CONUS and OCONUS delivery support via MTT. Evolving demand for this course will dictate scheduled offerings and delivery locations.

1.0.5.3 LEARNING MANAGEMENT SYSTEM (LMS) and CYBER TRAINING SUPPORT

SYSTEM

CTA uses a contractor owned / operated solution for its Learning Management System (LMS) and Cyber Training Support System. The current system is comprised of Blackboard integrated with virtual machines provisioned through a cloud environment (Amazon). The technical specifications of the current cyber training support/delivery system shall be provided via the reading room or as deemed appropriate by the contracting officer.

For this PWS, the contractor will provide an LMS and cyber training delivery solution that is, at minimum, as capable as the extant system. Further, the contractor’s provided solutions shall be SCORM compliant and capable of readily ingesting CTA existing courseware and delivering same.

The contractor’s LMS solution shall have the capability of providing an easy to navigate, intuitive student (user) interface that allows (at minimum) for dynamic display of upcoming course scheduling and easy selection of scheduled courses from that display. Further, the system shall have the capability of displaying extant (and future) certification pathways, constituent courses and (upon user selection) dynamically provide upcoming scheduled offerings of the courses comprising the selected certification. In all cases, the contractor’s LMS solution/system must be professional (font consistency, image quality, etc…) and represent a best in class capability. A representative example of the type of desired functionality may be found via the Defense Acquisition University’s (DAU) website.

The contractor shall provide CTA Government staff full access to their proposed system to enable Government oversight and evaluation functions.

1.0.5.4 TRAINING ACCREDITATION

Accreditation is a formal process by which different aspects of CTA’s program and integrated operations are evaluated by outside accreditation bodies against standards of quality and competence established by the accrediting body. In short, accreditation helps ensure CTA provides the highest quality cyber investigative training that exceeds mission partner training requirements.

The accreditations obtained by CTA over the last 25 years demonstrate CTA’s commitment to quality, integrity, continuous improvement, accountability, and value for money. Accordingly, maintaining all accreditations in good standing is of critical importance. Each of the accreditations indicated below have associated dependencies that must be met and kept. The contractor shall provide support to the government, as directed, to maintain these accreditations.

1.0.5.4.1 Council on Occupational Education (COE)

Since 1971, the Council on Occupational Education has been recognized as a national institutional accrediting agency by the U.S. Secretary of Education.

One of the core tenants of achieving and maintaining COE accreditation is “utilize[ing] a campus-based instructional delivery system with at least 25 percent of the institution’s total (students trained) being derived from enrollment in a traditional (bricks and mortar) programs” (COE, council.org/achieving-accreditation, 2024).

CTA was most recently recertified by COE in 2019. During this PWS, the contractor shall provide support to maintain CTA’s accreditation in good standing. A copy of the CTA self-study will be made available via the reading room or at the contracting officer’s direction.

1.0.5.4.2 American Council on Education (ACE)

ACE accreditation involves the evaluation of CTA courses by ACE evaluators for quality, efficacy, value and providing recommendations for college credit equivalence. ACE evaluation provides a further means of demonstrating the quality CTA’s courses through this independent evaluation process. The comprehensive list of courses evaluated by ACE and awarded college credit recommendations may be found on the ACE website by searching for DC3.

During this PWS, CTA courses with ACE college credit recommendations, as well as new courses developed, will need review and assessment by ACE. The contractor shall perform tasks necessary to support all ACE reviews.

1.0.5.4.3 International Accreditors for Continuing Education and Training (IACET)

IACET accreditation is a review by (IACET) against ANSI/IACET 2018-1 standards.

This review and accreditation are a validation of the processes and framework by which CTA courses are developed and kept current. Furthermore, IACET accreditation allows CTA to offer Continuing Education Units (CEUs) for courses and other learning materials.

During this PWS, the contractor shall perform tasks necessary to maintain this certification including making certain course development processes and procedures maintain alignment to ANSI/IACET standards.

1.0.6 TASKS

The following tasks are in support of this contract:

• Task 1 – Cyber Training Academy (CTA) Operations and Administration

• Task 2 – Cyber Training Courses and Curriculum

• Task 3 – Cyber Training Environment and Capabilities

• Task 4 – Cyber Training Delivery

• Task 5 – Mobile Training Teams (MTTs)

• Task 6 – Program Management

• Task 7 – Additional Cyber Training Classroom (Optional) Note 1: Tasks 2, 5, and 7 have been identified to have surge requirements that are unknown (subject to change) at the time of IDIQ contract award. Details on the level of effort within these Tasks will be placed on separate Task Orders from the annual. Ordering Procedures will be provided in detail on how to handle surge requirements at the time of award.

1.1 TASK 1 – CTA OPERATIONS AND ADMINISTRATION

BUSINESS RELATIONS

The contractor shall work with the CTA Director, Deputy Director, Government Contracting Officer’s Representative(s) (COR), Government Program Manager (GPM), and Government Team Leads to accomplish government requirements, goals, and mission objectives as efficiently and effectively as possible. This shall include sharing or coordinating information resulting from the work required within this PWS and working as a team to perform tasks in concert.

The contractor shall ensure minimum duplication of effort in the execution of all work specified within this PWS and build upon work previously accomplished by the Government, the contractor, or other contractors to the fullest extent practicable.

NON-PERSONAL SERVICES

This PWS is a non-personal services contract. The Government will not supervise contractor personnel nor control the method(s) by which the contractor performs the required tasks. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services or give the perception of personal services.

If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor’s Program Manager’s responsibility to notify the CTA Director or Deputy Director immediately. Contractor services shall not be used to perform Inherently Government Functions.

1.1.1 SUBTASK 1 – CONTRACT ADMINISTRATION and MANAGEMENT

1.1.1.1 The contractor shall ensure the number of personnel, job categories, expertise and experience are sufficient to perform the work specified within the PWS. The contractor shall notify the CTA Director, Deputy Director or COR, 10 business days prior to any personnel re-assignments, losses, or replacements. The contractor, at its own expense, shall maintain proficiency, certification, and continuing education requirements necessary for each performance area of this PWS.

1.1.1.2 The contractor shall fully cooperate with the Government and other contractors.

1.1.1.3 The contractor shall provide employees who understand the unique requirements of cyber investigations and cyber counter-intelligence operations.

1.1.1.4 The contractor shall staff site supervision at the area of primary performance IAW the

PWS. The PM is responsible for the overall management of contractor personnel and is the primary interface between the Government and the contractor. This individual shall have full contractor authority to act in all contractual matters and be responsible and accountable to the Government in representing the contractor for meeting the performance requirements of this PWS. The PM shall be available during normal business hours to meet with the CTA Director, Deputy Director, CO, COR or Government Team Leads to discuss program and/or technical issues as required.

If the PM is unavailable for an extended period (more than 48 hours), these duties must be delegated to another contractor and the government notified who will be performing these duties within the 48-hour time frame.

1.1.1.5 The contractor shall ensure that personnel accessing DoD information systems have the proper and current DoD/USAF information assurance (IA) certification to perform information assurance functions IAW Air Force Manual (AFMAN) 17-1303, Air Force Cybersecurity Workforce Improvement Program, DoD Directive (DoDD) 8140.01, Cyberspace Workforce Management, and DoD 8570.01-M, Information Assurance Workforce Improvement Program.

1.1.1.6 The contractor shall ensure all contractor personnel complete ancillary training. This shall include Operations Security (OPSEC), Force Protection (FP), Human Relations (HR), Security, and Information Protection training and other ancillary training.

1.1.2 SUBTASK 2 – ACADEMY CERTIFICATION and ACCREDITATION SUPPORT

The contractor shall perform all support tasks necessary to maintain CTA’s current accreditations.

1.1.2.1 The contractor shall maintain CTA’s COE accreditation in good standing.

1.1.2.2 The contractor shall maintain course ACE accreditation(s).

1.1.2.3 The contractor shall maintain IACET accreditation including ensuring courses are designed in accordance with IACET requirements and best practices.

1.1.2.4 The contractor shall ensure designated courses align to the Defense Cyber Workforce

Framework.

1.1.3 SUBTASK 3 – STUDENT SERVICE SUPPORT

The Registrar Office is the primary focal point for student and customer engagement with CTA and as such it is deemed a critical function.

1.1.3.1 The contractor shall provide Registrar staff supporting the Government lead that comprehend CTA’s training mission, are knowledgeable in cyber investigative training and skilled / experienced in providing the highest quality customer service.

1.1.3.2 The contractor shall support the Government lead in marketing and outreach to increase enrollments in all cyber training offerings.

1.1.3.3 The contractor shall support the Government lead with student questions, inquiries, and communications.

1.1.3.4 The contractor shall manage student registration services for CTA students as well as online student enrollments.

1.1.3.5 The contractor shall support registration services on an as-needed basis for Government site customers.

1.1.3.6 The contractor shall provide student records management to include direct support with registrations, withdraws, questions, and other information requests, as required.

1.1.3.7 The contractor shall provide registered students with a Student Welcome Packet (Section

2, Deliverable 36) of information and automated notifications regarding course reminders, schedule changes, and other instructions and guidance that help prepare students for the courses.

1.1.3.8 The contractor shall interface directly with CTA customers to gather information on the customer training needs, estimate training demand, and provide this information to the Government lead to facilitate course delivery schedule management and update(s).

1.1.3.9 The contractor shall integrate student records management into the contractor’s training system solution (i.e., LMS).

1.1.3.10 The contractor shall ensure the protection of student records and information, such as Personally Identifiable Information (PII), in accordance with DoD and USAF requirements.

1.1.3.11 The contractor shall track and provide reporting on student data, such as student attendance, student performance, student trending, specific course demands, course cancellations, and student organizational data. Provide the Registrar Office Statistical Report as recorded in the training system solution (Section 2, Deliverable 18). Weekly reports are required for the CTA Director and Deputy Director in support of CTA operational reviews.

1.1.4 SUBTASK 4 – GRAPHIC ARTS, MULTIMEDIA, AND DOCUMENT PRINTING

SERVICES SUPPORT

1.1.4.1 The contractor shall provide the highest quality professional graphic arts, graphic design, graphic editing, document printing, audio/video support, and specialized multimedia support, as needed, in the design, development, maintenance, and updating of all CTA graphic arts, multimedia, website, LMS and training materials (regardless of delivery modality). The contractor shall ensure all materials are modern, professional, consistent, and of the highest quality possible.

1.1.4.2 The contractor shall provide online learning products (such as CyberCasts, QuickBytes, etc.), adjunct instructional videos, and interactive graphics. The contractor’s LMS system/solution shall separate CyberCasts and QuickBytes from CTA’s formal course offerings. Students must be able to (from the landing page of the LMS), at a minimum, identify the type of training they wish to select (ie. CyberCast, QuickByte, formal course) and from there be directed to an area containing only those offerings and (as required) the scheduled offering for each. In all cases the contractor’s system shall provide for an intuitive, user focused interface that encourages student participation and facilitates (makes easy) the ability for a student to: 1) Identify training opportunities; 2) Understand how training offerings connect to CTA certifications and/or DCWF work-roles; 3) register for courses/offerings and 4) track their learning / certification progress.

1.1.4.3 The contractor shall, provide support to the Government for printing, binding, and shipping of all (unclassified) instructional materials (e.g., student guides, instructor guides, etc.). All classified printing requirements will be managed by the Government.

1.1.4.4 The contractor shall design multimedia presentations and materials for use in workshops, resident/mobile education events, training exercises, and marketing forums; project planning requirements set forth in this PWS.

1.1.4.5 The contractor shall provide applicable IT support to implement multimedia presentations.

1.1.4.6 The contractor shall conduct routine assessments of all CTA training materials for the purposes of ensuring consistency, quality, and accuracy. The contractor shall document and deliver the results of this analysis to the Government, along with any recommended changes, to via the MSR.

1.1.4.7 The contractor shall support the development of marketing content for CTA’s strategic communication efforts to continue to inform and engage a wide range of DoD, Federal and International partners about CTA training offerings, mission support areas, training certifications, and capabilities

1.1.5 SUBTASK 5 – CTA WEBSITE DEVELOPMENT AND MAINTENANCE

1.1.5.1 The contractor shall develop, secure, maintain, and proactively update / enhance, CTA’s public website (www.dcita.edu).

1.1.5.2 The contractor shall ensure CTA’s public website is secure, of the highest quality with particular emphasis on proactive vulnerability identification and remediation. The contractor shall ensure all contractor provided CTA websites are secure, protect personal or Government information in accordance with cybersecurity guidelines and policies set forth in this PWS.

1.1.5.3 The contractor shall notify the CTA Director, Deputy Director, and COR, in writing of any security incidents involving CTA’s public website and/or LMS within 4 hours of incident discovery.

1.1.5.4 The contractor shall ensure that all website content remains up-to-date, is relevant, and can be easily accessed (508 compliance).

1.1.5.5 The contractor may be required to integrate single-sign-on between DC3’s website and

CTA’s, enabling seamless transition for persons moving between sites. Contractor will be notified of this requirement should it arise.

1.1.5.6 The contractor shall develop, maintain, and make available to the Government, all documentation associated with the website (e.g., hardware and software maintenance manuals, user manuals, source code, licenses, domain registration, etc.) (Section 2, Deliverable 30).

1.2 TASK 2 – CYBER TRAINING COURSES AND CURRICULUM

As set forth earlier in this PWS, the contractor can expect numerous and various, unscheduled for and un-planned for, course development efforts to arise frequently throughout each period of performance of this PWS. These efforts can and do take the form of single course development efforts, multiple course development efforts, and extant course modernization / update efforts, as set forth below.

New course development is understood to mean the development, from scratch, of a new cyber investigative training offering.

Major course re-development is understood to mean a change of more than 30% of any course’s content.

These efforts (above) are understood to be separate and distinct from regular course maintenance efforts.

The contractor shall perform curriculum quality assurance audits on specified CTA courses and associated training support functions (VMs, range solutions, etc.).

The contractor is responsible for working with the Government leads to review all courses and provide input for course updates and make certain courses are relevant, maintained in accordance with the requirements of the course design documents meet customer mission needs, and continue to provide the highest value for money possible.

The contractor is responsible for ensuring (as appropriate) courses align to existing certifications and accreditation requirements as well as aligning to DoD frameworks and standards and additional commercial certifications, as applicable or directed by the Government.

1.2.1 SUBTASK 1 – CYBER TRAINING REQUIREMENTS GATHERING

The Government will engage with customers, determine, and refine customer, cyber investigative training requirements and develop a course requirements document that will describe, the course, the terminal learning objectives, the intended audience, and other relevant information.

1.2.1.1 The contractor shall provide support with requirement’s gathering and course requirements development.

1.2.1.2 The contractor shall augment and support the Government in requirements gathering through such methods as student surveys, interviews with SMEs, industry best practice reviews, etc.

1.2.1.3 The contractor shall work with internal and external SMEs to inform iterative course updates and maintenance.

1.2.2 SUBTASK 2 – DEVELOPMENT PROJECT PLANNING

1.2.2.1 Upon receipt of the course requirements document from the Government; the contractor shall, within 7 business days, develop and deliver project plan (Section 2, Deliverable

34) for all work necessary to complete course design and develop the associated course.

1.2.2.2 The contractor shall ensure the project plan show course development effort to include any temporary staffing as well as time-phased activities with gates, deliverables, dependencies, and completion dates.

1.2.2.3 The Government shall use project plan to inform build / no-build decisions. Accordingly, the contractor shall ensure project plans are accurate and complete. The contractor will be notified in writing by the CTA Director and/or COR of build / no-build decisions.

1.2.2.4 For all course development, re-development and update efforts the contractor shall to the maximum extent possible, efficiently make use of all SME staffing from those included in their base proposal.

1.2.2.5 The contractor shall detail in their course development plan resource requirements and if

/ how these requirements will / would impact CTA operations.

1.2.2.6 The contractor shall immediately notify the Government of any changes during course development impacting course development effort(s) or other CTA operations such as delivery.

1.2.2.7 The contractor shall not engage in course development work that has not been approved of by the Government in writing.

1.2.3 SUBTASK 3 – COURSE DEVELOPMENT

1.2.3.1.1 The contractor shall utilize a Project Management Application for all course development that provides for tacking of milestones, module completions, deliverables for review. The contractor shall ensure the Government has read access to this system for the purposes of contractor performance oversight and evaluation.

1.2.3.1.2 The contractor’s project plan shall provide overall project planning, communication strategy, progress tracking, progress reporting, roadmaps, and timelines for all updates.

1.2.3.1.3 The contractor shall differentiate each course development effort by project name.

1.2.3.1.4 As appropriate and consistent with Government direction; the contractor shall ensure all courses are developed as practical training offerings, designed for practitioners;

heavily supported by immersive, hands-on exercises, practices, scenarios, and performance-based assessments.

1.2.3.1.5 The requirement is training that is reflective of requirements, immersive and transfers knowledge through practical exercises, vignettes, etc.

1.2.3.1.6 Upon written approval by the Government to begin course development; the contractor shall, within 30 calendar days, develop a course design plan document (Section 2, Deliverable 19). This document will describe the course in complete detail, decomposing Terminal Learning Objectives (TLOs) into Enabling Learning Objectives (ELOs), align/associated the appropriate Knowledge, Skills, and Abilities (KSAs) requisite to achieving the course objectives and provide mapping of these to the DoD Cyber Workforce Framework (DCWF).

1.2.3.1.7 This process (1.2.3.1.6) is iterative with the output (course design plan document) socialized by the Government with respective stakeholders until finalized by the Government.

1.2.3.1.8 The contractor’s course design plan document shall describe instructional strategies, methods, media used, and a syllabus/course map.

1.2.3.1.9 Unless otherwise approved by the Government, the contractor shall ensure at least

50% of any course developed contains hands-on exercises, practices, practice exams, and performance-based assessments that measure and assess the learner’s ability to perform specific tasks.

1.2.3.1.10 The contractor’s design plan document shall show the percentages of instructional delivery, student activities and student assessments for the entire course.

1.2.3.1.11 The contractor shall utilize the ISD, ADDIE model, along with Bloom’s taxonomy level of learning and/or Substitution, Augmentation, Modification, Redefinition (SAMR) Model for all course development (unless otherwise directed by the Government). detailed below.

1.2.3.1.12 The contractor shall develop courses and curriculum IAW the design plan document approved by the Government. Any changes to the course design/development must be approved by the Government, in writing, and incorporated into the design plan document before implementation.

1.2.3.1.13 The contractor shall review all course materials, technical documents, and manuals and ensure they effectively enable instructional delivery.

1.2.3.1.14 The contractor shall review all courseware for grammar, spelling, voice, format, and consistency.

1.2.3.1.15 The contractor shall perform curriculum quality assurance audits on all CTA training materials; updating, maintaining and keeping current all CTA training courses and materials.

1.2.3.1.16 The contractor shall provide user/test administration and critique creation and management within the test and contractor’s LMS.

1.2.3.1.17 As set out in the contractor’s course development plan; the contractor shall plan, design, and develop e-learning products, including objectives, storyboards, web-based aids, videos, etc.…

1.2.3.1.18 The contractor shall provide the Government access to the contractor’s system for developing, storing, modifying, and delivering all CTA course materials. The contractor shall ensure Government access privileges are sufficient to allow for Government review, oversight, and evaluation of all CTA courses and training materials resident in the contractor’s system.

1.2.3.1.19 The contractor, as part of course development, shall prepare a Student Guide for the course, containing all the requisite information a student would need to be successful in the course.

1.2.3.1.20 The contractor shall develop (and utilize) Instructor Guides for all courses to maintain integrity and consistency (over multiple iterations and varying instructional staff) and ensure the learning objectives, course pacing, and other relevant delivery criteria defined in the course design document are consistently met.

1.2.3.1.21 The contractor shall ensure Instructor Guides are appropriate in length, complexity, and detail depending upon the course, the material presented, and learning objectives.

1.2.3.1.22 When appropriate, the contractor shall utilize a courseware developer’s instructor guide in place of a contractor developed instructor guide for commercial courses delivered at CTA, such as NET +, SEC+, and others.

1.2.3.1.23 The contractor shall provide the Government regular updates and communication on course development progress including reviews of content, reviews of instructional materials, demonstrations of associated vignettes, and routine meetings with the content developers and integrators and other project team members (as necessary) via weekly meetings and Monthly Status Reports (MSRs).

1.2.3.1.24 The contractor shall ensure the Government is kept up to date on all course development efforts to facilitate, if necessary, changes early enough in the process to ensure the delivered item(s) meet the Government’s requirements.

1.2.4 SUBTASK 3 – TRAINING CONTENT TECHINCAL INTERGRATION

The contractor shall perform all activities necessary to integrate courses and associated training materials into the contractor’s cyber training system(s) and delivery platforms. The integration of training may vary depending on the course requirements and course design, customer training environment, and training site location requirements. At present all CTA course materials are within and provisioned by Blackboard with virtual machine support (as needed) provided through Amazon Web Services (AWS). Any contractor proposed solution must be (minimally) compliant with the capabilities of these systems.

The tasks set out below are respective to either:

1.2.4.1 Migration of CTA courses into a system different from that which is currently used by

CTA, or;

1.2.4.2 Development of new courses under this PWS and their subsequent integration into the cyber training system.

1.2.4.3 The contractor shall integrate training and courseware with the contractor’s training systems, VMs, training platform(s), simulated network environments, etc.

1.2.4.4 The contractor shall perform integration testing, as appropriate, to ensure training operates as intended and designed.

1.2.5 SUBTASK 4 – COURSE EVALUATION and MAINTENANCE

1.2.5.1 The contractor shall support course reviews and evaluations, to identify changes / updates are necessary for CTA courses.

1.2.5.2 The contractor shall support the Government in conducting regular audits of courses and course materials soliciting feedback from contractor SMEs, students, and other stakeholders.

1.2.5.3 The contractor shall support Government evaluations of all CTA courses and (annually) provide a written report of recommended course update actions to the Government.

(Section 2, Deliverable 20). The annual course review cycle shall not be greater than one calendar year from the previous review cycle as recorded on the course’s design plan document unless otherwise directed by the Government.

1.2.6 SUBTASK 5 – INFORMATIONAL and EDUCATIONAL RESOURCES

1.2.6.1 The contractor shall develop and maintain a set of informational and educational resources that engage CTA’s customer base and promote the courses delivered at CTA.

This includes, but is not limited to, a portfolio of webinars (referred to as CyberCasts), Discussion Threads, Tutorials, and Emerging Technology articles/news. These items shall be easily found on the student landing page and readily, in a user-friendly manner, accessible to students.

1.2.6.2 The contractor shall ensure the contents of its resources remain up to date and relevant in the cyber community.

1.2.6.3 The contractor shall maintain these materials / resources (as needed) in a secure, CAC/PIV-enabled portal with username/password option (as a part of the contractor’s cyber technical training solution).

1.2.7 SUBTASK 6 – COURSE CATALOG

1.2.7.1 The contractor shall design, develop, and maintain an annual (FY) course catalog that provides a comprehensive accounting and description of the Academy’s training offerings (Section 2, Deliverable 21).

1.2.7.2 The contractor shall ensure the course catalog corresponds to the most up-to-date training offerings. The course catalog shall follow the most current and approved DC3 CTA format.

1.2.7.3 The contractor shall provide the Government a draft of the next years Course Catalog, within 90 calendar days of the end of the fiscal year.

1.2.8 SUBTASK 7 – COURSE CALENDAR

As set forth earlier in this PWS; the demand for course delivery will vary, significantly, throughout the duration of this PWS.

At the beginning of each fiscal year the Government develops a notional / draft calendar based, in part, upon the prior year’s student throughput. For reasons explained earlier in this PWS, and given that CTA’s student base is drawn from across the entire DoD as well as Federal and International partners; there are and will be variances (year to year) especially in time phasing of student demand and course (type) demand. The contractor should expect at least 40% of the notional / draft calendar to change throughout any given FY.

1.2.8.1 The contractor shall provide the Government, as requested, metrics, throughput and other data as requested to support the Government’s calendar development efforts.

1.2.8.2 As set forth in Task 2, the contractor shall update the Government of all course development efforts and how those efforts and resource constraints impact delivery capacity (type, amount, time-phasing, etc.).

1.2.8.3 The contractor shall, within 3 business days of changes to the delivery calendar, ensure the publicly available delivery calendar (available to and used by students) via the CTA website is current and operates in a manner earlier set forth in this document.

1.2.8.4 The contractor’s impact statement shall detail resource allocations, their impact to planned delivery activities and recommendations for efficient time phasing

1.2.8.5 The contractor shall provide students, via the CTA website, the ability to request courses as well as provide for a wait list capability for scheduled offerings.

1.2.8.6 The contractor shall provide the Government updates on student requests and wait lists via the Weekly Status Report (WSR) as well as the Monthly Status Report (MSR).

1.2.8.7 The contractor will not make updates or changes to the delivery calendar that have not been approved of by the Government in writing.

1.3 TASK 3 – CYBER TRAINING ENVIRONMENT AND CAPABILITIES

The contractor shall perform all tasks required to provide the contractor’s physical and virtual cyber training environments and capabilities necessary for the successful delivery of cyber training. For the purposes of this section ‘cyber training environment’ is understood to mean the complete, integrated ‘system’ (LMS, Virtual Machines, Website(s), etc.) that comprise the contractor’ provided training solution.

1.3.1 SUBTASK 1 – CYBER TRAINING CLASSROOM

1.3.1.1 The contractor shall provide cyber training classrooms as referenced in Section 1.0.5.2 and all necessary furniture, equipment, tools, and other materials for delivering training under the contract, unless otherwise directed by the Government. To the maximum extent possible, all necessary furniture, equipment, tools, and other materials used in the classroom training environment shall be CFE. Furniture, equipment, tools, and other materials not provided as CFE will be purchased by the Government.

1.3.1.2 At some point during the performance of this contract, the contractor may be required to provide one Sensitive Compartmentalized Information Facility (SCIF) to be used for curriculum development and instruction as referenced in Section 1.0.5.2. It will not be required that this SCIF be co-located with the other classrooms in the contractor’s primary training (Academy) location.

1.3.1.3 The contractor shall provide classrooms that utilize state of the art tools, technologies, and virtualization capabilities for instructor facilitation and student learning.

1.3.1.4 The contractor shall ensure each student is provided the resources necessary to navigate through the instructor led courses (e.g., computers, monitors, connectivity, course materials, etc.). The goal is to provide students with a best-in-class training experience.

1.3.2 SUBTASK 2 – TECHNICAL TRAINING SOLUTION CAPABILITY

REQUIREMENTS

1.3.2.1 The contractor shall provide a solution that meets a minimum set of capability requirements set forth in this contract.

1.3.2.1.1 The current cyber training system used by the Academy is a cloud hosted solution of Blackboard with virtual machine provisioning via AWS.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .