BAA-RQKS-2015-0004-IDIQ-SOO.pdf
PDF 469 KB Posted
- Attached to
- Microelectronics & Embedded Systems Assurance (MESA) Federal contract opportunity
- Solicitation number
- BAA-RQKS-2015-0004
About this file
Basic IDIQ Statement of Objectives (SOO)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| BAA-RQKS-2015-0004.pdf | ||
| BAA-RQKS-2015-0004-ModelK Certs.pdf | ||
| BAA-RQKS-2015-0004-CDRLs.pdf | ||
| BAA-RQKS-2015-0004-DraftDD254.pdf | ||
| BAA-RQKS-2015-0004.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BAA-RQKS-2015-0004
Attachment 1
Microelectronics and Embedded System Assurance (MESA) IDIQ Statement of Objectives (SOO)
17 March 2015
1.0 Background:
Assurance of the security, reliability and trustworthiness of microelectronic devices, integrated circuits, and the intellectual property (IP) they host is vital to the continued technical superiority of Air Force weapon systems. All modern defense weapon systems are inherently reliant on microelectronic devices and embedded systems for their operation. Critical program information (CPI) is routinely exposed to the threat of reverse engineering due to combat and peacetime losses and foreign military/direct commercial sales. The continued trend toward outsourcing of integrated circuit and microelectronics fabrication to facilities outside the US increases the probability of introducing counterfeit or untrustworthy parts into the supply chain. Both of these threats can result in significant degradation in mission effectiveness; shorten the expected combat-effective life of a system;
reduce technological advantage; significantly alter program direction; or enable an adversary to defeat, counter, copy, or modify technologies or capabilities.
2.0 Objective:
The objective of this contract is to conduct basic, applied, and advanced Research and Development (R&D) to develop, evaluate, and facilitate the transition of technologies to improve the security and reliability of microelectronics and embedded systems. This research encompasses a multi-faceted approach to assurance for
Department of Defense (DoD) weapon systems at the microelectronic device and architecture level.
Base Support, available for proposal inclusion, includes the Microelectronics and Embedded System Assurance
(MESA) Laboratory. The MESA laboratory is equipped with a variety of state-of-the-art security and microelectronics evaluation instruments and software. Specialized laboratory equipment information is listed in the Task Order SOOs. Proposal(s) must include a plan to meet the requirements specified (Base Support or otherwise) to include Facility, IT Networks, and available Resources.
3.0 Tasks and Technical Requirements:
3.1 Security and Reliability Assessment: Contractors shall conduct R&D to assess the security and reliability of devices (to include microelectronics, radio-frequency, electro-optic, and photonic devices), integrated circuits, and embedded systems to include relevant hosted IP. The R&D shall include investigation of the vulnerability of microelectronic devices and IP to advanced reverse engineering attack vectors.
3.2. Assurance Technologies: Contractors shall conduct R&D to advance technologies and systems engineering approaches to eliminate, mitigate, or tolerate vulnerabilities or reduced reliability of insecure or inherently untrustworthy microelectronic devices or IP.
3.3. Assessment Tools: Contractors shall conduct R&D of new assessment techniques to evaluate the security and reliability of microelectronic devices and IP. The R&D shall focus on development and integration of innovative tools, processes, and techniques to improve the efficiency and effectiveness of microelectronics assessments. This shall include acquisition, modifications, and integration of custom test configurations.
3.4. Vulnerability Discovery: Contractors shall conduct R&D to discover and characterize the threat of security vulnerabilities and reverse engineering attack vectors to microelectronic devices and embedded systems.
The R&D shall include ongoing comprehensive literature searches of relevant open-source research to maintain awareness of new or emerging threats.
3.5. System Security Architectures: Contractors shall evaluate the effectiveness of system security architectures, designs and plans as well as participate in testing and review of program system security architecture/design reviews.
3.6. MESA Networks: Contractors shall develop and operate research networks as necessary. These networks must adhere to applicable security standards and meet performance requirements for associated task(s).
3.7. Microelectronics Trust: Contractors shall conduct R&D towards advancement in the field of detecting counterfeit or maliciously modified microelectronic devices or IP. The R&D shall include advancing the state of the art with regard to use of invasive and non-invasive microelectronics failure analysis techniques to identify untrustworthy devices.
3.8. Cyber Assurance for Microelectronic Devices: Contractors shall conduct R&D to assess the security and reliability of microelectronic devices and IP in the presence of cyber threats. The R&D shall include advancing the state of the art related to assessment, mitigation, and assurance for cyber threats to microelectronics.
4.0 Management:
The contractor shall exercise program, administrative, and financial management functions during this effort including establishing activities and milestones; tracking performance, cost, and schedule; overseeing quality performance; managing subcontractors; planning, forecasting, and reporting funding and funding changes; and preparing appropriate documentation. The contractor shall provide optimum technical performance on simultaneous TOs by effectively managing personnel and facility resources while meeting cost and schedule requirements. The contractor shall ensure conflict of interest resolution between internal R&D and any work associated with MESA security and reliability assessment/evaluations. If a conflict is anticipated, the contractor shall provide a mitigation plan within their business proposal(s). The contractor shall plan and conduct periodic technical review meetings as specified in the individual task order(s) which shall include subcontractor(s), AFRL, and other research personnel. The contractor shall maintain the required security standards for classified activities and data as well as ensure operational security (OPSEC) for the program.
5.0 Deliverables:
Data shall be delivered in accordance with the Contracts Data Requirements List (CDRLs) as attached to the Basic
IDIQ. Specific hardware/software deliverables will be included in each task order as applicable.
6.0 Security:
6.1 Program Security Requirements: Individuals must be US citizens and may be required to have SCI DCID 6/4
Top Secret Eligibility based on a SSBI/SBPR to work classified efforts. Work will be required to be conducted within an accredited Special Access Program Facility (SAPF) and/or a Sensitive Compartmented
Information Facility (SCIF). Specific security details and requirements will be outlined within future task orders. All classified efforts must be in compliance with the National Industrial Security Program Operating
Manual (NISPOM). Other regulations/policy that may apply to this contract are JAFAN 6/0 (Revision 1);
SAF/AAZ Memorandum “Air Force Special Access Programs Nomination Process (SAPNP)” (30 Sep 2013);
USD(I) Memorandum, Special Access Programs Nomination Process (20 May 2013); the DoD Manual
5205.07, Volume 4 (10 Oct 2013); “Special Access Program (SAP) Security Manual”: Marking; SAF/AAZ
Implementation Memorandum (7 Nov 2013); United States Air Force Security Marking Guide for SAPs (17
Jul 2011) and Revision 1 (16 Oct 2013); DoD SAPCO Memorandum, JAFAN 6/9 (23 Mar 04), Change 1 (20
Dec 05) and JAFAN 6/3 (15 Oct 2004); JAFAN 6/3 Implementation Guide, Version 1 (Sep 2006); DoD SAPCO
Memorandum, Transition to the Risk Management Framework (RMF) (18 Dec 2013); Joint Special Access
Program Implementation Guide (JSIG) (9 Oct 2013); DoD 8570.1-M, Information Assurance Workforce
Improvement Program (24 Jan 2012 – incorporating Change 3); Intelligence Community Directives (ICD) 704 and 705; other applicable SCI regulations/policy; other applicable Security Classification Guides (SCG); and other applicable regulations/policy and subsequent revisions.
Provide the following information with proposal submission: CAGE Code, Organization Name, and Security
Point of Contract (name/phone number). Questions regarding security should be directed to Robin
Grollmus at (937) 656-5701.
6.2 OPSEC Requirements: General OPSEC procedures, policies, and awareness are required in an effort to reduce program vulnerability from successful adversary collection and exploitation of critical information.
OPSEC will be applied throughout the lifecycle of the contract. The Critical Information List will be provided upon request by the RYOY Information Protection Office. While working on the government installation
OPSEC will be provided by the RYOY Information Protection Office.
6.3 Vault Operations: The following details additional security requirements pertaining to operation in the
MESA facility. When required, the contractor shall be responsible for the opening/closing of the MESA vault. This includes performing end-of-the-day security checks in accordance with Air Force requirements and MESA Vault Standard Operating Procedures (SOP). Vault operations will require use of security codes and combination locks during normal and extended duty days. Responding to alarms may be required during normal and extended duty days.
6.4 Security Training: The contractor will be required to participate in the United States Government’s (USG) in-house and web-based security training program under the terms of the contract. The USG will provide the contractor with access to the on-line system. The contractor will be required to take specialized security training as deemed applicable by USG.
File details come from the government source that posted it. Updated .