DRAFT -- M67854-22-R-7701_CVR_RFP Attachment 1-PWS v6.8.pdf
PDF 782 KB Posted
- Attached to
- Cyber Vulnerability Research (CVR) Federal contract opportunity
- Solicitation number
- M6785422R7701
- Issued by
- United States Marine Corps
About this file
This document is a pre-solicitation synopsis notice for solicitation number M6785422R7701 for Cyber Vulnerability Research services. The Marine Corps Systems Command intends to release a solicitation to acquire Cyber Vulnerability Research services from the Joint Cyber Weapons Product Manager Office and Program Manager Marine Corps Cyberspace Operations. The services will research, develop, test, deliver and employ exploits, payloads and implants to execute components of the cyber kill chain to enable commanders to disrupt, deny, degrade or destroy targets in cyberspace. The contract will be a single-award, cost-plus-fixed-fee indefinite delivery indefinite quantity contract with a five year ordering period. The North American Industry Classification System code is 541715. Questions about the draft RFP are due by May 12, 2022 and the formal RFP will be released on SAM.gov by the end of May 2022. Interested parties must register in the System for Award Management to be eligible for award.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| M67854-22-R-7701_Government response to Industry CVR feedback (for Public Release).pdf | ||
| DRAFT -- M67854-22-R-7701_CVR_RFP_v1.7.pdf | ||
| DRAFT -- M67854-22-R-7701_CVR_RFP Attachment 2-PPQ_v1.3.pdf | ||
| DRAFT -- M67854-22-R-7701_CVR_RFP Attachment 6-Task Order 1 PWS v1.5.pdf | ||
| DRAFT -- M67854-22-R-7701_CVR_RFP Attachment 3-Staffing Matrix v1.0.xlsx | XLSX spreadsheet | |
| DRAFT -- M67854-22-R-7701_CVR_RFP Attachment 4-Pricing Worksheet v1.1.xlsx | XLSX spreadsheet | |
| DRAFT -- M67854-22-R-7701_CVR_RFP Attachment 5-Task Order 1-Pricing Worksheet v1.1.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED
CYBER VULNERABILITY RESEARCH (CVR)
PERFORMANCE WORK STATEMENT
SINGLE AWARD TASK ORDER CONTRACT (SATOC)
25 April 2022
Version 6.8
FOR RELEASE TO THE PUBLIC
i.
This Page is Intentionally Left Blank
PM MCCO UNCLASSIFIED M67854-22-R-7701
ii
TABLE OF CONTENTS
1. GENERAL
1.1 Description of Services/Introduction
1.2 Background
1.3 Objective
1.4 Scope
1.5 Period of Performance
1.6 General Requirements and Information
1.6.1 Quality Control
1.6.2 Quality Assurance
1.6.3 Recognized Holidays
1.6.4 Hours of Operation
1.6.5 Place of Performance
1.6.6 Type of Contract
1.6.7 Security Requirements
1.6.7.4 Additional System Security Requirements
1.6.7.5 Information Assurance/Cybersecurity Requirements
1.6.8 Post Award Conference/Periodic Progress Meetings
1.6.9 Contracting Officer Representative (COR)
1.6.10 Key Personnel
1.6.11 Identification of Contractor Employees
1.6.12 Contractor Travel
1.6.13 Other Direct Costs
1.6.14 Data Rights
1.6.15 Organizational Conflict of Interest
1.6.16 Phase In/Phase Out Period
1.6.17 Government Extended Off-Site Working Conditions
1.6.18 Dress and Conduct
1.6.19 Program Management
1.6.20 Business Relations
1.6.21 Task Orders
2. DEFINITIONS AND ACRONYMS
2.1. DEFINITIONS
2.2. ACRONYMS
3. GOVERNMENT FURNISHED ITEMS AND SERVICES
4. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES
5. SPECIFIC TASKS
5.1 Cyber Vulnerability Overview
5.1.2 Cyberspace Operational Requirements
iii
5.1.3 Development Processes
5.1.4 Kill Chain Elements
5.1.5 Tiers of implant equity
5.1.6 General Use Cases
5.1.7 Capability definitions
5.1.8 Implants stages
5.2 Specific Cyber Vulnerability Tasks
5.3 Task Order 0001: Vulnerability Research, Reverse Engineering, Exploit Procurement, and Target and Market
Analysis ................................................................................................................... Error! Bookmark not defined.
5.3.1 Lead VR/RE and Exploit Procurement Subject Matter Expert ....................... Error! Bookmark not defined.
5.3.2 Target and Market Analysis ............................................................................ Error! Bookmark not defined.
6. APPLICABLE PUBLICATIONS (CURRENT EDITIONS) ................................. Error! Bookmark not defined.
7. ATTACHMENT/TECHNICAL EXHIBIT LISTING
Attachment/Technical Exhibit List: ............................................................................. Error! Bookmark not defined.
Cyber Vulnerability Research
PART 1
GENERAL INFORMATION
1. GENERAL
This Cyber Vulnerability Research (CVR) Single Award, Task Order Contract (SATOC)
Performance Work Statement (PWS) supports requirements for the Joint Cyber Weapons
(JCW) program, the United States Marine Corps, United States Cyber Command, and other Government agencies.
1.1 Description of Services/Introduction
The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform cyber vulnerability research as defined in this PWS except for those items specified as Government furnished property and services. The contractor shall perform to the standards in this PWS and the SATOC.
1.2 Background
The JCW program provides advanced cyber warfare capabilities in direct support of U.S.
Cyber Command, Combatant Commanders, and national agencies to enable and accomplish global operations. Activities within the JCW program deliver cyberspace superiority capabilities though research, development, testing, evaluation, and integration of cyber technologies. The JCW program includes support to a Combat Support Team to develop prototypes for testing new cyber weapons to outpace modernized defenses used by peer adversaries and to enhance lethality and relevance of software constructed cyber weapons.
1.3 Objective
The objective of the Cyber Vulnerability Research SATOC is to research, develop, integrate, and purchase software, firmware and supporting hardware to enable
Commanders to disrupt, deny, degrade, or destroy targets in cyberspace.
1.4 Scope
The scope of this effort is to provide services and products to research, develop, test, deliver and employ exploits, payloads, and implants to execute the necessary components of the cyber kill chain to enable Commanders to disrupt, deny, degrade, or destroy targets in cyberspace.
1.5 Period of Performance
The SATOC will have a five-year ordering period. Each task order issued against this
SATOC within the five-year ordering period will identify the period of performance which is specific to each order.
The contractor shall continue performance in emergency or mission essential conditions in the event of a Government shutdown, and as directed by the Contracting Officer.
1.6 General Requirements and Information
1.6.1 Quality Control
The contractor shall develop and maintain an effective quality control plan (QCP) to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s QCP is the means by which it assures itself that its work complies with the requirements of the contract. Within 30 days after contract award, one copy of the QCP shall be emailed to the Contracting Officer and the Contracting
Officer’s Representative (COR) in a PDF format as an attachment to the email. The quality system procedures, planning, and all other documentation and data that comprise the contractor’s quality system, shall be made available to the Government for quality surveillance inspections. After the Government’s acceptance of the QCP, the contractor shall obtain the Government Contracting Officer or COR’s acceptance in writing of any proposed changes to the contractor’s QCP. All revisions to the contractor’s QCP are subject to Government review and approval. The Government may find the QCP
“unacceptable” whenever the contractor’s procedures do not accomplish quality control objectives. The contractor shall revise the QCP within 5 calendar days from receipt of notice that the QCP is found “unacceptable” as determined by the Contracting Officer or
COR. The contractor shall submit an updated QCP within 5 calendar days of the changes implemented thereafter. After acceptance of the QCP, the contractor shall receive the
Contracting Officer’s acceptance in writing of any proposed change to his QC system.
CDRL B001: DI-MISC-80508B Quality Control Plan
1.6.2 Quality Assurance
The Government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.6.3 Recognized Holidays
The contractor is not required to perform services on holidays.
New Year’s Day Labor Day
Martin Luther King Jr.’s Birthday Columbus Day
President’s Day Veteran’s Day
Juneteenth National Independence Day Thanksgiving
Memorial Day Christmas
Independence Day
1.6.4 Hours of Operation
The contractor is responsible for being available for Government communication, between the hours of 0800 – 1700 Eastern Time (ET) Monday through Friday except
Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings.
The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. When hiring personnel, the contractor shall keep in mind that the stability and continuity of the workforce are essential.
1.6.5 Place of Performance
The work to be performed under this contract shall be performed at the contractor’s facility, unless stated otherwise in a task order.
1.6.6 Type of Contract
The Government contemplates the award of a hybrid, single award Indefinite
Delivery/Indefinite Quantity contract consisting of Firm Fixed Price and Cost type
Contract Line Item Numbers (CLINs).
1.6.7 Security Requirements
This contract will require the contractor to have a Top Secret/Sensitive Compartmented
Information (TS/SCI) Facility Clearance and will require certain contractors to obtain and maintain classified access eligibility. The contractor shall have a valid Top
Secret/Sensitive Compartmented Information Facility Clearance and a Top
Secret/Sensitive Compartmented Information Safeguarding Level prior to classified performance. The prime contractor and all sub-contractors (through the prime contractor) shall adhere to all aspects of CFR 32 Part 117 NISPOM and DoD Manual 5220.22
Volume 2. All personnel identified to perform on this contract shall maintain compliance with Department of Defense, Department of the Navy, and Marine Corps Information and
Personnel Security Policy to include completed background investigations (as required) prior to classified performance. This contract shall include a DoD Contract Security
Classification Specification (DD-254) as an attachment. Certain contractors will be required to perform IT-I/II duties that will require favorably adjudicated Tier 5/3 Level investigations. The Defense Counterintelligence Security Agency (DCSA) will not authorize contractors to submit the necessary Tier Level investigations solely in support of IT level designation requirements, but are required to submit investigations for those employees requiring both Secret access and IT-II designation. The Government
Contracting Activity Security Office (GCASO) is required to submit any required investigations in support of IT-I level designations. The contractor is required to provide a roster of prospective contractor employees performing IT-I duties to the MCSC
Contracting Officer’s Representative (COR). This roster shall include: full names, Social
Security Numbers, e-mail address and phone number for each contractor requiring investigations in support of IT Level designations. The COR will verify the IT-I requirements and forward the roster to the GCASO. Contractors found to be lacking required investigations will be contacted by the GCASO.
Facility Security Officers (FSOs) are responsible for notifying the MCSC AC/S G-2
Personnel Security Office (PERSEC Office) via encrypted e-mail to
MCSC_Security@usmc.mil or 703-432-3374/3952 if any contractor performing on this contract receives an unfavorable adjudication. The FSO must also notify the PERSEC mailto:MCSC_Security@usmc.mil
Office, within 24 hours, of any adverse/derogatory information associated with the 13
Adjudicative Guidelines concerning any contractor performing on this contract, if they have been granted an IT designation, issued a CAC, a MCSC Building Badge and/or granted classified access. The FSO shall notify the Government (written notice) within
24 hours of any contractor personnel added or removed from the contract that have been granted IT designations, issued a Common Access Card (CAC) and/or a MCSC Building badge/access.
Contractor Key Personnel performing work under this contract must have a TS/SCI
Clearance with Counter Intelligence Polygraph at time of the proposal submission, and must maintain the level of security required for the life of the contract. The security requirements are in accordance with the attached DD254. Contractor Key Personnel performing work under this contract must have access to TS/SCI email and a TS/SCI
National Secure Telephone System (NSTS) phone line in order to communicate with the
Government and exchange TS/SCI information.
Operations Security (OPSEC) Requirements. While performing aboard NAVY/USMC sites, the contractor shall comply with the provisions of DoD Directive 5205.02E, "DoD
OPSEC Program," SECNAV 3070.2, CMDO 3070.1A, MCO3070.2A, and the
MARCORSYSCOMO P5510.2B Security Manual, at all other sites the contractor shall comply with the local command and/or program OPSEC plan.
1.6.7.1 Physical Security. The contractor shall be responsible for safeguarding all
Government equipment, information and property provided for contractor use. At the close of each work period, Government facilities, equipment, and materials shall be secured.
1.6.7.2 Key Control. The contractor shall establish and implement methods of making sure all keys/key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards.
No keys issued to the contractor by the Government shall be duplicated. The contractor shall develop procedures covering key control that shall be included in the Quality Control
Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The contractor shall immediately report any occurrences of lost or duplicate keys to the Contracting Officer.
1.6.7.2.1 In the event keys, other than master keys, are lost or duplicated, the contractor shall, upon direction of the Contracting Officer, re-key or replace the affected lock or locks;
however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the contractor.
1.6.7.2.2 The contractor shall prohibit the use of Government issued keys by any persons other than the contractor’s employees. The contractor shall prohibit the opening of locked areas by contractor employees to permit entrance of persons other than contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.
1.6.7.3 System Security
1.6.7.3.1 System Security Plan and Plans of Action and Milestones (SSP/POAM)
Reviews.
1.6.7.3.1.1 Within thirty (30) days of TO award, the contractor shall make its System
Security Plan(s) (SSP(s)) for its covered contractor information system(s) available for review by the Government at the contractor’s facility. The SSP(s) shall implement the security requirements in Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which is included in this contract. The contractor shall fully cooperate in the Government's review of the SSPs at the contractor's facility.
1.6.7.3.1.2 lf the Government determines that the SSP(s) does not adequately implement the requirements of DFARS clause 252.204-7012 then the Government shall notify the contractor of each identified deficiency. The contractor shall correct any identified deficiencies within thirty (30) days of notification by the Government. The Contracting
Officer may provide for a correction period longer than thirty (30) days and, in such a case, may require the contractor to submit a plan of action and milestones (POAM) for the correction of the identified deficiencies. The contractor shall immediately notify the
Contracting Officer of any failure or anticipated failure to meet a milestone in such a
POAM.
1.6.7.3.1.3 Upon the conclusion of the correction period, the Government may conduct a follow-on review of the SSP(s) at the contractor's facilities. The Government may continue to conduct follow-on reviews until the Government determines that the contractor has corrected all identified deficiencies in the SSP(s).
1.6.7.3.1.4 The Government may, in its sole discretion, conduct subsequent reviews at the contractor's site to verify the information in the SSP(s). The Government will conduct such reviews at least every three (3) years (measured from the date of contract award) and may conduct such reviews at any time upon thirty (30) days' notice to the contractor.
1.6.7.3.2 Compliance to National Institute of Standards and Technology (NIST) 800-
1.6.7.3.2.1 The contractor shall fully implement the CUI Security Requirements
(Requirements) and associated Relevant Security Controls (Controls) in NIST Special
Publication 800-171 (Rev. I) (NIST SP 800-171), or establish a SSP(s) and POAMs that varies from NIST 800-171 only in accordance with DFARS clause 252.204-7012(b)(2), for all covered contractor information systems affecting this contract. Notwithstanding the allowance for such variation, the contractor shall identify in any SSP and POAM their plans to implement the following, at a minimum:
(1) Implement Control 3.5.3 (Multi-factor authentication). This means that multi-factor authentication is required for all users, privileged and unprivileged accounts that log into a network. In other words, any system that is not standalone should be required to utilize acceptable multi-factor authentication. For legacy systems and systems that cannot support this requirement, such as CNC equipment, etc., a combination of physical and logical protections acceptable to the Government may be substituted;
(2) Implement Control 3.1.5 (least privilege) and associated Controls, and identify practices that the contractor implements to restrict the unnecessary sharing with, or flow of, covered defense information to its subcontractors, suppliers, or contractors based on need-to-know principles;
(3) Implement Control 3.1.12 (monitoring and control remote access sessions).).
Require monitoring and controlling of remote access sessions and include mechanisms to audit the sessions and methods;
(4) Audit user privileges on at least an annual basis;
(5) Implement:
i. Control 3.13.11 (FIPS 140-2 validated cryptology or implementation of
NSA or NIST approved algorithms (i.e. FIPS 140-2 Annex A: AES or Triple DES) or compensating controls as documented in a SSP and POAM); and,
ii. NIST Cryptographic Algorithm Validation Program (CAVP) (see https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program);
(6) Implement Control 3.13.16 (Protect the confidentiality of CUI at rest) or provide a POAM for implementation which shall be evaluated by the Navy for risk acceptance.
(7) Implement Control 3.1.19 (encrypt CUI on mobile devices) or provide a plan of action for implementation which can be evaluated by the Government Program
Manager for risk to the program.
1.6.7.3.3 Cyber Incident Response
1.6.7.3.3.1 The contractor shall, within fifteen (15) days of discovering the cyber incident
(inclusive of the 72-hour reporting period covered below), deliver all data used in performance of the contract that the contractor determines is impacted by the incident and begin assessment of potential warfighter/program impact.
1.6.7.3.3.2 Incident data shall be delivered in accordance with the Department of Defense
Cyber Crimes Center (DC3) Instructions for Submitting Media available at http:/ www.acq.osd.mil/dpap/dars/pgi/docs/Instructions _for_Submitting_Media.docx. In http://www.acq.osd.mil/dpap/dars/pgi/docs/Instructions%20_for_Submitting_Media.docx delivery of the incident data, the contractor shall, to the extent practical, remove contractor-owned information from Government covered defense information.
1.6.7.3.3.3 If the contractor subsequently identifies any such data not previously delivered to DC3, then the contractor shall immediately notify the Contracting Officer in writing and shall deliver the incident data within (10) days of identification. In such a case, the contractor may request a delivery date later than ten (10) days after identification. The Contracting Officer will approve or disapprove the request after coordination with DC3.
1.6.7.3.4 Naval Criminal Investigative Service (NCIS) Outreach
1.6.7.3.4.1 The contractor shall engage with, comply with, conduct meetings, and address recommendations made by NCIS industry outreach efforts and consider recommendations for hardening of covered contractor information systems affecting
DON programs and technologies.
1.6.7.3.5 NCIS/Industry Monitoring
1.6.7.3.5.1 In the event of a cyber incident or at any time the Government has indication of a vulnerability or potential vulnerability, the contractor shall cooperate with NCIS, which may include cooperation related to: threat indicators; pre-determined incident information derived from the contractor's infrastructure systems; and the continuous provision of all contractor, subcontractor or contractor logs that show network activity, including any additional logs the contractor, subcontractor or contractor agrees to initiate as a result of the cyber incident or notice of actual or potential vulnerability.
1.6.7.3.5.2 If the Government determines that the collection of all logs does not adequately protect its interests, the contractor and NCIS will work together to implement additional measures, which may include allowing the installation of an appropriate network device that is owned and maintained by NCIS, on the contractor’s information systems or information technology assets. The specific details (e.g., type of device, type of data gathered, monitoring period) regarding the installation of an NCIS network device shall be the subject of a separate agreement negotiated between NCIS and the contractor.
In the alternative, the contractor may install network sensor capabilities or a network monitoring service, either of which must be reviewed for acceptability by NCIS. Use of this alternative approach shall also be the subject of a separate agreement negotiated between NCIS and the contractor.
1.6.7.3.5.3 In all cases, the collection or provision of data and any activities associated with this performance work statement shall be in accordance with federal, state, and non-
US law.
1.6.7.4 Additional System Security Requirements.
To provide adequate security, the contractor shall implement NIST Special Publication
800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and
Organizations. The contractor shall provide a System Security Plan (SSP) and Plan of
Action and Milestones (POAMs) in accordance with contractor’s SSP (CDRL A001) indicating whether the contractor has implemented the security requirements therein, plans to implement the security requirements, or that the requirement is not applicable.
The contractor shall submit a list in accordance with the contractor’s Record of Tier 1
Level Suppliers Receiving/Developing CUI (CDRL A002) of all supporting Tier 1 Level suppliers receiving or developing covered defense information, otherwise known as CUI.
In addition, the contractor shall provide its plan to Government review and approval to track flow down of covered defense information and to assess DFARS Clause 252.204-
7012 compliance of known Tier 1 Level suppliers.
The contractor shall document and report all cyber incidents that affect the covered contractor information system or the covered defense information residing therein, or that affect the contractor’s ability to perform requirements designated as operationally critical support via the Cyber Incident Reporting (CDRL A003). The contractor shall submit malicious software discovered and isolated in connection with a reported cyber incident to the DoD Cyber Crime Center. The contractor shall report all cyber incidents or compromise related to Government CUI in accordance with DFARS 252.204-7012 to the
Damage Assessment Office (DAMO) via the DIB-NET Website (http://dibnet.dod.mil) within 72 hours. The contractor shall, if requested, submit media and additional information to support damage assessment.
CDRL A001: DI-MGMT-82247 Contractor’s System Security Plan
CDRL A002: DI-MISC-80711A Contractor’s Record of Tier 1 Level Suppliers
Receiving/Developing CUI
CDRL A003: DI-MISC-80711A Cyber Incident Reporting
1.6.7.5 Information Assurance/Cybersecurity Requirements
This service acquisition will contain performance objectives related to information assurance (cybersecurity), the requirements of DFARS 239.7102-3(d) and PGI 239.7102-
3 concerning information assurance (cybersecurity) contractor training and certification are applicable. As described in FAR 46.203, the provision of information assurance
(cybersecurity) is of such importance that attention must be tied to contract quality requirements. The classification of information assurance (cybersecurity) provided under this contract is: (1) Military-Federal; (2) noncomplex; and (3) a common critical service.
Failure by the contractor to obtain, or maintain, the required information assurance
(cybersecurity) certifications, is a critical nonconformance as defined in FAR 46.101.
Likewise, a single instance whereby the contractor is unable to provide the documentation for one of its personnel when requested by the Government, as described at DFARS 252.239-7001(b), is also a critical nonconformance and will subject the contractor to one or a combination of the following remedies: an unsatisfactory CPARS rating, a show cause or cure notice issued from the contracting officer, and/or the application of payment withholdings consistent with the terms of the contract.
1.6.7.6 Cybersecurity Workforce Report
The contractor shall deliver to the Government a roster of contractor personnel that are trained and certified pursuant to DFARS 252.239-7001, in accordance with DoD
8570.01-M. Contractor personnel who do not have proper and current certifications will be denied access to DoD information systems for the purpose of performing cybersecurity functions. The loss of a certification by a contractor employee does not relieve the contractor of their responsibility to continue providing the services required by a task order issued under the SATOC. The data deliverable shall be generated, delivered to the Government monthly, and shall consist of current certification information for personnel who are assigned to tasks related to cybersecurity/information assurance in accordance with the specific performance requirements that accompany each individual task order issued under the SATOC.
1.6.8 Post Award Conference/Periodic Progress Meetings
The contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition
Regulation Subpart 42.5. The post award conference shall be held with 10 miles of Fort
Meade, MD. The Contracting Officer, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings, the Contracting Officer will apprise the contractor of how the Government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the
Government.
1.6.8.1 Task Order Post Award Conferences (TOPAC)
The times, dates, and locations for TOPACs will be specified in each task order (TO).
The principal purpose of the TOPAC is for the contractor to demonstrate to the
Government the operating procedures, methodologies, and processes that will be used by the contractor to perform the specific requirements of the TO. Each TOPAC conference will include a review of the TO’s terms, conditions, and specific requirements. During the TOPAC, the participants will review the applicable roles and responsibilities of the parties. The TOPAC also provides the parties an opportunity to identify, and resolve, any ambiguity with respect to the TO’s terms and conditions.
The contractor shall prepare a TOPAC Agenda, which meets the minimum requirements provided below for the TOPAC (in accordance with CDRL B004), TOPAC Conference Minutes (in accordance with CDRL B005), and TOPAC Briefing
Materials (in accordance with CDRL B006). The data deliverable shall be generated and delivered to the Government in accordance with the specific performance requirements that accompany each TO.
Entrance Criteria for the TOPAC:
(1) Government Acceptance of the TOPAC agenda and briefing materials
(2) Submission of the following CDRLs for Government review
CDRL B002 – Management Plan
Agenda for the TOPAC (minimum requirements)
(1) Introduction and Overview
(2) Discussion and clarification of requirements
(3) Contractor identification and risk assessment of any and all GFI and GFP deficiencies
(4) Contract Management Plan
(5) Phase-In Transition Plan
(6) Computer Requirements
(7) Phase-Out Transition Plan
(8) Subcontractor Management and Organizational structure
(9) Organizational and Consultant Conflicts of Interest
(10) International Traffic in Arms Regulations (ITAR) Compliance -
Export of Defense Services
TOPAC Exit Criteria
(1) Government acceptance of the TOPAC minutes in accordance with CDRL
B005.
CDRL B002: DI-MGMT-80004A Management Plan
CDRL B004: DI‐ADMN‐81249B Conference Agenda
CDRL B005: DI-ADMN-81250B Conference Minutes
CDRL B006: DI- MGMT-81605 Briefing Material
1.6.8.2 Program Management Reviews (PMRs)
The contractor shall conduct TO Program Management Reviews (PMRs) as identified in the TO PWS on a not more than quarterly basis throughout the TO period of performance
(POP) to assess program cost, schedule, performance, process implementation, risk, and status of the TO. The initial TO PMR shall be conducted within 90 calendar days after the TOPAC specified in paragraph 1.6.8.1 and quarterly thereafter. The TO PMRs may be held in conjunction with other reviews and conferences to meet PMR objectives and to utilize time more efficiently, and may be conducted via secure video teleconference
(VTC) or teleconference to reduce costs. In addition to any entrance and exit criteria, minimum agenda items for TO PMRs will be specified in the TO.
The contractor shall prepare Conference Agendas for the PMRs (in accordance with
CDRL B004), Conference Minutes (in accordance with CDRL B005), and Briefing
Materials (in accordance with CDRL B006). The data deliverable shall be generated and delivered to the Government in accordance with the specific performance requirements in the applicable TO.
1.6.8.3 In Process Working Meetings (IPWM)
Government and contractor IPWMs may be conducted at the COR’s discretion to review and discuss risks/issues (i.e., cost, schedule, performance), and provide a forum to promote and sustain the continuous interchange of ideas. IPWMs shall meet at a jointly agreed upon time and location. The IPWMs may be conducted via secure VTC or teleconference upon agreement of the Government and contractor.
IPWMs are intended to be working level interactions that promote timely and responsive identification of risks and issues, and progressively elaborate planning for existing, within scope, requirements. IPWMs provide a forum for both the contractor and the
Government to maintain relatively continuous communication. Regarding problem or issue identification and resolution, IPWMs can serve as a first step in triaging the root cause for any concerns and promote collaborative resolution of problems. IPWMs do not replace the formal mechanism(s) that are in place for identifying and correcting non– conforming performance as specified in this or any task order PWS, nor do IPWMs meetings provide authority, or approval of, any unauthorized changes or deviations to the terms and conditions of the SATOC or TO.
Not every IPWM will require the deliverables referred to below. However, to the extent that updated schedules, timelines, or proposed, in scope, resolutions to performance issues are resolved at a IPWM or at the direction of the COR, then the appropriate supporting documentation shall be generated as specified below. The contractor shall prepare, when required by the Government, Conference Agendas for the reviews (in accordance with CDRL B004), Conference Minutes (in accordance with
CDRL B005), and/or Briefing Materials (in accordance with CDRL B006). The data deliverables shall be generated and delivered to the Government in accordance with the
DD Form 1423 issued with a TO.
1.6.9 Contracting Officer Representative (COR).
The (COR) will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance;
maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including
Government drawings, designs, specifications; monitor contractor's performance and notifies both the Contracting Officer and contractor of any deficiencies; coordinate availability of Government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.
1.6.10 Key Personnel
The following personnel are designated as key personnel by the Government: (1) Lead
Vulnerability Researcher (VR)/Reverse Engineer (RE), and (2) Exploit Procurement subject matter expert. Both the Lead VR/RE and Exploit Procurement subject matter expert shall be responsible for the performance of the work.
1.6.10.1 Lead Vulnerability Researcher (VR)/Reverse Engineer (RE) and Exploit
Procurement Subject Matter Expert.
1.6.10.1.1 The contractor shall provide a Lead VR/RE who shall be responsible for the performance of the work. The name of the Lead VR/RE shall be designated in writing to the Contracting Officer. The Lead VR/RE shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. In the event of a conflict between the Lead VR/RE and Exploit Procurement subject matter expert, the decisions of the Lead VR/RE shall prevail.
1.6.10.1.2 The contractor shall provide an Exploit Procurement subject matter expert who shall be responsible for the performance of the work. The name of the Exploit
Procurement subject matter expert shall be designated in writing to the Contracting
Officer. The Exploit Procurement subject matter expert shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. In the event of a conflict between the Lead VR/RE and Exploit Procurement subject matter expert, the decision of the Lead VR/RE shall prevail.
1.6.10.1.3 The Lead VR/RE or Exploit Procurement subject matter expert shall respond to emails or phone calls from the Government within 1 business day. The contractor shall plan for the Lead VR/RE or Exploit Procurement subject matter expert to be available between 0800 – 1700 ET, Monday through Friday, except Federal holidays or when the Government facility is closed for administrative reasons.
1.6.11 Identification of Contractor Employees
All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. Contractors shall be required to obtain and wear badges in the performance of this contract.
1.6.12 Contractor Travel
The contractor shall be required to travel anywhere OCONUS or CONUS, with anticipated travel to Texas, Florida, Alabama, Colorado, California, Hawaii, and within the National Capital Region (NCR) during the performance of this contract to attend meetings, conferences, and training. The contractor may be required to travel to off-site training locations and to ship training aids to these locations in support of this PWS. The contractor will be authorized travel expenses consistent with the substantive provisions of the Joint Travel Regulation (JTR) and the limitation of funds specified in this contract.
All travel requires Government approval/authorization and notification to the COR prior to any travel. The contractor shall be responsible for all travel and the associated travel costs to meet the requirements of this PWS, including any travel to other Government facilities or other contractor facilities that may be required during the performance of this contract or any TOs issued thereunder. If a CLIN allows for travel that is required to support Government approved surge requirements, the travel shall be approved in advance by the Government and shall be on a reimbursable cost basis. The COR must approve ALL travel prior to travel occurring. All contractor travel required to support
Government approved requirements shall be requested through the COR a minimum of
15 calendar days prior to the start date for travel and shall identify all costs associated with the proposed travel that are allowable under FAR Part 31. The Government will not reimburse the contractor for travel costs incurred beyond funding obligated in each TO.
The contractor shall prepare a report for all Government funded travel undertaken by the contractor on any TO for services issued under the SATOC in accordance with CDRL
B003 - Trip Travel Report within five (5) working days after each approved travel. The data deliverable shall be generated and delivered to the Government for reportable events in accordance with the specific performance requirements that accompany each individual TO for services issued under the SATOC.
CDRL B003: DI‐MISC‐81943 Trip/Travel Report
1.6.12.1 Travel Policy
Travel required for tasks assigned under this contract will be governed in accordance with: Federal Travel Regulations, prescribed by the General Services Administration for travel in the contiguous 48 United States, (hereinafter the FTR); Joint Travel Regulation, Volume 2, DoD Civilian Personnel, Appendix A, prescribed by the Department of
Defense, for travel in Alaska, Hawaii, the Commonwealth of Puerto Rico, and territories and possessions of the United States (hereinafter the JTR); and Standardized Regulations
(Government Civilians, Foreign Areas), Section 925, "Maximum Travel Per Diem
Allowances for Foreign Areas," prescribed by the Department of State, for travel in areas not covered in the FTR or JTR. Foreign travel may be required during performance under this SATOC. The requirements for DoD contractor personnel traveling overseas are specified in the DoD Foreign Clearance Manual located at https://www.fcg.pentagon.mil/fcg.cfm. All contractor personnel travel to OCONUS locations will be in accordance with the DoD Foreign Clearance Manual to include http://www.fcg.pentagon.mil/fcg.cfm http://www.fcg.pentagon.mil/fcg.cfm country, theater, and special area clearance requirements as applicable. In addition, contractor personnel required to travel to OCONUS locations shall meet all prescribed training requirements set forth in the then-current edition of the DoD Foreign Clearance
Manual. Contractor personnel are not eligible for no‐fee passports even for DoD‐ sponsored travel. Contractor personnel will travel on the same fee passports as tourists.
Contractor personnel shall obtain those passports from the Department of State at no cost to the US Government.
1.6.13 Other Direct Costs
This category includes travel (outlined in 1.6.12), reproduction, shipping expenses, procurement of hardware, software, firmware, and other information technology. It could also entail the renting of suitable training and cyber vulnerabilities research venues, and the procurement of information technology, hardware, software, and firmware that is required to perform the specific tasks identified in any TO issued under this SATOC.
1.6.14 Data Rights
Government’s data rights are preserved in the DFARS Part 227 clauses that are incorporated into the CVR solicitation and contract.
1.6.15 Organizational Conflict of Interest
Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR
Subpart 9.5. The contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such
OCI. The contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the
Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the contractor from participation in subsequent contracted requirements which may be affected by the OCI.
1.6.16 Phase In/Phase Out Period
To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the contractor shall have personnel on board, during the phase in period, which is the first 30 days after contract award. The contractor shall have personnel available to answer the Government’s questions and concerns during the phase out period, which is the last 30 days of the contract. During the phase in period, the contractor shall become familiar with performance requirements in order to commence full performance of services on the contract start date, which is the first day after the phase in period ends.
1.6.17 Government Extended Off-Site Working Conditions
If it appears likely that Government personnel will be furloughed, the contractor shall contact the Contracting Officer or the COR to receive direction. It is the Government's decision as to whether the contract performance and price will be affected as a result of the furlough of Government employees or a Government shutdown. In the event that furloughed Government employees or a Government shutdown affects the direct cost or direct pricing of the contract, the contractor may submit a Request for Equitable
Adjustment (REA) in accordance with DFARS clause 252.243-7002 and will first communicate with and provide its formal REA submission directly to the Contracting
Officer. Generally, the following situations apply:
(1) Contractor personnel that are able to continue contract performance (either on-site or at a site other than their normal work location) shall continue to work, provided that there is sufficient funding on any TO issued under the contract, and the contract price will not be adjusted.
(2) Contractor personnel that are not able to continue contract performance (either on-site or at a site other than their normal work location) may be asked to stop work, and the contract price may be adjusted.
1.6.18 Dress and Conduct
Contractor personnel shall dress in a manner consistent with the task for which hired and while work is being performed in Government owned or controlled space(s). In most cases, “business casual” is appropriate. Clothing must not be excessively revealing, worn out, ill‐fitting, or offensive and disrespectful of federal or local Government and policy.
Moreover, clothing and shoes shall conform to safety regulations. The contractor shall also bear all costs to obtain all safety equipment for personnel. Furthermore, the contractor shall always present a professional demeanor while performing on this contract. Behavior that is disruptive, unsafe, disrespectful, offensive, or detrimental to morale shall not be tolerated. The contractor shall ensure that its personnel do not allow personal business to interfere with job performance, nor use Government resources for personal business.
1.6.19 Program Management
The contractor shall designate one of the Key Personnel as the primary Point of Contact
(POC) who will be responsible for all program management activities for the contract.
The designated POC shall plan, organize, manage, schedule, implement, control, analyze, and report on all elements of contract performance. The designated POC shall be prepared to present and discuss with the Program Manager, Marine Corps Cyber
Operations (PM MCCO), Contracting Officer, and COR the status of contract activities, requirements, and issues. The designated POC shall also be responsible for assessing requirements changes and implementing approved changes, as authorized by the
Contracting Officer. In the absence of the designated POC, the contractor shall designate an alternate POC to serve in the designated POC’s place.
In addition, the contractor shall designate one of its employees as the Task Order
Manager (TOM) for all TOs issued under this SATOC, who has appropriate qualifications, and who has corporate decision-making authority to effectively and rapidly respond to each TO’s requirements. The TOM shall be the principal point of contact between the contractor, the Contracting Officer and COR for all administrative and technical requirements for each TO issued. The contractor shall determine where the
TOM will be geographically located based on their assessment of how to best satisfy the
Government’s service requirements for each TO issued. The contractor shall exercise its judgment when determining whether or not a single individual can perform the functions of primary, contract-level POC in addition to the responsibilities of a TOM.
In cases where the places of performance under a single TO are geographically dislocated, the contractor shall designate a Site Manager for each installation who shall be responsible for the performance of work at that installation and who has appropriate corporate decision-making authority to effectively respond to TO requirements.
However, unless specified in the TO, the designated Site Manager is not required to be physically located at each site. The contractor shall exercise its discretion when determining whether the duties of the Site Manager shall be full time.
1.6.20 Business Relations
The contractor shall coordinate all activities needed to execute the requirements contained herein and in any TO.
1.6.20.1 Cooperation
While it is not planned, there may be instances in which more than one contractor is required to work on the same base/location. In such instances, it is the expectation of the
Government that the contractor extends basic professional courtesy and collaborative interaction. Should an issue arise, the contractor shall reach a mutual agreement without the assistance of the Government. In the event that the contractors cannot resolve an issue, it is the responsibility of the contractor to promptly notify the Contracting Officer in writing and furnish recommendations for a solution. The contractor shall not be relieved of its obligations under the SATOC (and any corresponding TO) or be entitled to any other adjustment because of failure to promptly refer matters to the Contracting
Officer or failure to implement the Contracting Officer’s direction. The contractor is not relieved of any contract requirements or entitled to any adjustments to the contract terms or price because of a failure to resolve a disagreement with another contractor unless the contractor provides prior notice to the Contracting Officer and proof to the Contracting
Officer that the failure to resolve was not due to the contractor’s negligence, fault, failure to cooperate, or failure to perform its obligations in good faith.
Should Contracting Officer intervention be required, the Government reserves the right to terminate the TO for convenience at no cost to the Government.
1.6.20.2 Constructive Changes
No modification, statement, or conduct of Government personnel who might visit the contractor’s facility or in any other manner communicate with contractor personnel during the performance of this contract will constitute a change under the “Changes” clause of this contract. No understanding or agreement, contract modification, change order, or other matter deviating from or constituting an alteration or change of the terms of the contract will be effective or binding upon the Government unless formalized by contractual documents executed by the Contracting Officer.
The Contracting Officer is the only person authorized to approve changes in the requirements of this contract, and, notwithstanding provisions contained elsewhere in the contract, the said authority remains solely with the Contracting Officer. In the event that the contractor effects any change(s) at the direction of any person other than the
Contracting Officer, these change(s) will be at the contractor’s expense. No adjustment will be made in the contract price or other contract terms and conditions, as the
Contracting Officer did not approve consideration for the unauthorized change. Further, should the unauthorized change be to the Government’s detriment, the contractor may be held financially responsible for its correction.
1.6.20.3 Contractor Responsibility to Subcontractors
The contractor shall provide the technology processes, test procedures, data, drawings, and other information required to facilitate competition to the fullest extent feasible and ensure performance by selected subcontractors. The contractor shall be fully responsible for ensuring that all appropriate contractual provisions and clauses are flowed down to its subcontractors and that those provisions are enforced.
1.6.21 Task Orders
TOs for services or work described herein may be issued by the Contracting Officer at…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .