DRAFT PWS 3 Tabo 2027 XT.CIO.CS_DC3.pdf

PDF 418 KB Posted

Attached to
RFI Amendment 2: Request for Information DC3 Technical, Analytical, and Business Operations (TABO) Federal contract opportunity
Solicitation number
FA701427DXXXX
Issued by
Department of the Air Force Headquarters District Washington

About this file

This is a Performance Work Statement (PWS) for the Department of Defense Cyber Crime Center (DC3), detailing comprehensive information technology, cybersecurity, and program management support services. The contract covers an anticipated 12-month base period with four 12-month option periods, located at 911 Elkridge Landing Road in Linthicum Heights, MD. The PWS outlines 11 primary tasks including strategic support, project planning, DevSecOps, infrastructure development, data management, artificial intelligence/machine learning, operational support, research and development, cybersecurity, and program management.

Key objectives include implementing a robust DevSecOps framework, providing enterprise IT strategic initiatives, managing cybersecurity operations, developing global hybrid cloud infrastructure, and supporting DC3's mission-critical capabilities. The contractor will be responsible for tasks such as maintaining IT project governance, conducting vulnerability assessments, operating a Security Operations Center, performing threat hunting, developing AI/ML models, and providing comprehensive operational support. Performance will be measured against specific service summary objectives, including maintaining system availability, meeting cybersecurity compliance requirements, and ensuring effective program management with regular reporting and risk mitigation.

View the file

Other files for this federal contract opportunity

Other files attached to RFI Amendment 2: Request for Information DC3 Technical, Analytical, and Business Operations (TABO), newest first.
File Type Posted
DC3 TABO RFI QA.pdf PDF
PWS 1 Tabo 2027 OED_CFL.DC3_1.7.26_REV1.pdf PDF
PWS 3 Tabo 2027 XT.CIO.CS_DC3_1.7.26_REV1.pdf PDF
PWS 4 Tabo 2027 ER_XE.DC3_1.7.26_REV1.pdf PDF
PWS 2 Tabo 2027 DCISE_VDP.DC3_1.7.26_REV1.pdf PDF
PWS 5 Tabo 2027 Sec_HR_JA.DC3_1.7.26_REV1.pdf PDF
DRAFT PWS 1 Tabo 2027 OED_CFL.DC3.pdf PDF
DRAFT PWS 5 Tabo 2027 Sec_HR_JA.DC3.pdf PDF
DRAFT PWS 2 Tabo 2027 DCISE_VDP.DC3.pdf PDF
DRAFT PWS 4 Tabo 2027 ER_XE.DC3.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CUI FA7014‐XX-X-XXXX

CUI

PERFORMANCE WORK STATEMENT

FOR

Information Technology (XT) Chief Information Officer (CIO)

Cybersecurity (CS)

AT

Department of Defense Cyber Crime Center (DC3)

23 December 2025

DRAFT

Controlled by: AFDW/PK CUI Categories: PROCURE Distribution/Dissemination Controls:

FEDCON AFTER AWARD

POC: Ulrike Powell

Contents

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 GENERAL

1.2 SCOPE

1.3 BACKGROUND

SECTION II

2.0 Tasks

2.1 TASK 1 – STRATEGY SUPPORT

2.2 TASK 2 – PROJECT PLANNING

2.4 TASK 4 – DEVELOPMENT, SECURITY AND OPERATIONS (DEVSECOPS)

2.6 TASK 6 – MANAGEMENT and INTELLIGENCE

2.7 TASK 7 – ARTIFICAL INTELLIGENCE AND MACHINE LEARNING

2.8 TASK 8 – OPERATIONAL SUPPORT

2.9 TASK 9 – RESEARCH and DEVELOPMENT

2.10 TASK 10 – CYBER SECURITY

2.11 TASK 11 – PROGRAM MANAGEMENT

SECTION III

3.0 SERVICE SUMMARY

SECTION IV

4.0 DELIVERABLES

4.1 DELIVERABLES MEDIA

4.2 PLACE(S) OF DELIVERY

4.3 BASIS OF ACCEPTANCE

4.4 DRAFT DELIVERABLES

4.5 WRITTEN ACCEPTANCE/REJECTION BY THE GOVERNMENT

4.6 MARKINGS

4.7 NON-CONFORMING PRODUCTS OR SERVICES

4.8 NOTICE REGARDING LATE DELIVERY/PROBLEM NOTIFICATION REPORT

(PNR) 34

SECTION V

5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,

INFORMATION, OR SERVICES

5.1 GOVERNMENT FURNISHED EQUIPMENT (GFE)

5.2 GOVERNMENT-FURNISHED INFORMATION (GFI)

5.3 FACILITIES ACCESS AND RESOURCE USAGE

5.4 CONTRACTOR FURNISHED ITEMS AND SERVICES

5.5 CONTRACTOR FURNISHED DATA

SECTION VI

6.0 GENERAL INFORMATION

6.1 PERIOD OF PERFORMANCE

6.2 PLACE OF PERFORMANCE

6.3 PERFORMANCE SCHEDULE

6.4 TRAVEL

6.5 QUALITY CONTROL

6.6 EMERGENCY OPERATIONS/MISSION ESSENTIAL PERSONNEL

6.7 SYSTEM FOR AWARD MANAGEMENT (FORMERLY CMRA)

6.8 SECURITY INSTRUCTIONS

6.11 MISCELLANEOUS PARAGRAPHS

SECTION VII

APPENDIX A – SUMMARY OF THE PWS

A1 – Overall Summary

A2 – Summary of Requirements by Task

APPENDIX B – GLOSSARY of KEY TERMS

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 GENERAL

The Department of Defense (DoD) Cyber Crime Center (DC3) Information Technology (XT), Chief Information Officer (CIO) Directorate is responsible for a full range of functional and technical services to include, but not limited to onsite technical support, critical infrastructure preventative maintenance, vendor support, and warranty coverage to support its information technology (IT) / CIO services at the DC3 buildings specified in the scope below. This performance work statement (PWS) establishes the requirements for contractor services in support of the DC3 XT/CIO Directorate.

The DC3 Cybersecurity (CS) Directorate actively protects IT assets, systems, and networks from cyber threats at the DC3 facilities specified below. This PWS outlines the requirements for contractor services that will augment and enhance the DC3 CS Directorate's defensive capabilities.

1.2 SCOPE

The Contractor shall provide comprehensive support to the DC3 XT/CIO and CS Directorates, aligning with the program’s mission to manage, maintain, and secure DC3's IT infrastructure.

The XT/CIO Directorate is responsible for overseeing DC3’s computer systems, networks, and data, ensuring seamless operation and alignment with strategic objectives, while the CS Directorate has fiduciary oversight of cybersecurity, protecting the IT infrastructure through the full lifecycle of threat management, which encompasses developing policies, implementing coordinated defenses, and disseminating actionable intelligence. Contractor services shall include furnishing all personnel, equipment, materials, and services necessary to perform the outlined tasks at DC3 facilities located at 911 Elkridge Landing Road and 1306 Concourse Drive in Linthicum Heights, MD. Deliverables will involve providing highly qualified personnel to meet stringent operational requirements and support the mission-critical operations of both Directorates as detailed in the Performance Work Statement (PWS). Through the fulfillment of these tasks, the Contractor shall address overarching goals of maintaining operational readiness and strengthening cybersecurity defenses as defined in the scope of this procurement.

1.3 BACKGROUND

The Department of Defense (DoD) Cyber Crime Center (DC3) Information Technology (XT)/CIO Directorate requires comprehensive contractor services to ensure the effective operation, maintenance, and enhancement of its IT infrastructure across the DC3 facilities. This Performance Work Statement (PWS) defines the Contractor’s responsibilities for delivering a broad array of tailored functional and technical support services. The Contractor shall provide onsite technical support, perform critical infrastructure preventative maintenance, ensure adherence to vendor service agreements, and manage warranty coverage to sustain and improve IT operational capabilities. Additionally, under the DC3 Cybersecurity (CS) Directorate’s purview, the Contractor shall deliver advanced cybersecurity services designed to detect, mitigate, and prevent emerging cyber threats. These services will include implementing innovative defense measures, threat monitoring, incident response, vulnerability management, and compliance assurance with applicable cybersecurity regulations, such as the Federal Information Security Modernization Act (FISMA) and DoW-specific cybersecurity frameworks.

Through the combined delivery of IT and cybersecurity support services, the Contractor shall play an integral role in fortifying the DC3’s IT ecosystem, minimizing operational disruptions, and safeguarding mission-critical systems and data against evolving threats. The overarching goal is to ensure a resilient and secure IT environment that underpins the DC3’s ability to meet its mission of protecting U.S. interests in cyberspace.

SECTION II

2.0 Tasks

The following tasks are in support of this contract:

• Task 1 – Strategy Support

• Task 2 – Project Planning

• Task 3 – General Directorate Support

• Task 4 – Development, Security and Operations (DevSecOps)

• Task 5 – Global Hybrid Cloud / Infrastructure Development

• Task 6 – Management and Intelligence

• Task 7 – Artificial Intelligence and Machine Learning (AI/ML)

• Task 8 – Operational Support

• Task 9 – Research and Development

• Task 10 – Cyber Security

• Task 11 – Program Management

Note 1: Tasks 1-9 are XT and CIO specific. Task 10 is CS specific. Task 11 pertains to XT, CIO and CS.

2.1 TASK 1 – STRATEGY SUPPORT

The Contractor shall provide strategic portfolio management to DC3, driving successful execution of enterprise IT & cybersecurity initiatives.

2.1.1 SUBTASK 1 – ENTERPRISE STRATEGY

2.1.1.1 The Contractor shall develop, maintain, and align all IT enterprise strategic initiatives, to include portfolio/acquisition strategies and associated roadmaps. These initiatives must be directly synchronized with the DC3 mission and priorities and adhere to all relevant cyber frameworks.

2.1.1.2 Develop, maintain, and execute DC3's enterprise IT architecture, cloud computing strategy, and enterprise data strategy in full alignment with the DC3 mission.

2.1.1.3 Manage and provide governance for DC3 enterprise portfolios by establishing and maintaining well-defined portfolio structures, formalizing all related processes, and implementing clear reporting and communication mechanisms.

2.1.1.4 Optimize the allocation of IT enterprise resources and manage program dependencies through comprehensive, data-driven analysis, such as conducting cost-benefit analyses, to inform build/buy decisions.

2.1.2 SUBTASK 2 – MAINTAIN INTERNAL AND EXTERNAL COLLABORATION

2.1.2.1 The Contractor shall facilitate internal and external communication and collaboration, including coordinating with external agencies to identify and integrate cutting-edge technologies and implementing a comprehensive strategy for external partnerships. This communication and collaboration will be presented monthly in the Strategic Communications Plan. (Section 4, Deliverable 1).

2.2 TASK 2 – PROJECT PLANNING

The Contractor shall provide extensive support for DC3's enterprise IT architecture, ensuring alignment with the DC3 mission.

2.2.1 SUBTASK 1 – PROJECT GOVERNANCE

2.2.1.1 The Contractor shall establish and maintain all IT project governance structures and provide comprehensive support services for project management, including planning, performance tracking, status reporting, and roadmap development.

2.2.1.2 Lead and manage all aspects of the IT and Cybersecurity project lifecycle, including feasibility studies, stakeholder management, risk management, and benefits realization.

2.2.1.3 Manage all incoming IT and Cybersecurity projects requirements from internal and external customers, including review, documentation, analysis, and stakeholder communication.

2.2.2 SUBTASK 2 – PROJECT EXECUTION

2.2.2.1 The Contractor shall be responsible for key project planning and execution activities, including developing stakeholder communication and project management plans, managing resources, and analyzing COTS/GOTS solutions.

2.3 TASK 3 – GENERAL DIRECTORATE SUPPORT

The Contractor shall provide integrated technical and operational support for DC3 to enable mission-critical capabilities.

2.3.1 SUBTASK 1 – USER SUPPORT

2.3.1.1 The Contractor shall enable and support the implementation of DoW Enterprise Identity, Credential, and Access Management (ICAM) capabilities and support the development of legally compliant, data-driven operations.

2.3.1.2 Provide inclusive user support services, including user onboarding, training, Tier 1 and 2 support, system monitoring, and knowledge management.

2.3.2 SUBTASK 2 – SECURE OPERATIONS

2.3.2.1 The Contractor shall ensure secure and compliant system operations by developing and enforcing Standard Operating Procedures (SOPs), implementing data governance, providing DevSecOps support, and executing a proactive vulnerability management program.

2.3.3 SUBTASK 3 – LIFECYCLE MANAGEMENT & CONTINUITY OF OPERATIONS

2.3.3.1 The Contractor shall be responsible for the full lifecycle management of all DC3 systems

(classified and unclassified), including maintaining a system inventory, providing ongoing development and support, and facilitating system integration via APIs.

2.3.3.2 Draft development and testing of COOP plans, providing subject matter expertise to ensure system recovery procedures are defined, documented, and validated continuously.

2.4 TASK 4 – DEVELOPMENT, SECURITY AND OPERATIONS (DEVSECOPS)

The Contractor shall implement and maintain an advanced and secure Development, Security and Operations (DevSecOps) support environment for DC3.

2.4.1 SUBTASK 1 – DevSecOps STRATEGY

2.4.1.1 The Contractor shall implement and adhere to the DOW-approved DevSecOps strategy for the development, maintenance, and execution of DC3's enterprise IT architecture, cloud computing, and data strategy

2.4.1.2 Adhere to government-approved DevSecOps cultural principles, policies, methodologies, and processes for all development and operational work on DC3 data and systems.

2.4.1.3 Create and manage CI/CD pipelines for infrastructure and applications, implementing security guardrails in line with government-defined DoW compliance requirements.

2.4.2 SUBTASK 2 – DevSecOps IMPLEMENTATION

2.4.2.1 The Contractor shall implement and maintain infrastructure and applications utilizing Infrastructure as Code (IaC) and Configuration as Code (CaC) technologies, in accordance with government-approved designs.

2.4.2.2 Implement and operate systems for continuous monitoring, observability, alerting, and reporting on the availability and cybersecurity of systems, providing data and status updates to government personnel.

2.4.2.3 Implement and manage technical mechanisms for data tagging and attribution across all resources in accordance with the government-approved data governance policy.

2.4.2.4 Implement and operate a configuration management system. Document and track all system and software configuration changes in accordance with the government-approved

Configuration Management Plan.

2.4.2.5 Incorporate and automate government-specified cybersecurity controls and guardrails into all CI/CD pipelines.

2.4.2.6 Implement technical controls to enforce government-defined boundaries. Support the maintenance of Authority to Operate (ATO) packages by providing all necessary technical evidence, documentation, and continuous monitoring data.

2.4.3 SUBTASK 3 – DevSecOps DEVELOPMENT

2.4.3.1 The Contractor shall Develop and maintain automation scripts (Section 4, Deliverable 2) to apply Security Technical Implementation Guides (STIGs) and to generate and update network diagrams and system configurations based on the live environment.

2.4.3.2 Develop and manage CI/CD pipeline artifacts to maintain consistency across on-premises, cloud, and hybrid networks, as specified by the government enterprise architecture.

2.4.3.3 Conduct software solution development, integration, and testing. Prepare solutions for deployment upon government review and authorization. Implement tools and processes to provide visibility and traceability throughout the software lifecycle.

2.4.4 SUBTASK 4 – DevSecOps EFFECIENCY

2.4.4.1 Research, test, and recommend the incorporation of Agentic AI and other AI capabilities into CI/CD pipelines. Upon government approval, integrate these capabilities to improve efficiency and speed.

2.4.4.2 Provide technical support for incident response activities by executing government-approved procedures, providing system data and logs, and implementing corrective actions as directed by the government lead.

2.4.4.3 Support the government's automated via CI/CD pipelines vulnerability management program by conducting regular scans, providing analysis of findings, recommending remediation actions, and implementing patches as directed.

2.5 TASK 5 – GLOBAL HYBRID CLOUD / INFRASTRUCTURE DEVELOPMENT

The Contractor shall deliver expert-level global IT infrastructure support to DC3, encompassing network administration, server management, cloud services, cybersecurity, and incident response to ensure a resilient and secure environment.

2.5.1 SUBTASK 1 – IMPLEMENTATION

2.5.1.1 The Contractor shall implement and adhere to government-approved DevSecOps processes to maintain Cloud and On-premises Infrastructures.

2.5.1.2 Implement and operate multiple impact levels across unclassified and classified environments in accordance with government-approved security architecture and designs.

2.5.1.3 Implement and operate logging mechanisms across all ATO boundaries in accordance with the government-approved logging and monitoring plan.

2.5.1.4 Implement and manage systems for continuous monitoring and observability on all resources, to include configuring alerts and generating performance reports for government review.

2.5.1.5 Implement and maintain government-approved Cross Domain Solutions across all specified security levels.

2.5.1.6 Support the deployment and integration of Cybersecurity Service Provider (CSSP) capabilities and implement technical controls required for DoW compliance.

2.5.2 SUBTASK 2 – DEVELOPMENT

2.5.2.1 Develop seamless integration between on-premises and cloud environments, utilize cloud technologies (e.g., edge computing) to support DC3 mission requirements, and implement cross domain solutions across all security levels.

2.5.2.2 Develop and maintain technical solutions to provide seamless integration between on-premises and cloud environments based on government-approved architecture.

2.5.2.3 Develop and maintain comprehensive documentation of technical designs and as-built architectures (Design and As-built Report) for government review and records (Section 4, Deliverable 3).

2.5.2.4 Develop and deliver user manuals and training materials for government-approved systems and tools (Section 4, Deliverable 4).

2.5.3 SUBTASK 3 – SUPPORT

2.5.3.1 Support the maintenance of appropriate Impact Level (IL) Authority to Operate (ATO) boundaries by implementing and documenting technical controls and providing continuous monitoring data for all discrete environments.

2.5.3.2 Support global DC3 mission objectives by providing resilient, global infrastructure services across on-premises, hybrid, and cloud networks. Provide subject matter expertise consistent with "Executive Cyber Leader," "Enterprise Architect," "IT Investment/Portfolio Management," "Software/Cloud Architect" and/or similar Cyber Work roles defined under DoDI 8140.

2.5.3.3 Provide technical and operational support for all designated DC3 network environments, including CONUS and OCONUS locations.

2.5.3.4 Adhere to and comply with all applicable Task Orders (TOs), Cyber Tasking Orders

(CTOs), and other binding directives, and provide documentation of compliance to the government lead.

2.5.3.5 Utilize cloud technologies, including edge computing, to support the execution of DC3 mission requirements as directed by the Government.

2.6 TASK 6 – MANAGEMENT and INTELLIGENCE

The Contractor shall establish and maintain an enterprise-wide data governance framework for DC3, ensuring data quality, security, interoperability, and compliance with Information Management, Knowledge Management and Records Management (IM/KM/RM).

2.6.1 SUBTASK 1 – DATA MANAGEMENT (DM)

2.6.1.1 Develop and recommend a data governance framework for government review and approval that aligns with the requirements of DC3 and its mission partners.

2.6.1.2 Draft and propose interoperable data standards and policies for government review and promulgation.

2.6.1.3 Implement, operate, and maintain a system for data tagging and metadata management in accordance with government-approved standards and policies.

2.6.1.4 Design, implement, and manage data quality monitoring and remediation processes, providing regular reports and performance metrics to the government lead.

2.6.1.5 Implement and maintain data security and access controls using DevSecOps methodologies, as specified in the government-approved system security plan

2.6.1.6 Develop training materials and conduct user training on government-approved data governance and data management procedures.

2.6.1.7 Continuously monitor the effectiveness of the data governance framework and provide actionable recommendations for improvement to government officials for their consideration and decision.

2.6.2 SUBTASK 2 – BUSINESS INTELLIGENCE (BI)

2.6.2.1 Facilitate stakeholder workshops to gather and document business requirements. Propose and recommend key business questions and KPIs for government review and final approval.

2.6.2.2 Conduct an assessment of existing infrastructure and data sources to create a detailed inventory. Analyze and report on the current state, including capabilities and gaps, for government review.

2.6.2.3 Develop and propose a detailed design for the business intelligence architecture, including ETL processes, data structures, and reporting platforms, based on government-approved requirements.

2.6.2.4 Build, configure, and implement the data warehouse/data lake environment in accordance with the government-approved design and data model.

2.6.2.5 Develop and configure reports and interactive dashboards to visualize data and track performance against government-approved KPIs and business questions.

2.6.2.6 Develop, test, and deploy the BI environment using automated pipelines. Continuously monitor the health and performance of the environment, providing regular status reports and alerts to the government lead.

2.6.3 SUBTASK 3 – MISSION INTELLIGENCE (MI):

2.6.3.1 Provide technical support to implement and maintain data-sharing interfaces and interoperability solutions as defined in government-to-government agreements.

2.6.3.2 Develop, document, test, and maintain Application Programming Interfaces (APIs) based on government-approved requirements and inter-agency data sharing agreements.

2.6.3.3 Implement and optimize technical solutions and automated processes designed to accelerate data exchange, in accordance with the terms specified in government-established inter-agency sharing agreements.

2.6.3.4 Develop reports and queries that fuse data from authorized external agency sources, as specified and permitted by government-established data sharing agreements and security policies.

2.6.4 SUBTASK 4 – RECORDS MANAGEMENT (RM):

2.6.4.1 Provide technical and analytical support for the development of an IM/KM/RM capability. Implement and maintain the capability in accordance with government-approved plans.

2.6.4.2 Draft, document, and maintain Standard Operating Procedures (SOPs) for the

IM/KM/RM capability for government review and final approval.

2.6.4.3 Assist in the development and coordination of DC3 publications and forms. Prepare documents for government review, final approval, and official publication.

2.6.4.4 Draft and recommend records management policies and updates for government review, consideration, and final promulgation.

2.6.4.5 Identify official records and propose classifications in accordance with the government-approved records control schedule and disposition instructions.

2.6.4.6 Implement, configure, and manage a technical system for tagging records according to the government-approved classification schema and policies.

2.6.4.7 Draft and document detailed records management procedures for government review and approval to ensure they align with official policy.

2.6.4.8 Implement and execute the government-approved records retention and disposition schedules, ensuring compliance with NARA-approved instructions.

2.6.4.9 Develop training materials and conduct user training on government-approved records management policies and procedures.

2.6.4.10 Monitor compliance with records management procedures and conduct audits as directed. Report findings and recommendations to the government lead for action.

2.6.4.11 Provide technical services to train and evaluate AI models to support records management functions, using government-furnished data in accordance with government-approved guidelines.

2.6.5 SUBTASK 5 – KNOWLEDGE MANAGEMENT (KM):

2.6.5.1 Draft and recommend a knowledge management strategy, including goals and performance metrics, for government review and final approval.

2.6.5.2 Design, build, and implement a knowledge repository based on government-approved requirements and architectural standards.

2.6.5.3 Develop and maintain technical capabilities for capturing and disseminating knowledge in accordance with government-approved policies and procedures.

2.6.5.4 Develop and configure dashboards to provide insights and track performance metrics based on government-defined Key Performance Indicators (KPIs).

2.6.5.5 Develop and maintain automated workflows that aggregate data from multiple BI tools to generate reports and alerts for government personnel, providing information to support their decision-making process.

2.6.5.6 Develop training materials and conduct user training on the government-approved knowledge management systems, policies, and procedures.

2.6.5.7 Maintain and regularly update the content of the knowledge base and FAQs using government-approved information and sources.

2.6.5.8 Monitor the technical health, performance, and usage of the knowledge management systems. Perform routine maintenance and provide regular reports to the government lead

2.6.5.9 Provide technical services to train, test, and evaluate AI models to support knowledge management functions, using government-furnished data in accordance with government-approved guidelines and objectives.

2.7 TASK 7 – ARTIFICAL INTELLIGENCE AND MACHINE LEARNING

The Contractor shall provide driving support for DC3's enterprise architecture, hybrid cloud computing, data strategy, and Artificial Intelligence/Machine Learning (AI/ML) initiatives.

2.7.1 SUBTASK 1 – ARTIFICIAL INTELLIGENCE

2.7.1.1 Conduct research to identify potential AI use cases that could support DC3 business goals. Provide a detailed analysis and formal recommendations for government review and prioritization.

2.7.1.2 Conduct a technical assessment of AI data readiness and infrastructure. Report on findings regarding data availability, quality, and accessibility, and provide recommendations for remediation to the Government.

2.7.1.3 Develop all AI models in strict adherence to government-approved data governance policies and enterprise architecture. Provide documentation and evidence of compliance as part of the development lifecycle.

2.7.1.4 Develop, test, and validate AI models against government-defined requirements.

Following government review and formal acceptance, deploy the models into the operational environment. Continuously monitor model performance and health, providing regular reports to the government lead.

2.7.2 SUBTASK 2 – MACHINE LEARNING

2.7.1.1 Assist Government stakeholders in identifying and documenting specific business problems. Propose and recommend potential machine learning objectives for government review and final approval.

2.7.1.2 Gather, process, and prepare data from government-approved sources for model training, performing data cleaning, transformation, and feature engineering as required.

2.7.1.3 Conduct research and analysis on various machine learning models. Provide a comparative analysis and data-driven recommendation for the most suitable model(s) for government review and selection.

2.7.1.4 Train, test, and tune the government-selected machine learning model(s) using the prepared data, with the objective of meeting government-defined performance metrics and mission goals.

2.7.1.5 Develop, test, and deploy the machine learning models into the operational environment following government review and formal acceptance. Continuously monitor model performance and health, providing regular reports to the government lead.

2.7.1.6 Implement and adhere to DevSecOps processes and methodologies throughout the model lifecycle to ensure comprehensive documentation, version control, and audibility of all machine learning assets.

2.8 TASK 8 – OPERATIONAL SUPPORT

The Contractor shall provide uninterrupted 12X5 global operational support for all DC3 systems, encompassing a resilient Network Operations Center (NOC) and Security Operations Center (SOC) capability.

2.8.1 SUBTASK 1 – SERVICE DESK SUPPORT

2.8.1.1 Provide System, Application, Infrastructure, and Telecommunications assistance and

Service Desk Support (12X5).

2.8.1.2 Provide Tier 0, Tier 1, and Tier 2 Service Desk Support for all designated systems and services.

2.8.1.3 Develop and maintain Troubleshooting Guides and Standard Operating Procedures

(SOPs) for government review and approval to improve Tier 0, Tier 1, and Tier 2 support.

2.8.1.4 Respond to, document, and track all incidents and service requests in the government-approved ticketing system.

2.8.1.5 Collect and report on Service Desk performance metrics as defined by the Government.

2.8.1.6 Perform ticket triaging and routing of all service desk requests to the appropriate support teams.

2.8.1.7 Manage and fulfill support requests for video and telecommunications services.

2.8.1.8 Support and fulfill service requests for applications, infrastructure, R&D, innovation, and networks.

2.8.2 SUBTASK 2 – PROCUREMENT and ASSET MANAGEMENT

2.8.2.1 Support the government's procurement process by assisting with the purchasing, receiving, tracking, distributing, and accounting of DC3 hardware and software requirements.

2.8.2.2 Create, manage, and maintain a DC3 Hardware and Software Inventory Library System, to include license details, issuance data, Points of Contact (PoCs), and vendor support contract information.

2.8.2.3 Document and regularly update the Total Cost of Operations (TCO) for all DC3 hardware and software assets, and report this information to the Government.

2.8.2.4 Ensure asset information within the inventory system is accurate and made available to authorized government personnel on demand.

2.8.2.5 Implement and follow the government-approved plan for hardware and software supply chain risk management across all DC3 assets.

2.8.2.6 Assist the Government in developing a chargeback or show back model by identifying and providing the component costs directly associated with infrastructure, data transfer, cloud services, applications, licenses, and training.

2.8.2.7 Support financial operations (FinOps) by implementing data tagging mechanisms on DC3 hardware, software, and infrastructure to track cost allocations as directed by the Government.

2.8.3 SUBTASK 3 – DATA CENTER HOSTING

2.8.3.1 Provide hosting and maintenance of servers in a commercial-grade data center that meets all government-specified physical and environmental security requirements.

2.8.4 SUBTASK 4 – UNINTERRUPTED 12X5 GLOBAL OPERATIONAL SUPPORT

2.8.4.1 Deploy and manage updates and releases to DC3 Systems in accordance with the government-approved release schedule and procedures.

2.8.4.2 Conduct continuous system monitoring, maintain comprehensive logs, and report on performance, security, and availability to the government lead.

2.8.4.3 Provision and manage physical, virtual, and cloud servers in accordance with government-approved designs and baselines.

2.8.4.4 Deploy and manage network configurations for firewalls, routers, and switches as directed by the government and in line with approved architecture.

2.8.4.5 Support IT resource management by providing inventory data, utilization reports, and capacity planning recommendations for government review.

2.8.4.6 Deploy applications to production environments following successful testing and upon government review and authorization.

2.8.4.7 Monitor application performance and availability, reporting any degradation or outages in accordance with the Incident Response Plan.

2.8.4.8 Provision application configurations in accordance with government-approved baselines and change management procedures.

2.8.4.9 Provision user accounts and access permissions as authorized and directed by the

Government.

2.8.4.10 Monitor for security incidents and respond to alerts in accordance with the government-approved Incident Response Plan.

2.8.4.11 Provision and maintain government-approved security tools and technologies.

2.8.4.12 Adhere to all applicable regulatory requirements and internal policies, and provide documentation and evidence of compliance to the government as required.

2.8.4.13 Support the government in aligning identified networks with the Risk Management

Framework (RMF) and support the maintenance of the Authority to Operate (ATO) by providing technical evidence and documentation.

2.8.4.14 Deploy, maintain, and secure the Network Infrastructure, including routers, switches, hubs, cabling, servers, and storage, as directed.

2.8.4.15 Operate and maintain networks to achieve a minimum availability of 99.5% and report all outages in accordance with the service level agreement (SLA).

2.8.4.16 Provide data-driven recommendations to the Government for upgrades, equipment replacement, repairs, and other changes to the DC3 IT infrastructure.

2.8.4.17 Track and document all repairs, changes, additions, or removals via the government-approved DevSecOps Process.

2.8.4.18 Notify the Government of any unusual circumstances that exist beyond the contractor’s control that may prevent meeting availability service levels.

2.8.4.19 Notify designated DC3 leaders in writing within 30 minutes of any P1 incident during regular business hours (Monday through Friday, 6:00 am through 6:00 pm EST).

2.8.4.20 Provide planning, implementation, and maintenance support for infrastructure changes, including thin client, virtual environment, and cloud services.

2.8.4.21 Operate and manage an Enterprise and Security Operations Center, to include a Data

Center, on a 12X5 basis.

2.8.4.22 Provide 12X5 operational support for the Command and Control (C2) Ops Center, including monitoring and initial response capabilities as defined in the Incident Response Plan.

2.9 TASK 9 – RESEARCH and DEVELOPMENT

The Contractor shall drive innovation and enhance DC3's IT technological capabilities through the development, maintenance, and integration of cutting-edge systems, expertise, and partnerships.

2.9.1 SUBTASK 1 – RESEARCH

2.9.1.1 Conduct research, feasibility studies, and technical assessments to produce analyses, reports, and data-driven recommendations that address DC3 mission requirements.

2.9.1.2 Support government-led coordination efforts with external agencies by providing technical subject matter expertise, identifying cutting-edge technologies, and making recommendations for innovation.

2.9.1.3 Participate in relevant cybercrime and forensic-related IT forums to gather information on emerging trends and technologies, and provide summaries and analyses of findings to the Government.

2.9.1.4 Conduct research on innovative technologies and capabilities, including technical collaboration with academic and industry organizations as directed by the Government.

2.9.2 SUBTASK 2 - DEVELOPMENT

2.9.2.1 Provide full lifecycle development support for systems that address DC3 directorate needs and the requirements of external partners as defined in government-to-government agreements.

2.9.2.2 Provide innovative technologies, capabilities, and subject matter expertise in technical collaboration with other organizations, as directed by the Government.

2.9.2.3 Conduct Digital and Multimedia Forensics (D/MM) software and tool development to support investigations, information sharing, incident response, and other forensic activities.

2.9.2.4 Provide ongoing operational maintenance and support for designated DC3 internal and external systems in accordance with government-approved service level agreements (SLAs).

2.9.3 SUBTASK 3 – TOOL VALIDATION

2.9.3.1 Perform independent testing and evaluation (T&E) of Commercial Off-the-Shelf (COTS) and Government Off-the-Shelf (GOTS) forensic tools against government-approved validation criteria.

2.9.3.2 Compile, document, and maintain all validation test results, procedures, and findings in a government-accessible central library.

2.10 TASK 10 – CYBER SECURITY

2.10.1 SUBTASK 1 – PENETRATION TESTING

2.10.1.1 The Contractor shall assess the security of DC3's networks and applications by simulating real-world cyberattacks.

2.10.1.2 Proactively identify and address security gaps before they can be exploited, strengthening DC3's overall security posture.

2.10.2 SUBTASK 2 – VULNERABILITY ASSESSMENT

2.10.2.1 The Contractor shall perform weekly vulnerability scans on all DC3 networks and applications using certified subject matter experts (SMEs) and industry-standard tools to identify and report vulnerabilities, and submit a Vulnerability Report using the CORA scoring model to the Government no later than 1700 EST every Friday (Section 4, Deliverable 5).

2.10.3 SUBTASK 3 – THREAT HUNTING

2.10.3.1 The Contractor shall provide a proactive and continuous security capability focused on actively searching for hidden or advanced threats within DC3's IT and Operational Technology (OT) environments.

2.10.3.2 Identify, analyze, and respond to threats, preventing significant damage or disruption.

2.10.3.3 Provide continuous monitoring and investigation of DC3's IT and OT environments to discover and investigate anomalous behavior.

2.10.3.4 Investigate the discovered anomalies to determine appropriate responses and validity of potential security incidents, ensuring a rapid and effective response to potential threats.

2.10.3.5 Submit an Anomaly Investigation Report to the Government no later than twenty-four

(24) hours of identification (Section 4, Deliverable 6).

2.10.4 SUBTASK 4 - COMPLIANCE

2.10.4.1 The Contractor shall provide certified Information System Security Officers (ISSOs) to develop and maintain Authorization to Operate (ATO) and/or Assess-Only Authorization packages for all DC3 systems, ensuring adherence to current DoD security regulations and guidelines, and submit a complete ATO and/or Assess-Only Authorization package to the Government for review and approval no less than 45 calendar days prior to the planned deployment of the system to production (Section 4, Deliverable 7).

2.10.4.2 Actively manage all applicable Orders and Taskers, implementing required changes and generating necessary documentation, including Plan of Action and Milestones (POA&Ms) when full compliance is not immediately achievable (Section 4, Deliverable 8).

2.10.5 SUBTASK 5 – INCIDENT RESPONSE

2.10.5.1 The Contractor shall provide a comprehensive incident response capability to detect, analyze, and respond to security incidents affecting DC3 networks and systems.

2.10.5.2 Investigate potential incidents and escalate confirmed incidents according to established procedures.

2.10.5.3 Perform comprehensive incident response activities, including containment, eradication, and recovery upon confirmation of a security incident.

2.10.5.4 Develop, update, and maintain DC3's Incident Response Policies and Procedures to ensure a coordinated and effective response to evolving cyber threats, and submit any necessary updates or revisions to the Government for review and approval no later than March 31st of each calendar year (Section 4, Deliverable 9).

2.10.6 SUBTASK 6 – BEST PRACTICES and INNOVATION

2.10.6.1 The Contractor shall continuously research emerging cybersecurity best practices and technologies from industry, academic, and government sources, providing the Government with well-researched and actionable recommendations for their potential implementation within DC3.

2.10.6.2 Emerging cybersecurity best practices and technology recommendations shall include analysis of benefits, risks, and implementation strategies, ensuring that DC3 remains at the forefront of cybersecurity innovation.

2.10.7 SUBTASK 7 – SECURITY OPERATIONS CENTER (SOC)

2.10.7.1 The Contractor shall establish and operate a comprehensive Security Operations Center

(SOC) to provide centralized management and coordination of DC3's defensive security operations.

2.10.7.2 The SOC will serve as the central hub for all security-related activities, including penetration testing, threat hunting, orders/taskers management, and incident response.

2.10.7.3 The Contractor shall procure and maintain all necessary tools and resources to ensure effective SOC operation, and provide continuous analysis of security events and trends to proactively identify and mitigate potential threats to the DC3 environment.

2.10.8 SUBTASK 8 – VULNERABILITY and CONFIGURATION MANAGEMENT

2.10.8.1 The Contractor to implement a comprehensive vulnerability management program to continuously identify, assess, and remediate security vulnerabilities on all DC3 systems.

2.10.8.2 Perform continuous patching and secure configuration management, to ensure compliance with DoW mandates, and actively monitoring system security posture to minimize the attack surface and reduce the risk of exploitation.

2.10.8.3 Implement an Infrastructure as Code, and a Configuration as Code process to ensure that all changes to DC3 systems are made in a centralized repository, evaluated in an automated fashion by Cybersecurity, and then deployed to production networks and applications once all Cybersecurity requirements have been met.

2.11 TASK 11 – PROGRAM MANAGEMENT

2.11.1 SUBTASK 1 – PROGRAM OVERSIGHT

2.11.1.1 The Contractor shall provide program management support. This includes the management and oversight of all activities performed by contractor personnel, including any subcontractors.

2.11.1.2 The Contractor shall identify a PM by name who shall provide management, direction, administration, quality control, and leadership to all contractor personnel and sub-contractor personnel.

2.11.1.3 PM shall ensure all IT and Cybersecurity programs align with the DC3 mission and strategic goals, including performing feasibility studies, establishing program governance, and managing the full program lifecycle.

2.11.2 SUBTASK 2 – PROGRAM MANAGEMENT PLAN (PMP)

2.11.2.1 The Contractor shall provide a PMP that documents all task/subtask requirements performed to satisfy the requirements of this PWS (Section 4, Deliverable 10).

2.11.2.2 The Contractor shall provide the Government with a draft PMP for review, modification, and approval. The final PMP shall incorporate the Government’s changes.

2.11.2.3 The PMP is an evolutionary document that shall be updated as needed to reflect changes and evolving training requirements (Section 4, Deliverable 11).

2.11.2.4 The Contractor shall work from the most current Government approved iteration of the

PMP.

2.11.2.5 The Contractor’s PMP shall, minimally:

• Describe the proposed management approach (e.g., shall proactively manage all IT program resources including personnel, cost, and infrastructure, including planning resource allocations, optimizing utilization, and preparing for surge capacity).

• Describe the contractor’s SOPs for all tasks.

• Include milestones, tasks, and subtasks required in this contract.

• Describe in detail the Contractor’s approach to risk management under this contract (e.g., shall be responsible for the development and maintenance of all essential program documentation and manage all incoming program requirements, ensuring detailed analysis and compliance).

• Describe in detail the Contractor’s approach to communications, including processes, procedures, communication approach, and other rules of engagement between the contractor and the Government (e.g., hall perform detailed analysis and technical assessment of Commercial-Off-The-Shelf (COTS) and Government-Off-The-Shelf (GOTS) solutions to facilitate informed decision-making).

• Include the current Organizational Chart and the approach to ensuring the Government is in receipt of the most current version of the Organizational Chart.

• Describe in detail the Contractor’s approach to obtaining short-term specialized expertise, when required for surge support.

• Contain stakeholder management and communication plan

2.11.3 SUBTASK 3 – RISK MANAGEMENT

2.11.3.1 The Contractor shall develop, implement, and maintain a comprehensive Risk

Management Plan (Section 4, Deliverable 12), as part of the overall PMP, for all tasks executed under this PWS.

2.11.3.2 The Contractor’s Risk Management Plan shall include, (minimally):

• Identification of risks, and the assessment of risks and their impacts, prioritization, mitigation, and control plans.

• Risk tracking, monitoring, and reporting process.

• Risk processes including the development of recovery plans in the event risks are realized.

• Escalation timelines and procedures for notifying the Government.

2.11.4 SUBTASK 4 – COMMUNICATION and MEETINGS

2.11.4.1 The Contractor shall facilitate Government and contractor communications; use industry best practices / standards and proven methodologies to track and document requirements and activities to allow for continuous monitoring and evaluation by the Government; and ensure all support and requirements performed are accomplished IAW the contract.

2.11.4.2 The Contractor shall notify the XT and CS Directors, Deputy Directors or Contracting

Officer’s Representative (COR) via a Problem Notification Report (PNR) of any technical, personnel, or general managerial problems encountered throughout the period of performance (POP) (Section 4, Deliverable 13).

2.11.5 SUBTASK 5 – CONDUCT KICKOFF MEETING

2.11.5.1 The Contractor shall schedule, coordinate, and host a Kick-Off Meeting at the location approved by the Government (Section 4, Deliverable 14) within ten (10) business days of award. The meeting shall provide an introduction between the contractor personnel and Government personnel who will be involved with the PWS. The meeting shall provide the opportunity to discuss technical, management, and security issues, and travel authorization and reporting procedures. At a minimum, the attendees shall include Key Contractor Personnel, representatives from the directorates, COR, relevant Government personnel, and the AFDW/PKA Contracting Officer (CO).

2.11.5.2 The Contractor shall, at least three-business days prior to the Kick-Off Meeting, provide a Kick-Off Meeting Agenda (Section 4, Deliverable 15) for review and approval by the XT and CS Directors and COR prior to finalizing. The agenda shall include, at a minimum, the following topics/deliverables:

• Points of Contact (POCs) for all parties.

• Personnel discussion (i.e., roles and responsibilities and lines of communication between contractor and Government).

• Staffing Plan and status.

• Transition-In Plan and discussion. This must include an update on the plan to relocate to the contractor facility and classrooms.

• Security discussion and requirements (i.e., building access, badges, Common

Access Cards (CACs), Personal Identity Verification (PIV).

• The contractor shall provide a Kick-Off Meeting Minutes Report (Section 4, Deliverable 15) documenting the Kick-Off Meeting discussion and capturing any action items.

2.11.6 SUBTASK 6 – MONTHLY STATUS REPORT (MSR)

2.11.6.1 The Contractor shall develop and provide an MSR (Section 4, Deliverable 16). The

MSR shall be presented at the Monthly Technical Status Meeting (Section 4, Deliverable 17). The MSR shall include, minimally, the following:

2.11.6.2 Activities during reporting period, by task (include ongoing activities, new activities, and activities completed, and progress to date on all above-mentioned activities). Each section shall start with a brief description of the task.

2.11.6.3 Problems and corrective actions taken as well as issues or concerns and proposed resolutions.

2.11.6.4 Personnel gains, losses, and status (e.g., out-processing, in-processing, security clearances, etc.). This shall include a copy of the latest Organizational Chart.

2.11.6.5 Government actions required.

2.11.6.6 Schedule execution and forecast reports defined during the Program Baseline Review

(show major tasks, milestones, and deliverables; planned and actual start and completion dates for each).

2.11.6.7 Summary of trips taken, conferences attended, etc. (attach Trip Reports to the MSR for reporting period).

2.11.7 SUBTASK 7 – ASSET MANAGEMENT SERVICES

2.11.7.1 The Contractor shall provide shall provide asset management on all GFE provided as a part of the PWS in accordance with DC3 policies and procedures.

2.11.8 SUBTASK 8 – GOVERNMENT REQUIRED TRAINING

The Government will provide the Contractor a list of all required training, with completion dates.

2.11.8.2 The Contractor shall successfully complete and/or attend all training identified by the

Government and use the Government’s approved system to take and record this training, primarily on Joint Knowledge Online (JKO).

2.11.8.3 The Contractor shall not directly bill the Government for any Government-required training. The type of training contemplated by this section is joint compliance training typically found in JKO or similar online DoW system.

2.11.9 SUBTASK 9 – KEY PERSONNEL

The following are the minimum personnel who shall be designated as “Key.” The Government does not intend to dictate the composition of the ideal team to perform this contract.

• Program Manager (PM)

2.11.9.1 Program Manager: The Contractor shall identify a PM by name to serve as the

Government’s primary POC. The PM shall provide overall management and oversight of all activities performed by contractor personnel, including subcontractors, to satisfy the requirements identified in this PWS. The PM shall facilitate Government and contractor communications, use industry-best standards and proven methodologies to track and document requirements and activities to allow for continuous monitoring and evaluation by the Government, and ensure all tasks are accomplished IAW this PWS.

The PM shall be responsible for the quality and efficiency of the Contractor’s performance and shall assist the Government with all financial and business processes of this PWS, excluding inherently Governmental functions. It is required that the PM has the authority to make decisions for the Contractor’s organization in response to Government issues, concerns, and comments; the authority to commit the prime Contractor’s organization; and to be proactive in alerting the Government to potential contractual or programmatic and resource limitations issues.

2.11.9.1.2 The PM is required to have the following qualifications:

• Top Secret Sensitive Compartmented Information (TS/SCI) clearance eligible.

• Project Management Professional® (PMP) certification.

• Experience within the last ten years managing a project, or program of similar size and complexity to this PWS.

• Experience within the last five years overseeing and determining manpower requirements for projects similar in size and complexity to this PWS, consisting of a diversity of technical skill sets and labor categories.

• Experience within the last five years performing financial and performance monitoring of contracts (e.g., performance metrics).

2.11.9.2 A key personnel substitution occurs when there is any person who, in an acting capacity, performs the duties of any Key Personnel temporarily (more than 30 consecutive calendar days).

2.11.9.3 The Contractor shall not replace any personnel designated as Key Personnel without the written approval of the XT and CS Director with concurrence of the CO. Prior to utilizing other than the Key Personnel specified in its proposal in response, the Contractor shall notify the XT and CS Director, CO, and COR of the existing PWS.

This notification shall be no later than ten (10) calendar days in advance of any proposed substitution and shall include justification and labor category of proposed substitution(s) in sufficient detail to permit evaluation of the impact on PWS performance. The Government will not be billed for positions left vacant over 30 calendar days unless the vacancy is due to Government delay and otherwise approved by the CO.

2.11.9.4 Substitute Key Personnel qualifications shall be equal to, or greater than, those of the

Key Personnel substituted. If the XT and CS Director, CO, and the COR determine that a proposed substitute Key Personnel is unacceptable, or that the reduction of effort would be so substantial as to impair the successful performance of the work under the contract, the Contractor may be subject to default action as prescribed by FAR 52.249-6 Termination.

2.11.9.5 For the purposes of this contract, all persons supporting this contract…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .