DRAFT PWS 5 Tabo 2027 Sec_HR_JA.DC3.pdf
PDF 428 KB Posted
- Attached to
- RFI Amendment 2: Request for Information DC3 Technical, Analytical, and Business Operations (TABO) Federal contract opportunity
- Solicitation number
- FA701427DXXXX
About this file
This Performance Work Statement (PWS) details comprehensive support services for the Department of Defense Cyber Crime Center (DC3), covering Security, Human Resources (HR), and Judge Advocate (JA) Directorates. The contract is structured around 14 key tasks with specific objectives including personnel security clearance processing, physical security management, sensitive compartmented information facility (SCIF) security operations, training and development, manpower management, legal advisory support, and digital evidence management.
The contract is for a 12-month base period with four 12-month option periods, located at 911 Elkridge Landing Road, Linthicum Heights, MD. The contractor will provide highly qualified personnel capable of meeting strict deadlines and maintaining compliance with DoD policies and intelligence community standards. Key requirements include managing personnel security clearances, conducting physical security inspections, maintaining SCIF security, developing comprehensive training programs, tracking personnel data, providing legal support, and managing digital evidence. The contractor must have a Program Manager with Top Secret/SCI clearance eligibility, Project Management Professional certification, and significant relevant experience in managing complex projects.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DC3 TABO RFI QA.pdf | ||
| PWS 1 Tabo 2027 OED_CFL.DC3_1.7.26_REV1.pdf | ||
| PWS 3 Tabo 2027 XT.CIO.CS_DC3_1.7.26_REV1.pdf | ||
| PWS 4 Tabo 2027 ER_XE.DC3_1.7.26_REV1.pdf | ||
| PWS 2 Tabo 2027 DCISE_VDP.DC3_1.7.26_REV1.pdf | ||
| PWS 5 Tabo 2027 Sec_HR_JA.DC3_1.7.26_REV1.pdf | ||
| DRAFT PWS 1 Tabo 2027 OED_CFL.DC3.pdf | ||
| DRAFT PWS 3 Tabo 2027 XT.CIO.CS_DC3.pdf | ||
| DRAFT PWS 2 Tabo 2027 DCISE_VDP.DC3.pdf | ||
| DRAFT PWS 4 Tabo 2027 ER_XE.DC3.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CUI FA7014‐XX-X-XXXX
CUI
PERFORMANCE WORK STATEMENT
FOR
Security Human Resources (HR)
Judge Advocate (JA)
AT
Department of Defense Cyber Crime Center (DC3)
23 December 2025
DRAFT
Controlled by: AFDW/PK CUI Categories: PROCURE Distribution/Dissemination Controls:
FEDCON AFTER AWARD
POC: Ulrike U. Powell
Contents
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 GENERAL
1.2 SCOPE
1.3 BACKGROUND
SECTION II
2.0 TASKS
2.1 TASK 1 – PERSONNEL CLEARANCE PROCESSING
2.2 TASK 2 – PHYSICAL SECURITY
2.3 TASK 3 – SENSITIVE COMPARTMENTED INFORMATION FACILITIES
(SCIF) 9
SECURITY OPERATIONS
2.4 TASK 4 – SECURITY PROGRAMS
2.5 TASK 5 – CONTINUITY OF OPERTIONS (COOP)
2.6 TASK 6 – SURVEY AND ASSESSMENT
2.7 TASK 7 – COMPREHENSIVE TRAINING and DEVELOPMENT PROGRAM ... 14
2.8 TASK 8 – INTEGRATED MANPOWER and POSITION MANAGEMENT
PROGRAM
2.9 TASK 9 – ADMINISTRATIVE and SUPPORT FUNCTIONS
2.10 TASK 10 – LEGAL ADVISORY and LITIGATION SUPPORT
2.11 TASK 11 – DIGITAL EVIDENCE
2.12 TASK 12 – KNOWLEDGE MANAGEMENT
2.13 TASK 13 – CUSTOMER SERVICE
2.14 TASK 14 – PROGRAM MANAGEMENT
SECTION III
3.0 SERVICE SUMMARY
SECTION IV
4.0 DELIVERABLES
4.1 DELIVERABLES MEDIA
4.2 PLACE(S) OF DELIVERY
4.3 BASIS OF ACCEPTANCE
4.4 DRAFT DELIVERABLES
4.5 WRITTEN ACCEPTANCE/REJECTION BY THE GOVERNMENT
4.6 MARKINGS
4.7 NON-CONFORMING PRODUCTS OR SERVICES
4.8 NOTICE REGARDING LATE DELIVERY/PROBLEM NOTIFICATION REPORT
(PNR) 38
SECTION V
5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,
INFORMATION, OR SERVICES
5.1 GOVERNMENT FURNISHED EQUIPMENT (GFE)
5.2 GOVERNMENT-FURNISHED INFORMATION (GFI)
5.3 FACILITIES ACCESS AND RESOURCE USAGE
5.4 CONTRACTOR FURNISHED ITEMS AND SERVICES
5.5 CONTRACTOR FURNISHED DATA
SECTION VI
6.0 GENERAL INFORMATION
6.1 PERIOD OF PERFORMANCE
6.2 PLACE OF PERFORMANCE
6.3 PERFORMANCE SCHEDULE
6.4 TRAVEL
6.5 QUALITY CONTROL
6.6 EMERGENCY OPERATIONS/MISSION ESSENTIAL PERSONNEL
6.7 SYSTEM FOR AWARD MANAGEMENT (FORMERLY CMRA)
6.8 SECURITY INSTRUCTIONS
6.9 MISCELLANEOUS PARAGRAPHS
SECTION VII
APPENDIX A – SUMMARY OF THE PWS
A1 – Overall Summary
A2 – Summary of Requirements by Task
APPENDIX B – GLOSSARY of KEY TERMS
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 GENERAL
The Department of Defense (DoD) Cyber Crime Center (DC3) Security Directorate ensures the security of all classified and sensitive assets at DC3 buildings specified in the scope below. This Performance Work Statement (PWS) establishes the requirements for Contractor services in support of the DC3 Security Directorate.
The DC3 Human Resources (HR) Directorate plays a vital role in managing personnel, manpower, and administrative functions, and this PWS defines the requirements for comprehensive Contractor services that are essential to the success of the DC3 HR Directorate.
The DC3 Judge Advocate (JA) Directorate is critical in providing essential legal and administrative support to DC3. This PWS outlines the requirements for Contractor services that will augment and enhance the DC3 JA Directorate's capabilities.
1.2 SCOPE
The Contractor shall furnish all personnel and services to perform the work to provide vulnerability disclosure services at the DC3 Buildings located at 911 Elkridge Landing Road, Linthicum Heights, MD 21090 and 1306 Concourse Drive, Linthicum Heights, MD 21090.
Contractor performance shall be in accordance with this PWS. The Contractor shall provide highly qualified personnel to support DC3 Security, HR and JA Directorate operations. The Contractor shall provide support to the DC3 Security, HR and JA Directorate by executing the following tasks in support of this contract.
The scope of this requirement includes execution of cyber intelligence and analytical production;
delivery of training and mentoring programs; and facilitation of mission partner engagement and interagency information sharing. The Contractor shall provide all personnel, management, supervision, tools, facilities, and expertise necessary to fulfill the tasks and subtasks defined herein, ensuring accuracy, timeliness, compliance, and seamless integration across DC3 directorates.
Performance under this contract requires a highly skilled, TS/SCI-eligible workforce capable of meeting strict deadlines, producing error-free deliverables, and maintaining compliance with DoW policies and intelligence community standards. The Contractor shall support dynamic operational environments and deliver continuous improvements that enhance DC3’s cyber and analytical mission effectiveness.
1.3 BACKGROUND
The DC3 Security Directorate serves as the critical guardian of sensitive assets and information, safeguarding the DC3's vital mission against evolving threats.
The DC3 HR Directorate efficiently and accurately executes all personnel actions and manages workforce and workload capabilities to optimize organizational performance.
The JA Directorate is responsible for handling a comprehensive range of legal and cyber forensic evidence and legal practices for DC3.
SECTION II
2.0 TASKS
The following tasks are in support of this contract:
• Task 1 – Personnel Clearance Processing
• Task 2 – Physical Security
• Task 3 – Sensitive Compartmented Information Facilities (SCIF) Security Operations
• Task 4 – Security Programs
• Task 5 – Continuity of Operations
• Task 6 – Survey and Assessments
• Task 7 – Comprehensive Training and Development Program
• Task 8 – Integrated Manpower and Position Management Program
• Task 9 – Administrative and Support Functions
• Task 10 – Legal Advisory and Litigation Support
• Task 11 – Digital Evidence
• Task 12 – Knowledge Management
• Task 13 – Customer Service
• Task 14 – Program Management
Note 1: Tasks 1-6 are Security specific. Tasks 7-9 are HR specific. Tasks 10-13 are JA specific.
Task 14 pertains to Security, HR, and JA.
2.1 TASK 1 – PERSONNEL CLEARANCE PROCESSING
This task covers the complete personnel security clearance lifecycle for DC3 personnel, from initial application to ongoing maintenance of records. The Contractor shall ensure compliance with DoW and Air Force regulations through comprehensive security processing, training, and auditing of security records.
2.1.1 SUBTASK 1 – CONTRACT ADMINISTRATION and MANAGEMENT
2.1.1.1 The Contractor shall ensure that personnel accessing DoW information systems have the proper and current DoW/United States Air Force (USAF) information assurance (IA) certification to perform information assurance functions IAW Air Force Manual (AFMAN) 17- 1303, Air Force Cybersecurity Workforce Improvement Program, DoD Directive (DoDD) 8140.01, Cyberspace Workforce Management, and DoD 8570.01-M, Information Assurance Workforce Improvement Program.
2.1.1.2 The Contractor shall ensure all Contractor personnel complete ancillary training. This shall include Operations Security (OPSEC), Force Protection (FP), Human Relations (HR), Security, and Information Protection training and other ancillary training.
2.1.2 SUBTASK 2 – PERSONNEL SECURITY PROCESSING
2.1.2.1 The Contractor shall manage the full security clearance lifecycle for DC3 personnel, including assisting applicants with Standard Form (SF) 86 completion, reviewing submissions for accuracy and completeness, and submitting applications to National Background Investigation Services (NBIS).
2.1.2.2 The Contractor shall update personnel security records in designated systems within 2 business days of receiving required documentation to reflect changes in status, access privileges, training completion, and other relevant information.
2.1.2.3 The Contractor shall regularly audit data entries to ensure accuracy and completeness, correcting any errors identified and generate reports from NBIS as requested by the Government POC, ensuring data accuracy and timelines.
2.1.3 SUBTASK 3 – SECURITY TRAINING AND AWARENESS
2.1.3.1 The Contractor shall coordinate and deliver security awareness training programs for all DC3 personnel, including scheduling sessions, managing attendance, tracking completion rates, and assisting with the development/maintenance of training materials in coordination with the CSO and the Human Resources department.
2.1.3.2 The Contractor shall conduct comprehensive security briefings for new employees and Contractors, preparing materials, delivering presentations, answering questions, and documenting attendance.
2.1.4 SUBTASK 4 – SECURITY RECORDS AND COMPLIANCE
2.1.4.1 The Contractor shall maintain and audit security records by the last business day of each quarter to ensure accuracy and compliance with regulatory requirements. This includes identifying and correcting discrepancies, updating inaccurate or incomplete records, and documenting all corrective actions in the Records Audit Report (Section 4, Deliverable 1).
2.1.4.2 The Contractor shall maintain the currency and accuracy of all security program documentation, including regular review and updates, proper versioning, archiving of obsolete documents, and timely addition of new documents to the repository.
2.2 TASK 2 – PHYSICAL SECURITY
This task focuses on maintaining the physical security of DC3 facilities through regular inspections, access control management, and active monitoring of security systems. The Contractor shall ensure a secure environment by identifying vulnerabilities, managing authorized access, and responding to security incidents according to established procedures.
2.2.1 SUBTASK 1 – CONDUCT REGULAR PHYSICAL SECURITY INSPECTIONS
2.2.1.1 The Contractor is responsible for working with the Government leads to review all physical access points and security measures.
2.2.1.2 The Contractor shall develop a physical security inspection checklist based on applicable regulations, organizational policies, and industry best practices. The check list shall cover all critical physical security elements (e.g., locks, doors, windows, fences, lighting) and, submit the Physical Security Inspection Checklist to the Government for review approval no later than 14 calendar days after contract start date (Section 4, Deliverable 2).
2.2.1.3 The Contractor shall conduct physical security inspections using the approved Physical Security Inspection Checklist weekly. The Contractor shall document all findings from the inspections, including any deficiencies, vulnerabilities, or areas of non-compliance (e.g., photograph and video security discrepancies). Critical deficiencies found during the inspection should be notified to the Government immediately. Stop the inspection and report. The inspection should continue after instructed to do so by the Government. An example of a critical deficiency would be entry or exit badge readers are found ineffective.
2.2.1.4 The Contractor shall, during physical security inspections verify the proper storage and handling of classified materials IAW Intelligence Community Directive 705 (ICD 705) and other applicable regulations (as identified by Government), using the checklist items and documenting findings in the Inspection Report.
2.2.1.5 A physical security Inspection Report shall be provided to the Government within three
(3) business days of each physical security inspection (Section 4, Deliverable 3). The report shall include the completed checklist, a summary of findings, and recommendations for corrective actions (if applicable).
2.2.2 SUBTASK 2 – MANAGE ACCESS CONTROL SYSTEMS
2.2.2.1 The Contractor shall administer the access control system, including issuing and deactivating badges, updating access control lists, and managing user profiles.
2.2.2.2 The Contractor shall ensure that all DC3 personnel have appropriate access privileges based on their job responsibilities and security clearances.
2.2.2.3 The Contractor shall investigate and resolve access control issues, such as lost or stolen badges, unauthorized access attempts, and system malfunctions IAW DC3 policy and procedures.
2.2.2.4 The Contractor shall conduct weekly audits of the access control system to ensure its integrity and effectiveness and maintain accurate records of all access control activities, including badges, access changes, and audit results and, provide access control system audit logs to the Government by the last business day of the month (Section 4, Deliverable 4).
2.2.3 SUBTASK 3 – MONITOR SECURITY CAMERAS and ALARMS
2.2.3.1 The Contractor shall monitor security cameras and alarm systems for suspicious activity or security breaches from 6:00 AM to 6:00 PM during normal business days.
2.2.3.2 The Contractor shall respond to alarms IAW established procedures.
2.2.3.3 Any incident requiring corrective action from the Contractor should be reported to the Government POC within two (2) hours of the incident.
2.2.3.4 The Contractor shall maintain accurate records of all alarm activation, security incidents, and responses in the Incident Report and submit one (1) business day following the incident (Section 4, Deliverable 5).
2.2.3.5 The Contractor shall regularly test security cameras and alarm systems to ensure they are functioning properly and analyze the data to identify trends and patterns that may indicate vulnerabilities or weaknesses in the countermeasures.
2.2.4 SUBTASK 4 – MANAGE VISITOR CONTROL
2.2.4.1 The Contractor shall adhere to implemented procedures for controlling visitor access to facilities, including sign-in/sign-out logs, visitor badges, and escort requirements.
2.2.4.2 The Contractor may be tasked with escorting visitors to their designated areas and ensure visitors comply with security regulations. The Contractor shall maintain accurate records of all visitor access to DC3.
2.2.4.3 The Contractor shall review the visitor log weekly to verify compliance and address any incomplete or missing entries immediately.
2.2.4.4 The Contractor shall ensure visitor control procedures are reviewed and updated at least quarterly to ensure ongoing alignment with evolving security policies and regulations.
2.3 TASK 3 – SENSITIVE COMPARTMENTED INFORMATION FACILITIES (SCIF)
SECURITY OPERATIONS
This task focuses on maintaining the security of DC3 Sensitive Compartmented Information Facilities (SCIFs) by controlling access, conducting regular inspections, and managing uncleared personnel. The Contractor shall ensure compliance with security regulations and protect classified information through diligent monitoring and adherence to established procedures.
2.3.1 SUBTASK 1 – CONTROL ACCESS to the SCIF
2.3.1.1 The Contractor shall verify the identity and authorization of all personnel seeking entry into a DC3 SCIF using approved identification methods (e.g., Common Access Card, DC3 badge, access control lists).
2.3.1.2 The Contractor shall maintain an accurate and complete access log, documenting the date, time, name, and purpose of entry for all individuals entering and exiting the SCIF.
2.3.1.3 The Contractor shall ensure that all visitors to the SCIF are properly escorted by authorized personnel and comply with all security regulations.
2.3.1.4 The Contractor shall conduct quarterly audits of SCIF access controls including physical security measures, access logs, badge issuance procedures, and alarm systems.
2.3.2 SUBTASK 2 – CONDUCT SCIF INSPECTIONS
2.3.2.1 The Contractor shall conduct monthly SCIF inspections using a standardized checklist to ensure compliance with security regulations.
2.3.2.2 SCIF inspections will include, but are not limited to, inspecting for unauthorized electronic devices and other prohibited items as identified by the Government.
2.3.2.3 The Contractor shall verify that all classified materials are properly labeled and secured IAW established procedures.
2.3.2.4 The Contractor shall respond to alarms and security incidents immediately and report incidents to the CSO.
2.3.2.5 The Contractor shall report any SCIF discrepancies or vulnerabilities to the CSO or Government POC immediately.
2.3.3 SUBTASK 3 – MANAGE and ESCORT UNCLEARED PERSONNEL
2.3.3.1 The Contractor shall ensure that all uncleared personnel entering the SCIF are properly briefed on security regulations and procedures and obtain prior authorization from the CSO when escorting uncleared personnel.
2.3.3.2 When applicable, the Contractor shall escort uncleared personnel within the SCIF, ensuring that they do not have access to classified information or unauthorized areas.
2.3.3.3 The Contractor shall maintain a log of all uncleared personnel who have entered the SCIF, including their name, affiliation, purpose of visit, and the escort’s name.
2.4 TASK 4 – SECURITY PROGRAMS
This task involves the comprehensive review and maintenance of various security programs, including Industrial, Information and Personnel Security. The Contractor shall ensure compliance with DoW, Air Force, and DC3 policies by examining documentation, records, and systems, promptly reporting any discrepancies to the appropriate authorities.
2.4.1 SUBTASK 1 – INDUSTRIAL SECURITY PROGRAM
2.4.1.1 The Contractor shall review document control records related to classified information to ensure compliance with established DC3 procedures.
2.4.1.2 The Contractor shall review practices related to processing and executing tasks covered under the Industrial Security Program, such as personnel security clearances, classified document control, and facility security. A summary of this review will be provided in the Industrial Security Program Summary Report, on the first business day of the month beginning 30 calendar days after contract start date (Section 4, Deliverable 6).
2.4.1.3 The Contractor shall track corrective actions resulting from the Industrial Security Program Summary Report, verifying their completion and effectiveness. This corrective action will be updated in the most recent Industrial Security Program Summary Report within 3 business days of the corrective action completion.
2.4.2 SUBTASK 2 – INFORMATION SECURITY AND DOCUMENT CONTROL
PROGRAM
2.4.2.1 The Contractor shall review Government-provided documentation (e.g., procedures, reports, Standard Operating Procedures) demonstrating compliance with DoW, AF, and DC3 information security and document control policies.
2.4.2.2 The Contractor shall review, adhere to, and enforce security measures and protection methods for classified and sensitive information, including physical security, access controls and data encryption.
2.4.2.3 The Contractor shall review document control records to ensure compliance with established procedures for creating, storing, transmitting, and destroying classified and sensitive information on a monthly basis.
2.4.3 SUBTASK 3 – PERSONNEL SECURITY PROGRAM
2.4.3.1 The Contractor shall review Government-provided documentation (e.g., records, procedures, reports, Standard Operating Procedures) to ensure understanding and compliance with DoW, AF, and DC3 personnel security policies.
2.4.3.2 The Contractor shall review organizational staff records (e.g., with appropriate authorization and IAW Privacy Act regulations) to ensure compliance with DoW, AF, and DC3 personnel security policies, focusing on the following areas; security clearance eligibility, background investigations, and security awareness training. Discrepancies should be reported to the CSO or Government POC within 4 hours.
2.4.3.3 The Contractor shall review transactions taken by Contractor personnel in systems, databases, and platforms related to personnel security actions [e.g., Defense Information System for Security (DISS), National Industrial Security Systems (NISS), eApplication (e-App) by
NBIS] ensuring compliance with established procedures and regulations. Discrepancies should be reported to the CSO or Government POC within 4 hours.
2.4.3.4 The Contractor shall maintain confidentiality and protect sensitive personnel information to include Privacy Act and Health Insurance Portability and Accountability Act (e.g., HIPAA) regulations.
2.4.4 SUBTASK 4 – OPERATIONAL SECURITY (OPSEC) AND CONTROLLED
UNCLASSIFIED INFORMATION (CUI) SECURITY PROGRAM
2.4.4.1 The Contractor shall review Government-provided documentation (e.g., records, procedures, reports, Standard Operating Procedures) to ensure understanding and compliance with DoW AF, and DC3 OPSEC and CUI security policies.
2.4.4.2 The Contractor shall review Security-owned databases and platforms to ensure compliance with DoW, AF, and DC3 OPSEC and CUI policies, focusing on areas such as access controls, data encryption, and data labeling on a monthly basis. Discrepancies should be reported to the CSO or Government POC within 4 hours.
2.4.4.3 The Contractor shall review transactions taken by Contractor personnel in systems, databases, and platforms related to OPSEC and CUI, ensuring compliance with established procedures and regulations on a monthly basis. Discrepancies should be reported to the CSO or Government POC immediately within four (4) hours.
2.4.4.4 The Contractor shall assist the Government in the development and delivery of OPSEC and CUI awareness training programs, providing feedback to the Government POC on the effectiveness of the training.
2.5 TASK 5 – CONTINUITY OF OPERTIONS (COOP)
This task encompasses the development, maintenance, and implementation of the organization's Continuity of Operations Plan (COOP) to ensure business functions continue during disruptions.
The Contractor shall assist in developing and maintaining the plan, participating in exercises, and coordinating with stakeholders to mitigate threats and vulnerabilities.
2.5.1 SUBTASK 1 – DEVELOPMENT AND MAINTENANCE
2.5.1.1 The Contractor shall assist in the development and maintenance of the organization's Continuity of Operations Plan (COOP) and develop and maintain procedures for relocating personnel, equipment, and essential records to alternate work locations.
2.5.1.2 The Contractor shall participate in COOP exercises and drills to test the plan's effectiveness and establish backup communication systems and procedures to ensure continuity of operations in the event of a disruption.
2.5.1.3 The Contractor shall develop and implement mitigation strategies to address identified threats and vulnerabilities and regularly review and update the COOP plan to ensure its effectiveness and relevance.
2.5.1.4 The Contractor shall assist in the coordination with external agencies and stakeholders during a COOP activation and participate in after-action reviews following COOP exercises or real-world events to identify areas for improvement.
2.6 TASK 6 – SURVEY AND ASSESSMENT
This task centers on proactively identifying vulnerabilities and ensuring compliance with security regulations through regular surveys and assessments. The Contractor shall conduct vulnerability assessments and compliance inspections, develop corrective action plans to address identified deficiencies, and track the progress and effectiveness of these actions.
2.6.1 SUBTASK 1 – CONDUCT SECURITY VULNERABILITY ASSESSMENTS
2.6.1.1 The Contractor shall develop a schedule for conducting Security Vulnerability Assessments (SVA), covering all critical areas and functions. The schedule shall be submitted to the Government for approval. The frequency of SVAs should be based on risk, but no less than monthly.
2.6.1.2 SVAs will be conducted to identify trends, patterns and anomalies for potential weaknesses in security programs, infrastructure, and operations.
2.6.1.3 SVAs will focus on identifying vulnerabilities not previously identified in routine inspections or other monitoring activities.
2.6.1.4 The Contractor shall document the assessment methodology, scope, and findings in a clear and concise manner (Section 4, Deliverable 7) by the last business day of each month. The SVA shall be submitted to the Government 5 business days after the SVA is complete.
2.6.2 SUBTASK 2 – CONDUCT COMPLIANCE INSPECTIONS
2.6.2.1 The Contractor shall develop a schedule for conducting compliance inspections to verify adherence to security regulations, policies, and procedures no later than 60 calendar days from contract start date. The schedule shall be submitted to the Government for approval.
2.6.2.2 Compliance inspections shall be conducted using established checklists and procedures.
The Contractor shall focus compliance inspections on areas where non-compliance could have a significant impact on security.
2.6.2.3 The Contractor shall document all findings of non-compliance, including specific violations and supporting evidence in the Security Compliance Report (Section 4, Deliverable 8). This report will be submitted to the Government three (3) business days after the report is complete.
2.6.3 SUBTASK 3 – DEVELOP and IMPLEMENT CORRECTIVE ACTION PLANS
2.6.3.1 For each vulnerability or deficiency identified in SVAs or compliance inspection report, the Contractor shall develop a detailed corrective action plan.
2.6.3.2 Corrective action plans should include root cause, specific actions to be taken, responsible parties, timelines for completion, and metrics for measuring effectiveness.
2.6.3.3 The Contractor shall prioritize corrective actions based on the severity of the risk and the potential impact of the vulnerability.
2.6.3.4 Corrective action plans shall be included in the SVA and Security Compliance Report when applicable.
2.6.4 SUBTASK 4 – TRACK and MONITOR CORRECTIVE ACTIONS
2.6.4.1 The Contractor shall maintain a system for tracking the progress of corrective actions, including milestones, completion dates, and responsible parties.
2.6.4.2 The Contractor shall monitor the implementation of corrective actions quarterly to ensure they are completed on time and address the identified vulnerabilities to verify the effectiveness of corrective actions.
2.6.4.3 In the event a corrective action is deemed insufficient by the Government, the Contractor shall provide a revised corrective action one (1) business day after the Government’s request.
2.7 TASK 7 – COMPREHENSIVE TRAINING and DEVELOPMENT PROGRAM
This task focuses on managing and administering a comprehensive training and development program for DC3 personnel, ensuring workforce readiness and compliance. The Contractor shall develop training plans, track completion rates, manage learning systems, and provide detailed reports on program performance and effectiveness to support informed decision-making.
2.7.1 SUBTASK 1 – INSTRUCTIONAL CURRENCY and QUALITY CONTROL
2.7.1.1 The Contractor shall maintain currency of all training instructions by establishing a verification process, soliciting feedback, and implementing version control.
2.7.2 SUBTASK 2 – TRAINING PLAN DEVELOPMENT
2.7.2.1 The Contractor shall develop an annual training plan that aligns with organizational goals, allocates resources, and identifies relevant educational opportunities.
2.7.2.2 The Contractor shall manage the Continuing Development (CD) program for the civilian workforce to foster employee growth and enhance organizational effectiveness.
2.7.2.3 The Contractor shall remain abreast of Air Force (AF) mentoring and coaching opportunities and disseminate information to employees to encourage participation in developmental programs.
2.7.2.4 The Contractor shall administer the DC3 Joint Knowledge Online (JKO) hierarchy and the MyLearning system, maintaining organizations, audiences, requirements, and personnel rosters to ensure access to training and accurate assignment of training requirements.
2.7.2.5 The Contractor shall, on a weekly basis, access the JKO dashboard, extract designated Directorate statistics as defined by the Government, and submit a concise report summarizing these statistics to the Executive Director. This report will support the Executive Director's informed decision-making process. The report will be due by 12:00 PM ET every Friday, beginning at contract award (Section 4, Deliverable 9).
2.7.3 SUBTASK 3 – TRACKING and COMPLIANCE
2.7.3.1 The Contractor shall establish and maintain a comprehensive and up-to-date roster of all Total Force Ancillary Training (TFAT) requirements, for all identified personnel within each Directorate. This roster shall include, at a minimum, the following elements for each training requirement: (a) Training Title, (b) Course Code, (c) Frequency/Recertification Period, (d) Target Audience (personnel categories), (e) Compliance Deadline, and (f) Completion Status.
The Contractor shall proactively update this roster as TFAT requirements change. This roster will be used to ensure compliance, workforce readiness, and timely reporting of training completion (Section 4, Deliverable 10).
2.7.3.2 The Contractor shall track civilian supervisors’ completion status for all Air Force mandated supervisory and management courses to ensure compliance and support leadership development.
2.7.3.3 The Contractor shall manage training checklist items through the Self-Inspection Assessment Monitor (SAPM) and utilize the DoW Management Internal Control Toolset (MICT) to ensure compliance and reduce the risk of audit findings.
2.7.3.4 The Contractor shall process Standard Form (SF) 182 requests for civilian and military personnel in a timely and efficient manner to ensure access to training opportunities.
2.7.3.5 The Contractor shall maintain a transaction register of training budget data by Directorate to ensure effective resource allocation and financial management.
2.7.3.6 The Contractor shall maintain a tracker of completed Individual Development Plans (IDPs) for civilian personnel, separated by DoW Performance Management and Appraisal Program (DPMAP) and Defense Civilian Intelligence Personnel System (DCIPS), to support employee growth and performance management.
2.7.3.7 The Contractor shall administer the Defense Organizational Climate Survey (DEOCS) to gather valuable feedback on the organizational climate.
2.7.3.8 The Contractor shall prepare slides, including developing and maintaining templates for any presentations, training or documentation needed by the HR department.
2.7.4 SUBTASK 4 – REPORTING
2.7.4.1 The Contractor shall develop, maintain, and submit a comprehensive monthly Training Program Performance Report, summarizing training completion rates, budget expenditures, and key performance indicators (KPIs) for all training programs as defined by the Government. The report shall include, at a minimum, the following elements for each training program: (a) Training Completion Rate (percentage of personnel completing required training), (b) Budget Expenditures (total and per-student cost), (c) Key Performance Indicators (KPIs), (d) Trend Analysis (identifying significant changes and patterns), and (e) Recommendations for Program Improvement (based on the trend analysis). The report shall be submitted to the HR Director by the 5th business day of each month (Section 4, Deliverable 11).
2.7.4.2 The Contractor shall develop and submit a quarterly report analyzing the effectiveness of the Continuing Development (CD) program, including employee participation rates, skills development outcomes, and alignment with organizational goals. The report shall be submitted to the HR Director by the 15th business day of each quarter (Section 4, Deliverable 12).
2.7.4.3 The Contractor shall develop and submit an annual report summarizing the overall performance of the Training & Development Program, including a review of goals and objectives, budget utilization, compliance metrics, and recommendations for future program development. The report shall be submitted to the HR Director by January 31st of each year (Section 4, Deliverable 13).
2.8 TASK 8 – INTEGRATED MANPOWER and POSITION MANAGEMENT PROGRAM
This task involves the accurate maintenance of personnel and position data, ensuring compliance with relevant regulations and guidelines. The Contractor shall track personnel, manage vacant positions, maintain organizational charts, and submit timely reports on key manpower statistics and program performance.
2.8.1 SUBTASK 1 – MAINTENANCE and PROCESSING
2.8.1.1 The Contractor shall accurately account for all civilian, military, and Contractor personnel, maintaining a current count of the actual personnel and performing a reconciliation process quarterly to identify and correct discrepancies.
2.8.1.2 The Contractor shall maintain a current in/out roster reflecting the presence or absence of all civilian, military, and Contractor personnel, updating the roster weekly with a minimum accuracy rate of [e.g., 99%].
2.8.1.3 The Contractor shall manage vacant civilian positions by tracking positions in the Human Resource Management System (HRMS) or a dedicated system and updating the status (e.g., advertised, interviewed, offer extended, filled) within one (1) business day of any change.
2.8.1.4 The Contractor shall maintain two sets of organizational charts (e.g., one official and one for internal use), updating charts within one (1) business day of any personnel changes affecting the chart's accuracy.
2.8.1.5 The Contractor shall submit Manpower Change Requests (MCRs) accurately and in a timely manner to reflect changes in manpower position data (e.g., series, organizational structure code), submitting complete and accurate MCRs within two (2) business days of receiving notification of the required change.
2.8.2 SUBTASK 2 – MANAGEMENT and COMPLIANCE
2.8.2.1 The Contractor shall maintain an accurate and up-to-date roster of all civilian positions and associated codes, validating the data against official sources monthly and correcting any errors within two (2) business days of discovery.
2.8.2.2 The Contractor shall maintain a roster of Information Assurance (IA) levels and associated certification requirements for all personnel, ensuring compliance with IA requirements and updating the roster within two (2) business days of any personnel certification changes or new requirements being issued.
2.8.2.3 The Contractor shall maintain a roster of Furlough Indicator Codes (FICs) assigned to civilian personnel, updating the roster within one (1) business day of any changes in personnel financial disclosures.
2.8.2.4 The Contractor shall coordinate manpower assessments with Air Force Office of Special Investigations/Directorate of Plans and Budget (AFOSI/DPB) and Air Force Manpower Analysis Agency (AFMAA), responding to data requests within two (2) business days and actively participating in assessment meetings as requested.
2.8.2.5 The Contractor shall accurately code all positions and personnel with the appropriate Cyber Workforce Role (CWR) codes, adhering to the latest Air Force CWR guidelines and updating the coding within two (2) business days of any changes in CWR roles or personnel assignments.
2.8.2.6 The Contractor shall track Civilian Position Descriptions (PDs) assigned to each manpower authorization, ensuring that all PDs are linked to the correct authorization and validating the links quarterly to maintain accuracy.
2.8.3 SUBTASK 3 – REPORTING
2.8.3.1 The Contractor shall develop and submit a monthly report summarizing key manpower statistics, including total personnel count, vacant positions, turnover rates, and diversity metrics.
The report shall be submitted to the HR Director by the 5th business day of each month (Section 4, Deliverable 14).
2.8.3.2 The Contractor shall develop and submit a quarterly report analyzing vacant positions, recruitment efforts, and time-to-fill metrics. The report shall be submitted to the HR Director by the 15th business day of each quarter (Section 4, Deliverable 15).
2.8.3.3 The Contractor shall develop and submit an annual report summarizing the overall performance of the Manpower & Position Management Program, including a review of manpower planning, resource allocation, compliance metrics, and recommendations for program improvements. The report shall be submitted to the HR Director by January 31st of each year (Section 4, Deliverable 16).
2.9 TASK 9 – ADMINISTRATIVE and SUPPORT FUNCTIONS
This task provides essential administrative and support functions to the HR department, including managing taskers, maintaining information resources, and developing electronic forms.
The Contractor shall also generate regular reports on HR service delivery, administrative process effectiveness, and overall program performance.
2.9.1 SUBTASK 1 – MANAGEMENT and ADMINISTRATION
2.9.1.1 The Contractor shall review all taskers assigned to HR in the Electronic Task Management System (ETMS) on a weekly basis, assign taskers to responsible parties within two
(2) business days of receipt, and monitor the progress of assigned taskers, escalating overdue or problematic taskers to HR leadership within one (1) business day of the tasker's due date.
2.9.1.2 The Contractor shall administer the HR, Training, and Military SharePoint pages, ensuring accurate, up-to-date, and easily accessible information by reviewing and updating content no less than monthly, managing user permissions within two (2) business days of a request, and soliciting user feedback by the last business day of the quarter (Section 4, Deliverable 17).
2.9.1.3 The Contractor shall create new and maintain existing DC3-HR electronic fillable PDF forms, ensuring that all forms are user-friendly, accurate, compliant with accessibility standards (e.g., Section 508), and contain data validation features, responding to any updates needed to current forms within two (2) business days. All newly created forms must undergo user testing prior to release.
2.9.1.4 The Contractor shall assist with the processing of DPMAP/DCIPS awards by assisting employees and supervisors with submitting award nominations within three (3) business day of the award nomination period opening and by providing support to the awards review board as requested by HR leadership within one (1) business day of the review board's request.
2.9.2 SUBTASK 2 – REPORTING
2.9.2.1 The Contractor shall develop and submit a monthly report summarizing HR service desk ticket resolution times, employee satisfaction scores, and common issue categories. The report shall be submitted to the HR Director by the 5th business day of each month (Section 4, Deliverable 18).
2.9.2.2 The Contractor shall develop and submit a quarterly report analyzing the effectiveness of HR administrative processes, including form processing times, document management efficiency, and compliance with internal policies. The report shall be submitted to the HR Director by the 15th business day of each quarter (Section 4, Deliverable 19).
2.9.2.3 The Contractor shall develop and submit an annual report summarizing the overall performance of the HR Administrative & Support Functions, including a review of key performance indicators (KPIs), process improvements, and recommendations for future enhancements. The report shall be submitted to the HR Director by January 31st of each year (Section 4, Deliverable 20).
2.10 TASK 10 – LEGAL ADVISORY and LITIGATION SUPPORT
This task focuses on strengthening the DC3/JA Directorate's legal capabilities through expert legal research, information management, and litigation support. The overall goal is to empower the JA Directorate to more effectively handle legal challenges and enhance its litigation success.
2.10.1 SUBTASK 1 – LEGAL INFORMATION SYSTEMS MANAGEMENT
2.10.1.1 The Contractor shall deliver a fully functional and tested electronic legal information system, populated with a minimum of 500 relevant legal documents and accessible to at least 25 concurrent users.
2.10.1.2 The Contractor shall deliver a secure, searchable, and adaptable legal information system with no critical vulnerabilities identified and achieves a successful keyword search, and includes a documented version control and update process allowing for seamless integration of new legal information and functionality updates at least twice per year.
2.10.2 SUBTASK 2 – EXPERT WITNESS PREPARATION and SUPPORT
2.10.2.1 The Contractor shall deliver a comprehensive expert witness training program with a minimum of 20 hours of instruction, including mock trial exercises, and demonstrate a minimum average improvement of 20% in participant scores on pre- and post-training assessments measuring knowledge of courtroom procedure, evidence presentation, and effective communication skills.
2.10.2.2 The Contractor shall provide comprehensive expert witness support to at least ten (10) DC3/JA examiners involved in active litigation cases, documenting a minimum of 20 hours of dedicated consultation and preparation assistance per examiner, resulting in positive feedback from legal counsel involved in at least 80% of the supported cases, as evidenced by a post-litigation survey indicating improved expert witness performance and contribution to the case outcome.
2.11 TASK 11 – DIGITAL EVIDENCE
This task focuses on enhancing the legal expertise and courtroom effectiveness of DC3 personnel by providing comprehensive training and support related to digital evidence and cybersecurity law. The overarching goal is to equip DC3 examiners with the knowledge, skills, and resources necessary to deliver impactful and legally sound testimony, thereby strengthening the JA Directorate's litigation success.
2.11.1 SUBTASK 1 – TRAINING PROGRAM DESIGN
2.11.1.1 The Contractor shall deliver quarterly reports by the last business day of each quarter documenting the monitoring of at least five (5) industry publications, three (3) relevant legal databases, and two (2) cybersecurity conferences, identifying a minimum of three (3) emerging trends or legal changes per quarter, and subsequently provide documented recommendations for updating training programs to address these changes, achieving a 90% acceptance rate of these recommendations by the DC3/JA Attorney Advisor (Section 4, Deliverable 21).
2.11.2 SUBTASK 2 – TRAINING PROGRAM DEVELOPMENT
2.11.2.1 The Contractor shall develop and deliver a minimum of four (4) distinct training programs per year, each focusing on specific digital evidence and legal topics identified in the assessments, covering a minimum of 40 training hours in total, and achieving an average participant satisfaction rating of 4.5 out of 5 on post-training evaluations for program relevance and quality (Section 4, Deliverable 22).
2.11.2.2 The Contractor shall provide all DC3/CFL examiners participating in training programs with comprehensive training manuals, access to necessary software and hardware tools, and online learning resources, resulting in a minimum of 80% of examiners demonstrating proficiency in the covered skills and techniques on post-training practical exercises and knowledge assessments (Section 4, Deliverable 23).
2.11.3 SUBTASK 3 – MOCK EXAMINATION IMPLEMENTATION
2.11.3.1 The Contractor shall develop and implement a minimum of six (6) unique mock examination scenarios per year, each based on real-world case studies and incorporating realistic legal challenges and cross-examination techniques, pushing DC3/CFL examiners to demonstrate their expertise in presenting digital evidence and defending their forensic methodologies under pressure (Section 4, Deliverable 24).
2.11.3.2 The Contractor shall provide individualized feedback reports to each DC3/CFL examiner following each mock examination, documenting specific areas for improvement and providing actionable strategies to strengthen their testimony and presentation skills, resulting in a minimum average improvement of 15% in examiner performance scores across subsequent mock examination scenarios. Additionally, feedback must be delivered within five (5) business days of the mock examination, as reported by 90% of participating examiners (Section 4, Deliverable 25).
2.12 TASK 12 – KNOWLEDGE MANAGEMENT
This task focuses on establishing the foundational documentation and processes necessary for effective operation and maintenance of the JA Legal Portal and its associated support systems.
2.12.1 SUBTASK 1 – FRAMEWORK DOCUMENTATION
2.12.1.1 The Contractor shall develop and implement a documented framework for managing the JA Legal Portal and ticketing system, ensuring 99.9% system uptime, resolving 90% of support tickets within two (2) business days, and maintaining a comprehensive user access management system that is audited quarterly, with findings showing no critical security vulnerabilities.
2.12.1.2 The Contractor shall develop and implement a content update schedule for the JA Legal Portal, ensuring monthly updates with at least five (5) new or updated legal resources, with 100% of content verified for accuracy and relevance to emerging legal trends, as determined by a legal subject matter expert review.
2.12.2 SUBTASK 2 – CONTENT CURATION and TAILORING
2.12.2.1 The Contractor shall track developments in digital evidence and trial preparation, delivering quarterly reports by the last business day of each quarter summarizing key insights and best practices, and creating at least three (3) actionable guidance documents per quarter that equip legal professionals to successfully navigate complex cases, with at least 80% of DoW legal personnel indicating that the guidance documents are "Highly Useful" or "Useful" in a post-distribution survey (Section 4, Deliverable 26).
2.12.2.2 The Contractor shall segment DoW legal practitioners into at least five (5) distinct groups based on roles and responsibilities, and deliver quarterly curated content via the JA Legal Portal and other approved methods, ensuring that at least 75% of segmented users access the content tailored to their role, as tracked by portal analytics and user feedback mechanisms.
2.13 TASK 13 – CUSTOMER SERVICE
This task focuses on actively gathering and analyzing customer feedback to understand their experiences with the JA services. The core objective is to proactively listen to the customer voice and translate it into tangible improvements.
2.13.1 SUBTASK 1 – FEEDBACK COLLECTION
2.13.1.1 The Contractor shall establish and maintain a dynamic feedback loop, collecting feedback from at least 75% of JA customers after each service interaction via surveys, interviews, or focus groups, and utilizing this feedback to drive a minimum of two (2) documented service improvements by the last business day of each quarter, resulting in a measurable increase in overall customer satisfaction scores by at least 5% year-over-year, as measured by a standardized customer satisfaction survey (Section 4, Deliverable 27).
2.13.1.2 The Contractor shall deliver a comprehensive quarterly analysis of customer feedback data by the last business day of each quarter, identifying key trends, pain points, and opportunities for service innovation, culminating in a prioritized list of at least three (3) actionable recommendations for service improvements with estimated impact on customer satisfaction, supported by data analysis and proposed implementation plans designed to achieve a minimum of a 10% improvement in customer satisfaction scores within the subsequent quarter (Section 4, Deliverable 28).
2.13.2 SUBTASK 2 – SERVICE IMPROVEMENT and TRACKING
2.13.2.1 The Contractor shall submit monthly progress reports by the 5th business day of each month, detailing project activities, accomplishments against milestones, identified challenges and mitigation strategies, a summary of customer feedback received that month, proposed changes to project plans, and key performance indicators (KPIs) demonstrating progress towards achieving the overall customer satisfaction goals, with a 100% on-time submission rate for all monthly reports (Section 4, Deliverable 29).
2.14 TASK 14 – PROGRAM MANAGEMENT
2.14.1 SUBTASK 1 – PROGRAM OVERSIGHT
2.14.1.1 The Contractor shall provide program management support. This includes the management and oversight of all activities performed by Contractor personnel, including any subcontractors.
2.14.1.2 The Contractor shall identify a PM by name who shall provide management, direction, administration, quality control, and leadership to all Contractor personnel and sub-contractor personnel.
2.14.2 SUBTASK 2 – PROGRAM MANAGEMENT PLAN (PMP)
2.14.2.1 The Contractor shall provide a PMP that documents all task/subtask requirements performed to satisfy the requirements of this PWS (Section 4, Deliverable 30).
2.14.2.2 The Contractor shall provide the Government with a draft PMP for review, modification, and approval. The final PMP shall incorporate the Government’s changes.
2.14.2.3 The PMP is an evolutionary document that shall be updated as needed to reflect changes and evolving training requirements (Section 4, Deliverable 31).
2.14.2.4 The Contractor shall work from the most current Government approved iteration of the
PMP.
2.14.2.5 The Contractor’s PMP shall, minimally:
• Describe the proposed management approach.
• Describe the Contractor’s SOPs for all tasks.
• Include milestones, tasks, and subtasks required in this contract.
• Describe in detail the Contractor’s approach to risk management under this contract.
• Describe in detail the Contractor’s approach to communications, including processes, procedures, communication approach, and other rules of engagement between the Contractor and the Government.
• Include the current Organizational Chart and the approach to ensuring the Government is in receipt of the most current version of the Organizational Chart.
• Describe in detail the Contractor’s approach to obtaining short-term specialized expertise, when required for surge support.
2.14.3 SUBTASK 3 – RISK MANAGEMENT
2.14.3.1 The Contractor shall develop, implement, and maintain a comprehensive Risk Management Plan (Section 4, Deliverable 32), as part of the overall PMP, for all tasks executed under this PWS.
2.14.3.2 The Contractor’s Risk Management Plan shall include, (minimally):
• Identification of risks, and the assessment of risks and their impacts, prioritization, mitigation, and control plans.
• Risk tracking, monitoring, and reporting process.
• Risk processes including the development of recovery plans in the event risks are realized.
• Escalation timelines and procedures for notifying the Government.
2.14.4 SUBTASK 4 – COMMUNICATION and MEETINGS
2.14.4.1 The Contractor shall facilitate Government and Contractor communications; use industry best practices / standards and proven methodologies to track and document requirements and activities to allow for continuous monitoring and evaluation by the Government; and ensure all support and requirements performed are accomplished IAW the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .