DRAFT - PWS.pdf

PDF 642 KB Posted

Attached to
Card Failure & Durability Analysis Federal contract opportunity
Solicitation number
Not on record
Issued by
Defense Human Resources Activity

View the file

Other files for this federal contract opportunity

Other files attached to Card Failure & Durability Analysis, newest first.
File Type Posted
Sources Sought Notice.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1 Ver: Mar 2019

Performance Work Statement (PWS) - DRAFT

1.0 INTRODUCTION

The Defense Manpower Data Center (DMDC) requires both scientific and engineering Card Failure & Durability Analysis in support of the Common Access Card (CAC) Program and related identity management solutions.

2.0 BACKGROUND

DMDC is the proponent organization within DoD for the implementation of smartcard technology for Identity Management program as directed by the Deputy Secretary of Defense. With approximately three million cards in circulation and 225,000 issued monthly, the DoD Identity Management solution is used across the DoD and several federal government agencies in compliance with Homeland Security Presidential Directive 12 (HSPD-12). DMDC contracts third-party subject matter experts to provide independent verification and validation with continuous testing of smartcard products in order to assess vulnerabilities, policies and regulations compliance, operability, and compatibility during pre-issuance or post-issuance of the tokens using cutting edge and emerging technology to maintain and sustain utmost integrity, quality, and operability across DoD and Federal agencies.

3.0 SCOPE

The contractor shall provide personnel, management, equipment, facilities, and materials necessary to ensure independent verification and validation of quality assurance, Federal and DoD standards compliance, and analysis services to maintain the integrity of the DoD smartcard Identity Management solutions (CACs, NEATS tokens, SIPR tokens, Uniformed Services ID (USID) cards, and other credentials and HSPD-12 solutions.

4.0 REQUIREMENTS The Contractor shall:

4.1 CARD ANALYSIS AND QUALITY ASSURANCE

Tasks under this contract will require at a minimum one personnel to obtain/maintain personnel security clearance at a minimum of TOP SECRET level.

4.1.1. Perform initial testing and analysis to ensure that new cardstock/tokens provided to the Government meet required specifications and standards during pre-issuance and post-issuance.

4.1.2. Perform follow-on quality testing, artificial aging tests and analysis to evaluate card durability characteristics and provide a report that assess whether the cards meet or exceed the Government’s minimum required life span in accordance with DoD policy; CAC life span is currently three years, although this minimum life span is subject to change. The Government anticipates durability and accelerated aging testing of at least two evaluations of vendor cardstock per year. The Contractor shall provide as many iterations of tests necessary to ensure compliance at the firm-fixed contract price. The Contractor shall monitor changes to Federal and DoD policy that govern card specifications, and shall make recommendations and suggest modifications to future versions of the current DoD card specifications to help ensure that the Government continues to receive products of the highest available quality.

4.1.3. Provide analysis, performance, testing, and guidance regarding specifications for next generation cards.

4.1.4. Perform continuous card performance evaluation against current specifications (Attachment A) and against future relevant specifications during the contract period of performance.

2 Ver: Mar 2019

4.1.5. Provide a detailed description of the approach intended to perform the testing and analysis and document the results. Card testing shall be completed within 15 working days after receipt of cardstock from the card manufacturer.

4.1.6. Provide an Independent Verification and Validation (IV&V) report of test methods, findings, and recommendations following completion of each analysis and within 10 working days of test completion. The Contractor shall indicate the overall compliance or non-compliance of the cards with standards in the report, including specific Federal and DoD standards met/not met.

4.2. CARD ANALYSIS

4.2.1. Analyze card failures and recommend ways to reduce the current card failure rate. Cards will be shipped to contractor facility for analysis via traceable, accountable method. The Contractor shall protect all tested cards from unauthorized release by ensuring the cards are maintained in a secure storage area for subsequent analysis or review until tested cards are periodically released for destruction or returned to DMDC. In coordination with DMDC, the Contractor shall release the cards for destruction when no longer needed for analysis in accordance with the prescribed procedures outlined in Attachments 1 - 6. In accordance with the DoD PKI certificate policy, the Contractor shall ensure cards are transported via a traceable, accountable method. For the extensive shipping procedures reference:

Attachment 1 – Contractors Approval Form for the Destruction of Classified Material at NSA/CMC Facility Attachment 2 – Common Access Card Return Instructions Attachment 3 – DMDC and NSA Return Card Overview Attachment 4 – CMC Required Procedures

Attachment 5 – Classified Material Conversion (CMC) Receipt for Destruction of Classified Material Attachment 6 – DMDC CAC Security Evaluation – Large Sample Task Order

4.2.2. Perform monthly analysis of issuance failures in order to investigate and address the high failure rates occurring using a statistically significant sample of cards (derived from the volume of cards received and issued).

The Contractor shall provide a report with detailed findings of cards that fail prematurely at the time of issuance and recommendations to decrease the card issuance failure rates.

4.2.3. Perform analysis of cards that have failed prematurely while in field use. Perform this analysis 4 times per year in order to help ensure that the cards will meet the three-year life expectancy. An example of the analysis required to determine root cause of failure may include de-encapsulation of chip.

4.2.4. Perform failure analysis on cards failed for specific reasons. DMDC will provide a sampling of cards which failed for specific reason(s) for the analysis. This analysis may be used by DMDC in multiple ways, including, but not limited to: 1) determining the root cause of the particular failure; or 2) monitoring the performance of specific functionality of the card. Analysis for this purpose will occur 3 times per year. Provide report of findings and recommendations following completion of each analysis.

4.3. STATISTICAL ANALYSIS

4.3.1. Use data provided by the Government monthly for field and card issuance failures and perform trend analysis to determine descriptive and demographic variances. The Contractor shall provide a report with analysis of the cumulative data in the monthly Senior Management Review (SMR). Reporting will assist in tracking failure trends related to card manufacturer, printer type and configuration, consumable products, and other factors as new trends areas are identified. Analysis will also identify sites with high issuance rates by location and issuance configuration.

4.4. EQUIPMENT ANALYSIS (OPTIONAL)

3 Ver: Mar 2019

4.4.1. Perform equipment evaluation and analysis of card-related equipment, proposed or incorporated, in the DoD CAC program or other DMDC-related programs. The Contractor shall evaluate and analyze equipment to ensure compatibility with the card and/or impact of equipment on card functionality. Examples of equipment which the contractor may evaluate or analyze include printers (direct-to-card printers and reverse image transfer printers), printer ribbons and other supplies, printer components, central issuance station equipment, linear and two dimensional barcode scanners, IC chip readers, and any other equipment related to card issuance and use.

4.4.2. Perform technical analysis on equipment currently in use by the DoD. Identify equipment problems and make recommendations for increased equipment reliability, compatibility, and durability to help ensure smooth program operation.

4.4.3. Analyze equipment that is emerging in the marketplace for future implementation by DMDC. Evaluate the integrity, reliability, durability, and cost effectiveness of the equipment under consideration. Offer alternate equipment recommendations if more appropriate, reliable equipment is available.

4.4.4 Provide report of findings and recommendations following completion of each analysis and within 10 working days of analysis completion.

4.5. SITE ANALYSIS (OPTIONAL)

4.5.1. Provide field service teams to visit sites with an abnormally high rate of failure; sites experiencing interoperability issues between the CAC and Physical Access Control System (PACS); or new CAC issuance sites.

Estimated number of site visits for failure analysis is 5 – 10 per year. Evaluate/troubleshoot equipment and cardstock, as well as the issuance processes and site activities. Reference section 7.0.

4.5.2. Identify problems that exist and recommend actions to be taken to fix the problems. The Contractor shall provide site visit reports that summarize site visit findings and provide explicit instructions explaining required actions necessary to resolve smartcard failure problems. The Contractor shall track card failure rates after the fixes are in place to determine whether the implemented recommendations had the desired impact.

4.6. INDUSTRY, CUTTING EDGE TECHNOLOGY, AND EMERGING STANDARDS (OPTIONAL)

4.6.1. Apprise the Government of new developments in card technologies as they arise in the industry. Attend approximately 10 conference/meetings per year, subject to advanced approval by the Contracting Officer’s Representative (COR). Reference section 7.0.

4.6.2. Prepare a trip report for each trip that addresses findings pertaining to DMDC-specific interests in the card market or technologies that may be of interest and support the DMDC’s mission within 10 working days of trip completion.

4.6.3. Provide technical analysis and expertise to support DMDC’s interest in the Generic Identity Command Set (GICS) standard and its testing requirement. Provide support by writing and developing emerging GICS testing requirements and methods to enhance cardholder capabilities and reduce card development costs through GICS efficiencies. Provide updates to the DMDC in the monthly Senior Management Reviews (SMR). Participate in technical working groups with DMDC representatives as needed.

4.7 SECURITY ANALYSIS (OPTIONAL)

4.7.1. Provide security analysis of cards with new/different chips from the ones currently fielded in the Program.

A sample description of this large task is included in Appendix C “DMDC Large Sample Task Order”.

4 Ver: Mar 2019

4.7.2. Provide report of findings and recommendations following completion of each analysis and within 10 working days of analysis completion.

4.8 CAC TEST LAB SUPPORT (OPTIONAL)

4.8.1. Ensure new cardstock procured under the DoD Smart Card Cardstock with ICC Specification are compliant with included standards and interoperable with existing and future DoD identity management solutions.

4.8.1.1. Create and maintain a communication test tool for CAC applet that is DoD specific (e.g. VCI secure messaging, certificate checks, etc.)

4.8.1.2. Run communications test tool on new card and/or applets as part of the IV&V evaluation process.

4.8.1.3. Run ISO 14443, 10373, and 7816 communications tests using Exponent’s Keolabs test bench on new card and/or applets as part of the IV&V evaluation process.

4.9 SPECIAL ASSIGNMENTS / RAPID RESPONSE CONTINGENCY SUPPORT

4.9.1 Support special DMDC operational technical CAC program challenges and requirements by working with DMDC points of contact to ensure smooth implementation of the CAC and related programs including systems, issuance, interoperability, standards, and daily use. Assist DMDC in overseeing identity management systems to help ensure appropriate analysis, testing, production to specifications, and quality assurance/control are in place so that each technology meets its performance specifications. Assist DMDC with providing overall support for identity management activities including but not limited to biometrics, physical and logical access control systems, mobile based credentials, derived credentials, equipment, and processes, and all other identity management systems and processes.

4.9.2 Provide rapid response technical analysis and expertise and contingency support to help address DMDC technical challenges and operational questions as they arise. Support would include industry research, assessment and evaluation of best practices, assistance with guidance documentation and specifications, testing support, data analytics, and other support activities necessary to fulfill DMDC’s mission.

4.9.3 Provide support to DMDC points of contact who are working with other Government agencies in the planning and/or implementation of smartcard or identity management programs that must support interoperability with the DoD program as required by HSPD-12 and other Government standards. Support will include providing subject matter expertise to bridge between the programs and assisting with all of the required documentation.

Historically, this has included work coordinating with other agencies seeking to utilize and interoperate their PIV card programs with the DoD infrastructure.

4.10 MONTHLY STATUS REPORTS AND SENIOR MANAGEMENT REVIEWS (SMR)

4.10.1. Participate in a monthly SMR. The SMR will be held on the last Tuesday of each month. The purpose of the SMR is to update task financial and expense related issues as well as address high-level project personnel, milestones, risks/issues/concerns, upcoming events and overall project status. In addition, the contractor will deliver these monthly status reports as part of the SMR materials:

Returned Card Stock Report-Issuance (PWS 4.2.2) Statistical Analysis Report (PWS 4.3.1) Equipment Analysis Report (PWS 4.4.2) Industry and Cutting Edge Technology Reports (PWS 4.6.1)

4.10.2 Provide a copy of the SMR meeting minutes no later than 5 working days after the meeting.

5 Ver: Mar 2019

5.0 DELIVERABLES

5.1. Deliverable requirements for the base and all option years are detailed below:

Deliverable Ref. Delivery Date

Durability and Artificial Aging Test Evaluation Report

4.1.2. 15th business day after test completion

Independent Verification and Validation (IV&V) Report of New Cards

4.1.5. 10th business day after completion of new card stock analysis

Returned Card Stock Report-Issuance

4.2.2. Included in the SMR, when analysis

is completed

Senior Management Review (SMR)

4.8 Monthly; materials due 5 business

days before the SMR meeting

Monthly Report 4.8 5 Business days before the SMR

Field Failure Analysis Update 4.2.3 10th business day after completion of new analysis

SMR Minutes 4.8.2 5th business day after SMR meeting

Trip Report 7.0 Within 5 business days after trip completion

Quality Control Plan 10.0 30 calendar days after award, 5 business days after any updates

6.0 CONTRACTOR MANPOWER REPORTING

The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the DMDC via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address: http://www.ecmra.mil/.

Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. Contractors may direct questions to the help desk at help desk at: http://www.ecmra.mil

The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for DMDC/Identity Management Division via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address: http://www.ecmra.mil/. Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year, unless a later date is otherwise authorized by the Office of the Under Secretary of Defense (Personnel and Readiness).

Contractors may direct questions to the help desk at help desk at: http://www.ecmra.mil

7.0 CONTRACTOR TRAVEL

The Contractor may be required to travel in support of tasks listed above to fulfill requirements outlined in the optional tasks of the PWS. All other travel shall be included in the firm-fixed price. Should travel become required for the optional tasks, a contract modification will be completed to incorporate funding for travel. All trips will be in accordance with applicable travel regulations and actual travel shall be coordinated and pre-approved by the Government COR in writing. Should travel be added at a later date, the Government will only reimburse allowable costs in accordance with FAR Clause 31.205-46 and the current Joint Travel Regulation. The Contractor shall bill

6 Ver: Mar 2019 and will be reimbursed at the Contractor's actual cost and per diem, no profit or fee shall be added. The Contractor shall be required to provide travel receipts to the COR as attachments in WAWF for all allowable costs. Travel projections are subject to change based on Government requirements. Local travel to attend meetings is considered a cost of doing business and shall not be reimbursed.

8.0 SECURITY

NOTE: Security Clearances are not required for access to unclassified data.

8.1 Security Clearances. Personnel performing on this PWS shall obtain a Secret or Top Secret clearance in accordance with the DD 254, Contract Security Classification Specification.

The Contractor must possess or obtain a facility security clearance at the level of Secret or Top Secret prior to contract award. The Contractor shall register and request security clearances through the National Industrial Security Program Central Access Information Security System (NCAISS) (https://www.dss.mil/is/ncaiss/). Contractor personnel shall have appropriate clearances prior to contract award unless otherwise approved in writing by the Contracting Officer (CO). If subcontractors are utilized in performance of a classified contract, the Prime Contractor shall create a Subcontract DD 254 in the National Industrial Security Program Contract Classification System (NCCS). The Prime Contractor shall ensure that any teaming partners or subcontractors have the appropriate security clearances prior to contract award.

8.1.1 A SF 312 Non-Disclosure Agreement (NDA) initiated by the company’s Facility Security Officer (FSO) is required for each of the Contractor’s personnel.

8.2 Security Manager Appointment. The Contractor shall appoint a security manager. The security manager shall provide employees with training required by DOD 5200.1-R, Information Security Program Regulation. The Contractor will also provide initial and follow-on training to Contractor personnel who work in DHRA controlled/restricted areas.

8.3 Listing of Employees & Clearance Documentation. The Contractor shall maintain a current listing of employees. Within 10 calendar days of contract award, the Contractor shall provide the COR a list with the names, location of performance and clearance requirements of all company employees assigned to this effort. The list shall be validated and signed by the company Facility Security Officer (FSO). An updated listing shall be provided when an employee's status or information changes.

8.4 Controlled/Restricted Areas. The Contractor shall be compliant with local procedures for entry to DHRA controlled/restricted areas where Contractor personnel will work.

8.5 Physical Security. The Contractor shall safeguard all Government property and controlled forms provided for Contractor use and adhere to the Government property requirements contained in this contract. At the end of each work day, all Government facilities, equipment and materials shall be secured.

8.6 Pass and Identification Items. The Contractor shall ensure the pass and identification items required for contract performance are obtained for employees and non-government owned vehicles.

7 Ver: Mar 2019

8.6.1 Comply with HSPD-12 Personal Identity Verification (PIV) issuance requirements, known as the Common Access Card (CAC). Be responsible for obtaining CAC or PIV ready status prior to contract start.

8.6.2 The Contractor shall maintain a current listing of employees. Within 10 calendar days of contract award, the Contractor shall securely provide the COR a list with the names, social security numbers, and date of birth of all employees performing on the contract. An updated listing shall be provided when an employee's status or information changes.

8.7 Retrieving Identification Media. The Contractor shall retrieve all identification media, including vehicle passes from employees who depart for any reason before the contract expires;

e.g. terminated for cause, retirement, etc.

8.8 Weapons, Firearms, and Ammunition. Contractor employees are prohibited from possessing weapons, firearms, or ammunition, on themselves or within their contractor-owned vehicle or privately-owned vehicle while on all DHRA installations.

8.9 For Official Use Only (FOUO). The Contractor shall comply with DoD 5400.7-R, Chapter 4, DoD Freedom of Information Act (FOIA) Program, requirements. This regulation sets policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding FOUO material.

8.10 Reporting Requirements. Contractor personnel shall report to an appropriate authority any information or circumstances of which they are aware may pose a threat to the security of DOD personnel, Contractor personnel, resources, and classified or unclassified defense information.

8.11 Key Control/Access Badge Control. The Contractor shall establish and implement methods of making sure all keys/badges issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. The Contractor shall not duplicate any keys issued by the Government.

8.11.1 Prohibited Use. The Contractor shall prohibit the use of keys, issued by the Government, by any persons other than the Contractor’s employees and the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in performance of contract work requirements in those areas.

8.12 Lock Combinations. The Contractor shall control access to all government provided lock combinations to preclude unauthorized entry. The Contractor is not authorized to record lock combinations without written approval by the COR. Records with written combinations to authorized secure storage containers, secure storage rooms, or certified vaults, shall be marked and safeguarded at the highest classification level as the classified material maintained inside the approved containers.

8 Ver: Mar 2019

8.13 Government Furnished Equipment (GFE). The Contractor shall establish and implement procedures to ensure all GFE to include laptops and other data processing devices, issued to the Contractor by the Government are not lost or misplaced, are not used by unauthorized persons or are not subject to unauthorized external devices. The Contractor shall immediately report to the COR any occurrences of lost GFE within two (2) hours of discovery of occurrence. In the event that GFE is lost, the Contractor may be required, upon written direction of the CO, to replace the equipment at no additional cost to the Government. The Government may replace the equipment and deduct the cost of such from the monthly payment due the Contractor.

8.14 Conduct while on Government Installation. The CO may direct the contractor to remove an employee(s) from an assignment under this contract for reasons of security or misconduct. Where the reasons for the removal request is due solely for security or misconduct by the employee(s), the replacement shall be at the contractor’s expense and not chargeable to the government.

8.15 Information System Security. The Contractor shall implement Information System (IS) security protections and ensure the protections are appropriate to the confidentiality, integrity, and availability needs of the Government. Establish appropriate administrative, technical, and physical safeguards to protect any and all nonpublic Government data.

8.16. Risk Management Framework. All Information Systems (IS), Platform Information Technology (PIT) and Information Technology (IT) Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data must be accredited in accordance with Department of Defense (DOD) Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT) and comply with annual Federal Information Security Management Act (FISMA) security control testing. IS and PIT systems must be categorized in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, implement a corresponding set of security controls from the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.

8.16.1 All systems subject to RMF must present evidence of authorization in the System Security Plan (SSP), Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD Risk Management Framework (RMF) or equivalent DoD Component PIT system accreditation decision that is current within 3 years. Evidence of FISMA compliance must be presented in the form of a POA&M. Systems must have and maintain an Authority to Operate (ATO) or, if acceptable to the Government, an Interim Authority to Operate (IATO) by contract award.

8.17 Information security continuous monitoring (ISCM). ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur.

The Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all IS and PIT systems under this requirement in accordance with NIST SP 800-137.

9 Ver: Mar 2019

8.18 Cyber Incident Reporting. Within 48 hours of discovery of any cyber incident the Contractor shall notify the DHRA Information Management (IM) office by emailing a cyber incident report to the following organizational box:[list DHRA/IM email org box here] The Contractor shall also notify the COR and CO at the time the incident is reported to

DHRA/IM.

8.18.1 The Contractor shall rapidly (within 72 hours) report cyber incidents to the DoD at http://dibnet.dod.mil. Prior to contract award the Contractor shall obtain a medium assurance certificate at http://iase.disa.mil/pki/eca/Pages/index.aspx in order to timely report cyber incidents to the DoD.

8.19 System Security Plan (SSP) The Contractor shall develop, document, and periodically update a System Security Plan (SSP) and any associated plans of action developed to satisfy the adequate security requirements of DFARS 252.204-7012, and in accordance with NIST Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”. The SSP shall describe the Contractor’s unclassified information system(s)/network(s) where covered defense information associated with the execution and performance of this contract is processed, is stored, or transmits. The SSP shall be provided to the Government as part of the proposal.

8.19.1 The Contractor shall provide the Government with access to the SSP (or extracts thereof) and any associated plans of action for each of the Contractor’s tier one level subcontractor(s), vendor(s), and/or supplier(s), and the subcontractor’s tier one level subcontractor(s), vendor(s), and/or supplier(s), who process, store, or transmit covered defense information associated with the execution and performance of this contract.

8.19.2 The Contractor shall support independent on-site government assessment of compliance of NIST SP 800-171 and NIST SP 800-171A.

8.20 Identification and Marking of Covered Defense Information (CDI). Identify all covered defense information associated with the execution and performance of this contract. At the post-award conference the Contractor and the Government/Program Office shall identify and affirm marking requirements for all covered defense information, as prescribed by DoDM

5200.01 Vol 4, Controlled Unclassified Information, and DoDI 5230.24, Distribution Statements on Technical Documents, to be provided to the Contractor, and/or to be developed by the Contractor, associated with the execution and performance of this contract.

8.20.1 Tracking CDI. Track all covered defense information associated with the execution and performance of this contract. The Contractor shall document, maintain, and provide to the Government, a record of tier 1 level subcontractors, vendors, and/or suppliers who will receive or develop covered defense information – as defined in DFARS Clause 252.204-7012 and associated with the execution and performance of this contract.

10 Ver: Mar 2019

8.20.2 The Contractor shall restrict unnecessary flow down of covered defense information in accordance with marking and dissemination requirements specified in the contract and based on a ‘need-to-know’ to execute and perform the requirements of this contract. This shall be addressed and documented at the post-award conference.

8.21 Compliance with Cybersecurity and Privacy DoD Instructions and Directives. The Contractor and all Contractor personnel with access to or responsibility for nonpublic Government data under this contract shall be in compliance with the latest versions of:

DoD Instruction (DoDI) 8500.01, Cybersecurity DoD Instruction (DoDI) 8510.01, DoD Risk Management Framework (RMF) for DoD Information Technology (IT) The Privacy Act (5 U.S.C. 552a) DoD 5400.11-R, and DoD Directive 5400.11, DoD Privacy Program DoD 6025.18-R DoD Health Information Privacy Regulation DoD 5200.2-R, Personnel Security Program HSPD-12, Homeland Security Presidential Directive NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal

Information Systems and Organizations NIST SP 800-137, Information Security Continuous Monitoring

8.22 Cloud Computing. Any commercial cloud computing services used for this requirement must comply with the DoD Cloud Computing Security Requirements Guide and DoD Cloud Computing Supplemental Guidance and Information as published by the Defense Information Systems Agency (DISA).

8.23 Information Assurance Workforce Qualifications. The Contractor shall ensure information assurance workforce personnel have appropriate [specify qualification levels] qualifications in accordance with DoD 8570.01-m prior to contract award.

9.0 GOVERNMENT FURNISHED PROPERTY/EQUIPMENT/INFORMATION

(GFP/GFE/GFI) Use when the Government will provide property, equipment or information to Contractors for performance of the contract. Briefly describe what will be provided, e.g.

computers, data, reports, etc.

10.0 PLACE OF PERFORMANCE

State whether Contractors will be working in Government space/facility or at the Contractor’s facility. When you are providing office space for contractors in the National Capitol Region (NCR), identify the number of spaces available and include a copy of the approved Government Furnished Space Memorandum in your requirement package.

11.0 QUALITY CONTROL Use standard paragraph below

The contractor shall implement and maintain a Quality Control Plan (QCP) to ensure work performed conforms to the scope of work and meets the requirements under this PWS. The QCP shall, at a minimum provide a method for performing inspections; identifying, correcting and

11 Ver: Mar 2019 preventing problems/defective service; addressing customer complaints, and improving the quality of services over the life of the contract.

12.0 QUALITY ASSURANCE

12.1. The Government reserves the right to perform inspections and surveillance to evaluate the Contractor’s compliance to the contract terms and performance of the requirements in the PWS.

12.2. Contract Discrepancy Report (CDR). In the event of unsatisfactory contractor performance, the COR or CO will issue a CDR that will explain the circumstances and findings concerning the incomplete or unsatisfactory service. The contractor shall acknowledge receipt of the CDR and respond in writing as to how he/she shall correct the unacceptable performance and avoid a recurrence. The Government will review the contractor's corrective action response to determine acceptability and will use any completed CDR as part of an overall evaluation of Contractor performance when determining present or future contractual actions.

13.0 ORGANIZATIONAL CONFLICTS OF INTEREST Use when applicable.

The Contractor acknowledges that it is familiar with FAR Subpart 9.5, Organizational and Consultant Conflicts of Interest, and agrees to avoid, neutralize or mitigate such conflicts of interest in accordance with the principles set forth in the FAR. If the performance requires the Contractor (to include subcontractors) to supply technical support related to systems or projects with which the Contractor is already directly concerned, either by prime or subcontract, the Contractor shall immediately inform the Contracting Officer. The PWS may be withdrawn if a conflict is found. The Contractor shall not undertake performance of any PWS requirements which requires it to supply technical support regarding such systems until the notice is given, and written consent to proceed is issued by the Contracting Officer.

14.0 APPLICABLE DOCUMENTS List applicable documents in the chart with web links to the location where they can be accessed a shown in the example below.

Document Web link

15.0 PERFORMANCE REQUIREMENT SUMMARY (PRS)

15.1 Purpose. The PRS lists performance objectives for the required services the Government will surveil. The absence of any contract requirement from the PRS shall not detract from its enforceability nor limit the rights or remedies of the Government under any other provision of the contract including the clauses entitled “Inspection of Services” or “Inspection” or “Default” in Section E and Section I of the contract.

12 Ver: Mar 2019

15.2 Components. The PRS states the performance objective (required service), and threshold (performance standard, accept and reject points (if applicable)) in either a qualitative or quantitative fashion for each critical success factor.

Below is a sample PRS, you can tailor for your requirements

Performance Objective

PWS paragraph

Performance Standard/Acceptable Quality Level

Provide qualified people at TO start

1.2.2.1 Performance is acceptable when qualified personnel are on the job at TO start, unless previously negotiated by the CO

Maintain stable workforce 1.2.2.2 Less than 5% Lapse Rate across all contracted positions

Effectively replaces/ substitutes personnel

1.2.2.2 Performance is acceptable when:

a) Vacancies are filled with qualified personnel within 14 days of vacancy, unless approved in writing or otherwise directed in advance by the CO

AND

b) there is no mission impact due to position vacancies or unqualified personnel Develop and submit all required deliverables

Section 1, 1.2.4 Performance is acceptable when:

a) 100% of deliverable requirements are met and received on time

AND

b) critical information is accurate

16. Mandatory Training Requirement for Contractor:

Contractor employees performing under this contract shall complete the following mandatory trainings within 30 days of contract award and date of any option exercised. If additional mandatory training is required, amendment or modification will be issued to incorporate the changes.

1. DoD Training on Unauthorized Disclosures IAW OSD Memorandum dated September 19, 2017 and the training is currently available at https://securityawareness.usalearning.gov/disclosure/index.html

2. Privacy Act and Personally Identifiable Information IAW DoDD 5400.11 dated October 29, 2014 and the training is currently available at https://securityawareness.usalearning.gov/piiv2/index.htm

3. IT Security Awareness IAW 5 CFR 930.301 and the training is currently available at https://iatraining.disa.mil/eta/disa_cac2018/launchPage.htm

4. National Insider Threat IAW Executive Order 13587 and the training is currently available at https://securityawareness.usalearning.gov/itawareness/index.htm

13 Ver: Mar 2019

5. Counterintelligence Awareness and Reporting Training IAW DoDD 5240.06 and the training is currently available at https://securityawareness.usalearning.gov/cidod

The Contractor program manager shall provide a copy of its employee(s)’ training certificate to the Contracting Officer’s Representative (COR) to meet the mandatory training requirements.

The CORs shall maintain the contractor’s certificate(s) in the COR file or CORT.

File details come from the government source that posted it. Updated .