Draft PWS.pdf
PDF 459 KB Posted
- Attached to
- IT and Telecom – Cyber Security and Data Backup Federal contract opportunity
- Solicitation number
- N0017821R4413
About this file
This pre-solicitation synopsis announces an upcoming solicitation for Risk Management Framework (RMF) security authorization package creation and maintenance services in support of the Naval Surface Warfare Center Dahlgren Division (NSWCDD). The requirement will be set aside 100% for small businesses. NSWCDD intends to issue a firm-fixed-price solicitation on or around November 17, 2021, with proposals due at least 30 days later. The agency aims to make award by January 23, 2023 based on best value. Interested parties should monitor SAM and respond to the contracting specialist by the closing date to provide input on requirement finalization. The attached draft PWS and CDRLs describe the RMF and cybersecurity support services to be provided. The Industry Day slides provide an overview of the requirement that the agency may discuss prior to solicitation if able given the ongoing health situation.
View the file
Other files for this federal contract opportunity
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
C.1 BACKGROUND
The Naval Surface Warfare Center, Dahlgren Division (NSWCDD) Command (Code 00), Corporate Operations (Code 10) and Technical Departments which include: Strategic and Computing Systems (A-Department); Electromagnetic and Sensor Systems (B-Department); Gun and Electronic Weapon Systems (E-Department); Weapons Control and Integration (H- Department); Warfare Analysis and Digital Modeling (M-Department); Readiness and Training Systems (R-Department); and Integrated Combat Systems (V-Department) have a need for Risk Management Framework (RMF) security authorization packages and to provide RMF Authority to Operate (ATO) maintenance for the entire range of Information Systems (ISs) necessary for NSWCDD and its associated site (Dam Neck Activity (DNA), located in Dam Neck, VA) to meet mission and operational objectives. RMF is the Department of Defense (DoD) process for identifying, implementing, validating, certifying, and managing Cybersecurity (CS) capabilities and services, expressed as Security Controls, Assessment Procedures (APs), and for authorizing the operation of DoD Information Systems (ISs), including testing in live/operational or Research, Development, Test, and Evaluation (RDT&E) environments, in accordance with statutory, federal, and DoD requirements.
C.2 SCOPE
This Performance Work Statement (PWS) defines the requirements for RMF support for Information Technology (IT) Systems supported by NSWCDD personnel, located in Dahlgren and Dam Neck Virginia. This effort primarily includes Information Assurance (IA)/Cybersecurity policy and control evaluations, preparation of supporting RMF and current Government approved process for packages and artifacts, implementation of security postures, and Subject Matter Expertise (SME) in IA/Cybersecurity Life-Cycle management, coordination, implementation, and deployment via the Naval Sea Systems Command (NAVSEA) Functional Authorizing Official (FAO) and the Navy Authorizing Official (NAO). The scope of this effort also encompasses the RMF work to be performed by NSWCDD personnel for IT Systems under the purview of the Naval Air Systems Command (NAVAIR) FAO, Defense Threat Reduction Agency (DTRA), Army, Marine Corps processes, and/or other Authorizing Officials. Performance will be measured against the requirements of the Performance Work Statement (PWS) and standards laid out in Attachment J.# (QASP)
C.3 APPLICABLE DOCUMENTS
The following documents are applicable to this Performance Work Statement (PWS).
Document No. Title Date
DISN CPG Defense Information Systems Network (DISN) Connection Process Guide, Version 5.1 https://www.disa.mil/~/media/Files/DISA/Services/DISN- Connect/References/DISN_CPG.pdf
Sep-16
DoD 5400.7- R
Department of Defense Freedom of Information Act Program http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/540007p.
Sep-98
DoD 8570.01-M
Information Assurance Workforce Improvement Program, Incorporating Change 4 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/857001 m.pdf
10-Nov-15
DOD Cloud
CPG V2.0
Department of Defense (DoD) Cloud Connection Process Guide, Version 2 https://www.disa.mil/~/media/Files/DISA/Services/DISN- Connect/References/CCPG.pdf
Mar-17
DOD Cloud
SRG V1R3
Department of Defense (DoD) Cloud Computing Security Requirements Guide, Version 1 Release 3 https://rmf.org/wp-content/uploads/2018/05/Cloud_Computing_SRG_v1r3.pdf
6-Mar-17
DoD Instruction 8551.01
Ports, Protocols, and Services Management (PPSM) Incorporating Chg 1 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/d odi/855101p.pdf
27-Jul-17
DoDD 8140.01
Cyberspace Workforce Management http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/814001_2 015_dodd.pdf
11-Aug-15
DoDI 8500.01
Cybersecurity http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2 014.pdf
14-Mar-14
DoDI 8510.01
Risk Management Framework (RMF) for DoD Information Technology (IT), Incorporating Chg 1 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2 014.pdf
24-May-16
DON CIO
Memorandu m 02-10
Information Assurance Policy Update for Platform Information Technology http://www.doncio.navy.mil/contentview.aspx?id=873
26-Apr-10
Joint Travel Reg
The Joint Travel Regulations http://www.defensetravel.dod.mil/Docs/perdiem/JTR.pdf
1-Oct-17
NAVSEA
9400.2-M
NAVSEA PIT-Control System Cybersecurity Implementation Manual, Version 5.0 https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocume nts%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation &FolderCTID=0x0120001D3 A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C
%2D4941%2DB568%2D7891
6015EBAD%7D
Oct-16
NAVSEA
FAO RMF
CPIG
NAVSEA Functional Authorizing Official Risk Management Framework Conversion Process Implementation Guidance https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocume nts%2FAnA%20News%20You%20Can%20Use%2FRMF%20Bridge%20Co nversion&FolderCTID=0x01 20001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%
2D0A7C%2D4941%2DB568
%2D78916015EBAD%7D
11-May-17
NAVSEA
Website
NAVSEA Enterprise Cybersecurity website:
https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx#
19-Jan-18
NAVSEAIN
ST 5239.2B
Naval Sea Systems Command (NAVSEA) Cybersecurity Program https://navsea.navy.deps.mil/field/cnrmcmarmc/ 1100/cybersecurity/Cybersecurity%20Library/Mock_25Feb_IG/NAVSEA- 5239.2B.pdf#search=5239%2E2B
20-Sep-16
NIST SP
800-37
Guide for Applying the Risk Management Framework to Federal Information Systems, Revision 1, February 2010 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf
5-Jun-14
NIST SP
800-53
Security and Privacy Controls for Federal Information Systems and Organizations, Revision 4, April 2013 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
22-Jan-15
NIST SP
800-53A
Assessing Security and Privacy Controls in Federal Information Systems and Organizations, Revision 4 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf
18-Dec-14
NSWCDDIN
ST 5239.6
Series
Policy on Portable Electronic Devices https://wwwdd.csd.disa.mil/program/iaweb/guidance/dahlgren.php
16-Dec-14
RDT&E
A&A Policy
Research, Development, Test and Evaluation Assessment and Authorization Policy for Isolated Enclaves https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocume nts%2FAnA%20News%20You%20Can%20Use%2FIsolated%20Enclave%2 0Policy%5FRDTnE&FolderC TID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D
3A4AD%2D0A7C%2D4941
%2DB568%2D78916015EBAD%7D
11-Apr-17
RPG 3.2 Risk Management Framework Process Guide, Version 3.2 https://portal.secnav.navy.mil/orgs/OPNAV/N2N6/DDCION/Policies/DDCI ON%20Guide%20- %20USN%20RMF%20Process%20Guide%20v3.2.pdf#search=rpg%203%2 E2
2-Sep-20
SECNAV M-
5239.2
Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification Manual https://doni.daps.dla.mil/SECNAV%20Manuals1/5239.2%20(2016).pdf
Jun-16
SECNAV M-
5510.36
Department of the Navy Information Security Program https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocume nts%2FAnA%20News%20You%20Can%20Use%2FVarious%20Classificati on%20Guides&FolderCTID= 0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4
AD%2D0A7C%2D4941%2D
B568%2D78916015EBAD%7D
Jun-06 https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx
SECNAVINS
T 5239.3C
Department of the Navy Cybersecurity Policy https://doni.documentservices.dla.mil/Directives/05000%20General%20Man agement%20Security%20and %20Safety%20Services/05- 200%20Management%20Program%20and%20Techniques%20Services/5239 .3C.pdf
2-May-16
SPAWAR
Memorandu m 5000 Ser 5.0/362
Navy Qualified Validator (NQV) https://usff.navy.deps.mil/sites/fccc10f/ odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllIte ms.aspx?RootFolder=%2 Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Fra mework%20RMF%2FRefere nces&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB2 1C8092BDDC5F94&View={
BFB9943D-D8DC-4363-8003-46D6928A3CB7}
19-Apr-16
USN RMF
Strategy
US Navy Risk Management Framework Implementation Strategy https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocume nts%2FAnA%20News%20You%20Can%20Use&FolderCTID=0x0120001D
3A817011E188468310622FC
CDCF5D8&View={64D3A4AD-0A7C-4941-B568-78916015EBAD}
1-Feb-17
Note: The applicable documents listed in this Section may be revised, reissued, or superseded throughout the performance of this PWS. When such is the case, the requirements of the superseding document shall take precedence.
C.4 DESCRIPTION OF SERVICES
NSWCDD has a requirement to support the Command in Cybersecurity policy and control evaluations, preparation of supporting RMF and current Government approved process for packages and artifacts, implementation of security postures, and Subject Matter Expertise (SME) in IA/Cybersecurity Life-Cycle management, coordination, implementation, and deployment via the Naval Sea Systems Command (NAVSEA) Functional Authorizing Official (FAO) and the Navy Authorizing Official (NAO).
On-site services will also be required at NSWCDD DNA. The Contractor shall provide recommended solutions for technical IT issues and perform to the standards, and the degree of ability, knowledge, skills and timeliness required in the PWS. The Contractor shall have the capability of developing technologies and have the technical expertise to transition into new operating environments.
The following Paragraphs describe the required A&A support services in detail.
C.4.1 RMF Package Creation
C.4.1.1 The Contractor shall provide RMF ashore and customer/afloat package creation and RMF ATO maintenance support throughout the lifecycle of the IT system. The Contractor shall fulfill Information System Security Engineer (ISSE) assignments in accordance with RMF to assess and authorize new ISs, and re-authorize existing system packages. The Contractor shall also fulfill assignments in accordance with RMF to provide package creation and maintenance support for ISs determined to be Assess Only or Non-IT Designation. These systems are primarily located at NSWCDD and its detachments listed in Section 1.0. IT Systems supported on this contract are primarily under NAVSEA FAO and NAO, but may be under the purview of the Naval Air Systems Command (NAVAIR) FAO, Defense Threat Reduction Agency (DTRA), Army, Marine Corp processes, and/or other Authorizing Officials. The Contractor will not be required to perform internal or external penetration testing on ISs.
The Contractor shall provide a staffing plan document to encompass each requirement location.
The Contractor shall deliver A&A creation and maintenance of packages; project planning schedules and charts; provide presentations on A&A creation; and provide maintenance documentation of changes and updates applied to Systems and Networks in accordance with CDRL A001, CDRL A002, and CDRL A003.
C.4.1.2 The Contractor shall assist NSWCDD and NSWC Dam Neck System POCs with developing overall RMF improvement strategies (i.e., inheritance, template utilization) to streamline approval processes and reduce the timeframe for overall RMF processing. Contractor shall also provide bi-monthly training and lessons-learned to System Representatives on best practices and strategies improve RMF workflows. (CDRL A003)
C.4.1.3 The Contractor shall provide all required information assurance/A&A document creation/preparation services and/or A&A maintenance services for security authorization packages throughout the lifecycle of the IT system. Creation/preparation services and/or A&A maintenance services includes standard RMF packages (to include PIT), Non-IT Designation packages, Assess Only packages, Interim Authorization to Test (IATT) packages, and Warfare Center Interim Authorization to Connect (IATC) documentation.
C.4.1.4 The Contractor shall have direct knowledge of Enterprise Mission Assurance Support Service (eMASS) and a minimum of six (6) years of experience utilizing the Navy’s instance of eMASS. Additionally, the Contractor shall have performed duties previously as an ISSE for Navy RMF packages, which resulted in the granting of thirty (30) or more RMF Authorizations to Operate (ATOs).
C.4.1.5 The Contractor shall adhere to the respective Authorizing Official-specific processes to identify and properly manage the risk of IT Systems in accordance with the DoD Instruction (DoDI) 8510.01, RMF for DoD Information Technology (IT), and when applicable, taking into consideration Navy–unique operational and environmental demands detailed in the Department of Navy Risk Management Process Guide and all superseding updates to the document. The Contractor shall follow the published Authorizing Official/Echelon II Business Rules (see Section 2) and supplemental Guidance (i.e., NAVSEA A&A News You Can Use notifications). The Command Information System Security Manager (ISSM) in coordination with the respective Authorizing Official will resolve any conflict between these rules.
C.4.1.6 The Contractor shall collaborate with the designated Authorizing Official (AO) (Navy Authorizing Official (NAO) or Functional Authorizing Official (FAO)) and their representatives for Platform IT (PIT) Afloat, PIT Ashore, RDT&E Zone A, B, C, D, and Cloud-based environment packages throughout all steps of the RMF process. Collaborate with the designated Naval Authorizing Official (NAO) and/or their representatives for Defense Business Systems (DBS), Zone A, Afloat Site, and all packages categorized as HIGH Risk, throughout all steps of the RMF process. The Authorizing Official responsible for package authorization may change at the discretion of the Government.
C.4.1.7 The Contractor shall ensure that any IT system functioning/being operated under a legacy DIACAP or PIT accreditation will be transitioned to RMF under package creation services.
There are currently over 10 legacy systems under DIACAP or PIT accreditation, of which the Government plans to transition to RMF. Over the past five years, a total of two (2) legacy systems have been transitioned to RMF. The Government expects the number of transitions to remain consistent until all remaining legacy systems are transitioned.
C.4.1.8 The Contractor shall ensure that any newly established IT systems assigned to the Contractor will be transitioned to RMF under package creation services.
C.4.1.9 The Contractor shall ensure maintenance services will be provided/included for any newly created packages throughout the year the ATO for that package was awarded as part of the package creation service. One (1) year following the award of the ATO, the package will then transition under A&A maintenance services and be charged accordingly.
C.4.1.10 The Contractor shall create/develop A&A artifacts such as to: PIT Designation, System Categorization, Security Plan (SP), Implementation Plan, Security Assessment Plan (SAP), Security Assessment Report (SAR), Privacy Impact Assessment (PIA), Risk Assessment documents, System Level or Information System Continuous Monitoring (SLCM) Strategy, hardware/software lists, and network/architecture diagrams for all assigned ISs as required by DoD, DON, NAVSEA, NSWCDD, and Navy Enterprise Mission Assurance Support Service (eMASS). (CDRL A003)
C.4.1.11 The Contractor shall collect, collaborate, or conduct vulnerability scans for all applicable environments and interpret results with Authorizing Official/Security Control Assessor (SCA)-accepted tools. Networked environments shall be scanned monthly. Non-networked/isolated environments shall be scanned quarterly.
C.4.1.12 The Contractor, during package creation activities, shall analyze, remediate (after coordinating with the respective System Administration team or System ISSO), and document vulnerabilities by:
• Performing vulnerability analysis;
• Remediating vulnerabilities posing a corresponding risk to operations (e.g., remove or quarantine); and
• Documenting residual risks into Plan of Action and Milestones (POA&Ms), Risk
Assessments and other applicable documents in eMASS.
C.4.1.13 The Contractor shall provide vulnerability scanning through the Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP) of the ISs (or subsequent tools mandated by Authorizing Officials). The Contractor is not expected to provide any scanning tools or scanning software licenses for this contract. Contractor scans shall either include full authorization boundaries or include sampling of authorization boundaries, as directed by the Government.
C.4.1.14 The Contractor shall scan and apply remediation (after coordinating with the respective environment System Administrator or System Representative) in accordance with the Defense Information Security Agency (DISA) Security Technical Implementation Guide (STIG), Security Requirements Guide (SRG), Security Readiness Review (SRR), and generate DISA checklists and/or artifacts.
C.4.1.15 The Contractor shall coordinate and collaborate with the respective System Administrator Team or System Representative before applying mitigation and remediation actions.
The Contractor will ensure mitigation and remediation actions are first applied to a sample environment/asset and receive concurrence from the System Administrator Team or Representative that the sample environment/asset still functions as desired before proceeding with applying remediation to the entire boundary. In the event of technical problems because of remediation (i.e., asset not functioning as desired), the Contractor will work with the appropriate System Administrator or Representative to “roll back” any changes and document them accordingly in the POA&M.
C.4.1.16 The Contractor shall prepare ISs for the authorization process within the timeframes outlined in 4.1.16. The Contractor shall perform ACAS and SCAP scans, all applicable Security Technical Implementation Guide (STIG), Security Requirements Guide (SRG), Security Readiness Review (SRR) checks, DISA checklists, and remediate system assets to acceptable levels as required by the ISSM or respective Information System Security Officer (ISSO). The Contractor shall create all documentation to prove compliance with requirements utilizing eMASS.
C.4.1.17 The Contractor shall collectively complete and submit all ISO/ISSE required tasks for each RMF step within the timeline identified.
• RMF Step 1 – Six (6) business days
• RMF Step 2 – Ten (10) business days
• RMF Step 3 – Thirty (30) business days
• RMF Step 4 – Twenty (20) business days
• RMF Step 5 – Ten (10) business days
• RMF Step 6 - Twenty (20) business days
C.4.1.18 The Contractor shall ensure in the event RMF is replaced by a new cybersecurity standard, the scope of required services in this PWS shall continue in accordance with the requirements identified in the new standard.
C.4.2 RMF Package Maintenance
The Contractor shall perform A&A maintenance for all assigned PIT (Afloat, Ashore, Site, Non-Navy), and assigned RMF authorization packages, including re-authorization efforts. The Contractor shall also fulfill assignments in accordance with RMF to provide package maintenance support for ISs determined to be Assess Only or Non-IT Designation. The tasking shall include creating, updating, and documenting all required artifacts.
C.4.2.1 The Contractor shall ensure any RMF Bridge Conversion (RBC) packages are maintained appropriately using the RMF eMASS record including obtaining a full ATO under maintenance services.
C.4.2.2 The Contractor shall ensure the A&A documentation is maintained for any IT System functioning under an expired RMF or RBC authorization under maintenance services to include ATO renewal.
C.4.2.3 The Contractor shall ensure maintenance is provided/included for any new packages created throughout the year the ATO was awarded for that package as part of the package creation services. One (1) year following the award of the ATO, the package will then transition under maintenance services.
C.4.2.4 The Contractor shall perform all requirements to prepare ISs for the re-authorization process by making them compliant within the timeframe identified above. Create all required RMF re-authorization package documentation and artifacts, as necessary. Re-authorization requirements include, but are not limited to, adhering to the Navy RPG, performing ACAS, SCAP scans, all required STIG checks and remediating system assets to acceptable levels in accordance with the PWS. The Contractor shall scan for vulnerability findings and apply remediation in accordance with the DISA STIGs, SRG, SRR tools, and shall generate DISA checklists and/or artifacts within the same timeframe. The Contractor shall utilize eMASS, other repositories, and tools to create and contain all documentation to prove compliance with requirements. The Contractor shall provide any additional artifacts to complete authorization and re-authorization packages based on each package’s unique requirements.
C.4.2.5 The Contractor shall evaluate all vulnerabilities identified during the A&A processes and recommend mitigation measures to System Administrator and System ISSO for reducing or eliminating identified risk items.
C.4.2.6 The Contractor shall perform remediation actions after collaborating with the respective System Administrator or System Representative for each IS, including STIG/SRG/SRR requirements and/or remediation, ACAS scanning and remediation, eMASS requirements, VRAM maintenance, and security control updates and reconciliation. The Contractor shall perform reconciliation of the POA&M and all applicable documentation based on security scans.
C.4.2.7 The Contractor shall work with the ISSO and the ISO to determine and implement (if necessary) fixes/mitigation for weaknesses and to determine the level of revalidation testing that is necessary.
C.4.2.8 The Contractor shall address all conditions and or stipulations identified in ATO and PIT Risk Assessment (PRA) letters.
C.4.2.9 The Contractor shall ensure that all cybersecurity requirements are addressed for A&A package maintenance.
C.4.2.10 The Contractor shall update all relevant security artifacts such as: the PIT Designation, System Categorization, Security Plan (SP), Implementation Plan, Security Assessment Plan (SAP), Security Assessment Report (SAR), Privacy Impact Assessment (PIA), POA&M, Risk Assessment documents, System Level or Information System Continuous Monitoring (SLCM) Strategy, hardware/software lists, and network/architecture diagrams based on the results of the continuous monitoring process for all assigned ISs. All documents shall be updated and uploaded in eMASS.
C.4.2.11 The Contractor shall complete development of system artifacts and appropriate ISSE testing to satisfy recurring review requirements (Annual Security Reviews, Quarterly Reviews, FISMA Reviews, Continuous Monitoring activities, etc.) for the authorized ISs as a result of maintenance performed and change management activities.
C.4.2.12 The Contractor shall self-assess, document, and report all security controls within eMASS.
C.4.2.13 The Contractor shall perform an Annual Security Review (ASR) of Security Controls and APs for the authorized ISs and document within eMASS.
C.4.2.14 The Contractor shall report the security status of the ISs (including the effectiveness of security controls employed within and inherited by the system) to the AO – through the Command ISSM – and other appropriate organizational officials in accordance with the monitoring strategy in the monthly status updates in accordance with CDRL A002.
C.4.2.15 The Contractor shall review the reported security status of the ISs (including the effectiveness of security controls employed within and inherited by the ISs) on an ongoing basis, in accordance with the monitoring strategy, to determine whether the risk to operations, organizational assets, individuals, or other organizations remains acceptable.
C.4.2.16 The Contractor shall provide support to the responsible IT System ISSO or System Representative (as requested) to prepare various documentation to support RMF submissions, various A&A projects, and inspections (i.e., Inspector General) such as Ports, Protocols, and Services Management (PPMS) registration submission, Tabletop Mission Cyber Risk Assessment (TMCRA), Conditional Authorization Requests (CARs), Memorandums of Understanding (MOUs)/Memorandums of Agreement (MOAs), security agreements, Concept of Operations (CONOPS) documents and waivers (as necessary) to include Public Key Infrastructure (PKI), and Host Based Solution Services (HBSS)), and DoDIN.
C.4.2.17 The Contractor shall assist the Government with determining the security impact of proposed or actual changes to the ISs and their environment of operation.
C.4.2.18 The Contractor shall routinely monitor configuration management of the assigned NSWCDD IT Systems, updating respective IT system Security Authorization Packages as needed, preparing necessary Authorization Modification (i.e., "Use Case" or Memorandum for Record (MFR)) documentation, and ensuring approvals are documented.
C.4.2.19 The Contractor shall adhere to required package maintenance intervals (i.e., daily, weekly, monthly, quarterly, annually) and updating IT System documentation as dictated by IT system configuration management system Change Control Board (CCB) (hardware/software addition/removal) to include vulnerability scanning intervals, etc.
C.4.2.20 The Contractor shall maintain the IS artifacts, update artifacts based on change management and perform reporting as required by DoD, DON, NAVSEA, NSWCDD, and eMASS.
C.4.2.21 The Contractor shall self-assess, document, and report all security controls within eMASS.
C.4.2.22 The Contractor shall capture meeting minutes from any and all A&A related collaboration meetings (informal, formal, adhoc, or otherwise) pertaining to the assigned IT System and provide said minutes to the Government Technical Points of Contact (TPOCs) in accordance with CDRL A006.
C.4.2.23 The Contractor shall determine when the updated Security Authorization Package is ready, complete, and of adequate quality for submission to external organizations (i.e., NAVSEA, NAO, SPAWAR) for review as required.
C.4.2.24 The Contractor shall be responsible for conducting the ISSM Quality Review (i.e., ensure NAVSEA/NAO checklists are accurate and complete) and advising the ISSM when packages are complete and ready for submission to external organizations (i.e., NAVSEA, NAO).
C.4.2.25 The Contractor shall prepare NAVSEA Trusted Package Submitting Officer (PSO) briefing material, such as draft Authorization to Operate letters and brief NAVSEA personnel to include Technical Area Experts (TAEs), FAOs, and/or their representatives during any and all RMF Checkpoint or Collaboration Meetings. (CDRL A007)
C.4.2.26 The Contractor shall respond when necessary by phone or e-mail to the Government Technical Points of Contact (TPOCs) or ISSM requests within one (1) business day.
C.4.2.27 The Contractor shall respond in writing to all package update requests (made by NAVSEA, NAO, etc.) within two (2) business days.
C.4.2.28 The Contractor shall make all ISSE required package updates in accordance with DOD, DON, and NAVSEA requests and requirements within three (3) business days. If more time is required, this must be coordinated with the Government Technical Points of Contact (TPOCs).
C.4.2.29 The Contractor shall provide hardware and software data gathered/updated during the RMF process (creation and maintenance) for inclusion in the applicable local asset-tracking database (i.e., NSWCDD Internet Protocol and Authorization (IPA) Database, Dell KACE). The Contractor shall ensure the data is provided in a format that is capable of being imported into the respective database.
C.4.2.30 The Contractor shall allow usage of any NSWCDD tools (i.e., Findings Management and Tracking System (FMATS), Internet Protocol and Authorization (IPA)) and applications developed for NSWCDD Package creation and maintenance by System Administrators or System Representatives for the duration of the contract and lifecycle of the
ATO.
C.4.2.31 The Contractor shall utilize NSWCDD or Warfare Center tools (as determined by the NSWCDD ISSM) (i.e., eMASSTer, STIG Manager, Evaluate STIG, Findings Management and Tracking System (FMATS), Internet Protocol and Authorization (IPA)) and applications developed for NSWCDD Package creation and maintenance for the duration of the contract and lifecycle of the ATO.
C.4.2.32 The Contractor shall ensure that any proprietary tools and applications/software, scripts etc. related to completion of A&A tasks used by, or developed during contract performance by the Contractor, will be available for use by the Government, at no additional cost, for the life of the contract.
C.4.2.33 The Contractor shall collaborate with Department resources as necessary for the potential development of tools, applications, and overall A&A strategies that may enhance or streamline the A&A documentation process.
C.4.2.34 The Contractor shall develop all necessary A&A documentation and upon completion deliver to System Representative (i.e., System ISSO/Program Manager) for acceptance on the Program’s behalf. System Representative shall ensure documentation accurately represents the IT System.
C.4.2.35 The Contractor shall provide a completion report to the respective System Representatives for all IT systems under maintenance that identifies the tasks done to complete the overall maintenance effort.
C.4.3 HOURS OF OPERATION AND COVERAGE
C.4.3.1 On-site Contractor personnel shall provide required services and staffing coverage for NSWCDD during normal business hours (Monday through Friday).
C.4.3.2 On-site Contractor shall be structured to allow for broadest range of support coverage in a specified work area during their arrival and departure of the workday.
C.4.3.3 All Contractor employees are encouraged to work in accordance with the same schedules as the Government office that they are supporting.
C.4.4 ABSENCE/LATE ARRIVAL
The Contractor shall notify the Governments TPOC via telephone or email for any delayed arrival or absence of on-site Contractor personnel as soon as possible
C.4.5 TELEWORK
C.4.5.1 Telework for Contractor personnel will be at the discretion of the Contractor and will not require Government TPOC and COR concurrence.
C.4.5.2 Government requires notification of telework days/schedule.
C.4.5.3 In the event of telework, the Contractor shall track all Government Furnished Equipment (GFE)/Government Furnished Property (GFP), listing personnel, asset tag numbers and serial numbers for all Navy/Marine Corps Intranet (NMCI) computer equipment in the Contractor’s possession (CDRL A004). All equipment shall be returned to the Government by the end of the Task Order or when equipment is no longer in use, whichever comes first.
C.4.6 WORK LOCATION
The primary work location is at NSWCDD, which includes the primary locations of Dahlgren, VA, and Dam Neck Activity (DNA), Virginia Beach, VA.
C.5 MANDATORY REQUIREMENTS
Mandatory Requirements must be maintained throughout the life of the Task Order. The mandatory requirements are as follows:
C.5.1 Requirement 1 - Facility Security Clearance: The Contractor’s primary facility for supporting this Task Order is required to have a clearance of SECRET.
C.5.2 Requirement 2 - Personnel Security Clearances: All personnel providing technical support under this requirement must possess clearances at the SECRET level or higher.
C.5.3 Requirement 3 - Personnel Certification and Requirements
C.5.3.1 The Contractors shall maintain Information Assurance (IA) certification and requirements throughout the delivery period in accordance with DoD 8570.01-M or successor and NSWCDDINST 5239.4C. Senior Systems Security Engineers shall maintain certification and requirements at the IA Workforce (IAWF) designation of Information Assurance Management (IAM) Level III, while Systems Security Engineers shall maintain certifications and requirements at the IAM Level II or higher designation. Contractors that require privileged use shall maintain the appropriate Information Assurance Technology (IAT) certification (IAT
II).
C.5.3.2 The Contractors that require privileged use shall have the appropriate Information Technology (IT) designation: IT-1 for privileged use and IT-2 for non-privileged use.
C.6 SKILLS AND TRAINING
The Contractor shall provide capable personnel with qualifications, experience levels, security clearances, and necessary licenses, certifications, and training required by Federal, State and
Local laws and regulations. Information assurance functions require certifications specified in
DFARS 252.223-7001 INFORMATION ASSURANCE CONTRACTOR TRAINING AND
CERTIFICATION. Training necessary to ensure that personnel performing under this Task Order maintain the knowledge and skills to successfully perform the required functions is the responsibility of the Contractor. Training necessary to maintain professional certification is the responsibility of the Contractor.
C.7 TRAVEL REQUIREMENTS
C.7.1 Contractor Travel Requirements
(a) During the performance of this effort, Contractor personnel may be required to travel to other sites to support program activities. Reimbursable travel costs for travel performed from the Contractor's facility to NSWC Dahlgren and/or NSWCDD DNA and from NSWC Dahlgren and/or NSWCDD DNA to the Contractor's facility is unallowable.
(b) The numbers of trips and types of personnel traveling shall be limited to the minimum required to accomplish work requirements and shall be coordinated with the COR via the specific work area Program Manager.
Projected travel destinations include:
• NSWCDD, Dahlgren, VA
• NSWCDD Dam Neck Activity (DNA), Virginia Beach, VA
• NAVSEA, Washington Navy Yard, Washington, DC
• NSWCPHD, Port Hueneme, CA
C.7.2 Materials and Equipment During the performance of this Task Order, there will not be materials or equipment authorized for purchase. The Contractor is responsible for any and all materials/equipment necessary to perform the work under the PWS.
C.8 GOVERNMENT FURNISHED EQUIPMENT AND MATERIALS
C.8.1 Government Furnished Office Space
The Government will provide office space to include all NSWCDD allowable IT equipment, phone, and general office supplies.
Base Year Opt Year I
Opt Year
II
Opt Year
III
Opt Year
IV
TOTAL
ON SITE TOTAL 8 8 8 8 8 40
C.8.2 Government Furnished Materials
The Government will provide additional GFE and Government Furnished Information (GFI), as required by the individual tasking to the Contractor. Laptops will be provided as GFP and can be found in Attachment J.??. The Contractor shall report the status of all GFE. (CDRL A004)
C.9 GOVERNMENT FURNISHED INFORMATION
C.9.1 The Government will provide access to information and documentation required for Task Order performance.
C.9.2 All information and documentation shall be retained at the Government work site.
C.9.3 The Government will provide access to the Navy A&A Tracking System, eMASS.
C.9.4 The Government will provide non-disclosure agreements and conflict of interest statements.
C.10 SECURITY REQUIREMENTS
The Department of Defense Contract Security Classification Specification (DD Form 254) (Attachments J.??) provides the security classification requirements for this order. The Contractor shall obtain facility and personnel security clearances at the level required by the Department Industrial Security Program prior to starting to work on tasks requiring clearances. Access to classified spaces and material and generation of classified material shall be in accordance with the attached DD Form 254. All personnel performing on-site must maintain the appropriate level security clearance. Some positions will require IT-Level 1 designation. In accordance with DoD/DON CSWF requirements, Contractors designated with IT Level-I are required to have at a minimum, a SECRET clearance based upon a favorably adjudicated T5/T5R completed within the last 6 years. Contractor employees that do not have a final clearance investigation within Defense Information Security System (DISS) are ineligible for IT Level-I designation until the T5/T5R has been favorably adjudicated, shall remain at IT level-II status in JPAS and shall not be assigned to a Task Order position requiring IT Level-I designation.
C.10.1 Facility Clearance: The Contractor shall possess and maintain a SECRET Facility Clearance as verified within the National Industrial Security System.
C.10.2 Physical Security: The Contractor shall be responsible for safeguarding all Government information or property provided for Contractor use. At the end of each work period, Government information, facilities, equipment and materials shall be secured as specified by the NISPOM and the NSWCDD Command Security Manual. No SECRET storage is required at the Contractor’s facility in order to meet requirements of receiving and generating classified material in accordance with this Task Order.
C.10.3 The Contractor shall require access to Communications Security (COMSEC) in order to use crypto keying material. Access to Non-SCI intelligence is needed in order to utilize intelligence documents related to foreign Government weapons systems. Access to NATO is required to obtain a SIPRnet account and to utilize the DTIC system to obtain documents on intelligence. Access to Foreign Government Information is not required to obtain documents on specific weapon systems. Controlled Unclassified Information (CUI), to include For Official Use Only (FOUO) and Personally Identifiable Information (PII), generated and/or provided under this contract shall be safeguarded and marked as specified in DoD 5400.7-R Chapters 3 and 4. All above accesses are needed to support and provide the system engineering, software development, and maintenance of Navy tactical initiatives and spiral and baseline developments to support NSWCDD. In performing under this contract, the Contractor shall have access to U.S. classified information.
C.10.4 Portable Electronic Devices (PEDs)
(a) Non-Government and/or personally owned portable electronic devices (PEDs) are prohibited in all NSWCDD buildings with the exception of personally owned cell phones which are authorized for use in spaces up to and including Controlled Access Areas. The Contractor shall ensure the onsite personnel remain compliant with this PED policy. NSWCDD instruction defines PEDs as the following: any electronic device designed to be easily transported, with the capability to store, record, receive or transmit text, images, video, or audio data in any format via any transmission medium. PED’s include, but are not limited to, pagers, laptops, radios, compact discs and cassette players/recorders. In addition, this includes removable storage media such as flash memory, memory sticks, multimedia cards and secure digital cards, micro-drive modules, ZIP drives, ZIP disks, recordable CDs, DVDs, MP3 players, iPad, digital picture frames, electronic book readers, kindle, nook, cameras, external hard dish drives, and floppy diskettes.
(b) Personal Wearable Fitness Devices (PWFDs) marketed primarily as fitness or sleep devices are allowed in all Navy spaces where collateral non-Sensitive Compartmented Information (SCI), classified information is processed, stored, or discussed up to and including secret. User must ensure PWFD is compliant with all requirements in NAVADMIN 216/15, Cyber Hygiene Authorization to use Personal Wearable Fitness Devices (e.g., Fitbit, Jawbone UP, etc.) in Navy Spaces, dated 14 September 2015 and register PWFD in the NSWCDD Fitness Device Tracker.
(c) PED’s belonging to an external organization shall not be connected to NSWCDD networks or infrastructure without prior approval from the NSWCDD Information Assurance and Compliance Branch. This approval will be granted using the TARIS form and action tracker process.
(d) Personally owned hardware or software shall not be connected or introduced to any NSWCDD hardware, network or information system infrastructure.
C.10.5 Electronic Spillages
(a) Electronic spillages (ES) are unacceptable and pose a risk to national security. An electronic spillage is defined as classified data placed on an information system (IS), media or hardcopy document possessing insufficient security controls to protect the data at the required classification level, thus posing a risk to national security (e.g., sensitive compartmented information (SCI) onto collateral, Secret onto Unclassified, etc.). The Contractor's performance as it relates to ES will be evaluated by the Government. ES reflects on the overall security posture of the Government and a lack of attention to detail with regard to the handling of classified information of IS security discipline and will be reflected in the Contractor's performance rating. In the event that a Contractor is determined to be responsible for an ES, all direct and indirect costs incurred by the Government for ES remediation will be charged to the Contractor.
(b) NSWCDD Command Security will be responsible for the corrective action plan in accordance with the security guidance reflected on the DOD Contract Security Classification Specification - DD254. NSWCDD Security will identify the Contractor facility and Task Order number associated with all electronic spillages that involve the Contractor. NSWCDD Security will identify the Contractor facility and Task Order number associated with all electronic spillages that involve the Contractor. NSWCDD Security will notify the Contracts Division with the Contractor facility to capture name and Task Order number, incident specifics and associated costs for clean-up. The Contracting Officer will be responsible to work with the Contractor Facility to capture the costs incurred during the spillage clean up. The Contractor is also responsible for taking Information Security Awareness training annually, via their Facility Security Officer (FSO), as part of the mandatory training requirements. If a spillage occurs additional training will be required to prevent recurrence.
C.10.6 Operations Security (OPSEC)
Contractor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information, personnel, facilities, equipment, and operations from compromise. All Contractors (including Sub-contractors) shall supplement their current security practices by requiring any personnel involved in executing this Task Order to complete Government -sponsored and administered Operations Security (OPSEC) training. In addition, all Contractors should be aware of the Critical Information and Indicators List (CIIL) for the organization they are supporting as well as the OPSEC plan for NSWCDD. These OPSEC requirements will be in effect throughout the life of the procurement from award through the conclusion of services at the end of the Period of Performance (PoP) or other procurement termination. The Contractor must immediately notify the Government upon the discovery of any nonconformance with the OPSEC Plan.
C.10.7 Training
C.10.7.1 Privacy training is mandatory for all NSWCDD personnel (military, civilian, and Contractor) and must be completed annually. The Total Workforce Management System (TWMS) is the official database for workforce training and is the tool for taking and recording Privacy Act training. The Contractor is responsible for ensuring individual annual privacy training requirements are met.
C.10.7.2 Cyber Security Workforce Force (CSWF) CSWF/IT-1 Designated Contract/Positions:
(a) In accordance with DOD/DON CSWF requirements, Contractor employees assigned to an IT Level-I designated position with SECRET access will be required to have a favorably adjudicated T5/T5R completed every 6 years. Contractor employees that require a SECRET Clearance as part of their job duties, with IT Level-I designation, will be initiated by the Government, and will be at the Government’s expense.
(b) Any Contractor employee, who has a final clearance and submitted T5/T5R that is accepted by OPM along with a favorable fingerprint check (SAC), is eligible for IT-1 designation. The Command Security Office will review all SF-86 paperwork for all Contractor employees nominated for IT Level-I designations if the T5/T5R is not completed.
(c) Contractor employees that do not have a final clearance investigation within JPAS are ineligible for IT Level-I designation until the T5/T5R has been favorably adjudicated, shall remain at IT level-II status in JPAS and shall not be assigned to a contract position requiring IT Level-I designation.
C.11 ENVIRONMENT AND SAFETY
C.11.1 On-Site Environmental Awareness
(a) The Contractor shall strictly adhere to all Federal, State and local laws and regulations, Executive Orders, and Department of Defense and Navy policies.
(b) The Contractor shall ensure that each Contractor employee who has been or will be issued a Common Access Card (CAC) completes the annual NSWCDD Environmental Awareness Training (EAT) within 30 days of commencing Task Order performance and annually thereafter as directed by their NSWCDD training coordinator or their COR.
(c) The Contractor shall ensure that each Contractor employee not required to complete the training described in part (b) above (i.e., those who do not have and will not be issued a CAC) reads the NSWCDD Environmental Policy Statement within 30 days of commencing Task Order performance. This document will be available from the COR, however, the policy is also provided on the publicly-available NSWCDD website, https://wwwdd.nmci.navy.mil/program /Safety_and_Environmental_Office and https://www.navsea.navy.mil/Portals/103/Documents/NSWC_Dahlgren/Resources/Environment alPolicy.pdf
(d) Within 30 days of commencing Task Order performance, the Contractor shall certify by e-mail to their COR that the requirements identified in Paragraphs (b) and (c) above have been met. The e-mail shall include each employee name and work site and shall indicate which requirement identified in Paragraph (b) or (c) above each employee has satisfied.
(e) Contractor copies of the records generated by the actions described in Paragraphs (b) and (c) above will be maintained and disposed of by the Contractor in accordance with SECNAVINST
5210.8 Series.
C.11.2 On-Site Safety Requirements
(a) The Contractor shall strictly adhere to Federal Occupational Safety and Health Agency https://wwwdd.nmci.navy.mil/program https://no-click.mil/?https://www.navsea.navy.mil/Portals/103/Documents/NSWC_Dahlgren/Resources/EnvironmentalPolicy.pdf https://no-click.mil/?https://www.navsea.navy.mil/Portals/103/Documents/NSWC_Dahlgren/Resources/EnvironmentalPolicy.pdf
(OSHA) Regulations, Environmental Protection Agency (EPA) Regulations, and all applicable state and local requirements.
(b) The Contractor shall ensure that each Contractor employee reads the document entitled, "Occupational Safety and Health (OSH) Policy Statement" within 30 days of commencing performance at NSWCDD. This document is available at: https://wwwdd.nmci.navy.mil /program/Safety_and_Environmental_Office/Safety/Safety.html.
(c) The Contractor shall provide each Contractor employee with the training required to do his/her job safely and in compliance with applicable regulations. The Contractor shall document and provide, upon request, qualifications, certifications, and licenses as required.
(d) The Contractor shall provide each Contractor employee with the personal protective equipment required to do their job safely and in compliance with all applicable regulations.
(e) Contractors working with ionizing radiation (radioactive material or machine sources) must comply with NAVSEA S0420-AA-RAD-010 (latest revision) [provided upon request]. Prior to bringing radioactive materials or machine sources on base, the Contractor must notify the Command Radiation Safety Officer in the Safety & Environmental Office.
(f) The Contractor shall ensure that all hazardous materials (hazmat) procured for NSWCDD are procured through or approved through the hazmat procurement process. Hazmat brought into NSWCDD work spaces shall be reviewed and approved by the Safety & Environmental Office prior to use by submitting an Authorized Use List addition form and Safety Data Sheet that shall be routed through the Government supervisor responsible for the specific work area. The Authorized Use List addition form can be found at https://wwwdd.nmci.navy.mil/program /Safety_and_Environmental_Office/.
(g) Upon request the Contractor shall submit their OSHA 300 Logs (injury/illness rates) for review by the Safety Office. If a Contractor's injury/illness rates are above the Bureau of Labor & Statistics Industry standards, a safety assessment will be performed by the Safety Office to determine if any administrative or engineering controls can be utilized to prevent further injuries/illnesses, or if any additional PPE or training will be required.
(h) Applicable Contractors shall submit Total Case Incident Rate (TCIR) and Days Away, Restricted and Transfer (DART) rates for the past three years upon request by the Safety Office.
A Contractor meets the definition of applicable if its employees worked 1,000 hours or more in any calendar quarter on site and where oversight is not directly provided in day to day activities by the command.
(i) The Contractor shall report all work-related injuries/illnesses that occurred while working at NSWCDD to the Safety Office.
(j) The Contractor shall ensure that all on-site Contractor work at NSWCDD is in accordance with the NSWCDDINST 5100.1D Occupational Safety and Health Instruction, available at:
https://wwwdd.nmci.navy.mil/program/Safety_and_Environmental_Office/Safety/Safety.html
C.12 TASK ORDER - CONTRACTOR MANAGEMENT
C.12.1 Project Management Plan - Contractor shall provide a Project Management Plan
The Contractor shall deliver; project planning charts for A&A package creation; provide presentations on A&A creation; and provide documentation of A&A maintenance to include changes and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .