DRAFT_PWS_EnterpriseSecurityServices_30JAN2025.pdf
PDF 219 KB Posted
- Attached to
- Enterprise Security Services (ESS) Federal contract opportunity
- Solicitation number
- FA810225R1000
About this file
This is a Performance Work Statement (PWS) for Enterprise Security Services (ESS) supporting the US Air Force High Frequency Global Communications System (HFGCS), with an accompanying pre-solicitation notice. The PWS outlines requirements for Intrusion Detection and Analysis, Vulnerability Scanning, Security Technical Implementation Guide (STIG) Services, Documentation and Analysis Services, and Code Review Services for HFGCS systems on both NIPRNet and SIPRNet environments. The period of performance is 5 years (1 base year plus 4 option years) starting in 2025.
The contractor must provide cybersecurity services including monitoring and analysis using tools like Splunk for intrusion detection and ACAS for vulnerability scanning, conduct STIG validations every 90 days, maintain Authorization to Operate documentation, and perform source code security analysis using Fortify. Key personnel must maintain IAT Level II certification per DODD 8140.01. The pre-solicitation notice indicates this is a market research effort under NAICS 541519 ($34M size standard) to determine if small business set-aside is feasible. The anticipated solicitation release is May/June 2025, with responses due June/July 2025 and award expected March 2026. The Air Force Life Cycle Management Center at Tinker AFB is the requiring agency.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SSS_Inquiry_QA_5MAR2025.pdf | ||
| SSS_Inquiry_Questions_and_Answers_28Feb2025.pdf | ||
| ContractorCapabilitySurvey_28Feb2025.pdf | ||
| SSS_Inquiry_Questions_and_Answers_14Feb2025.pdf | ||
| SSS_Inquiry_Questions_and_Answers.pdf | ||
| SSS_3Feb2025.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
FOR
US Air Force (USAF)
High Frequency Global Communications System (HFGCS)
System Program Office (SPO)
Enterprise Security Services (ESS)
Unclassified
30 January 2025
Contract: FA8102-22-D-0004
Scope Command Next Generation
Approved by:
Department of the Air Force
AFLCMC/HBDH
3001 Staff Dr., Bldg. 3001 Tinker AFB, OK 73145-9042
30 January 2025 Enterprise Security Services (ESS)
Page | 2
DESCRIPTION OF SERVICES / GENERAL INFORMATION
The contractor shall fully comply with all applicable contractor requirements specified in the basic contract Performance Work Statement (PWS) in addition to the requirements specifically identified by this effort.
1. SCOPE: The contractor will be responsible for Intrusion Detection and Analysis, Vulnerability Scanning, Security Technical Implementation Guide (STIG) Services, Documentation and Analysis Services, and Code Review Services for the High Frequency Global Communication System (HFGCS) residing in each of the applicable Non-classified Internet Protocol Router Network (NIPRNet) & Secret Internet Protocol Router Network (SIPRNet) environments. This requirement includes all testing, analysis, and documentation support in order to receive the Department of Defense (DoD) mandated assessment and authorization. In addition, daily information assurance monitoring, analysis, and reporting are required. The contracted personnel shall possess the requisite clearance levels or be eligible to obtain and maintain the requisite clearance levels to conduct the actions described in this PWS. This PWS covers a Period of Performance (PoP) for a total of five (5) years to include one (1) base year and four (4) one-year options.
1.1. Non-Production Environments
The Non-Production environments are the software, hardware, and appliances, placed into operation for engineering and testing of both infrastructure and application changes.
Non-Production environments in this context also invludes all subsystems, modules, and applications within the Systems and all future modifications, modernizations, and projects of the Systems.
1.2. Production Environments
The Production Environments are the software, hardware, and appliances, placed into operation for use by end users. It includes virtual machines, containers, and virtual infrastructure in the HFGCS residing in both NIPRNet & SIPRNet.
Production Environments include the following:
Operational Environments: Operationally-ready environments to support the HFGCS Community users. Operational environments used by HFGCS Systems are fully controlled and in alignment with the Production Baselines (PBLs).
Training Environment: Operationally-ready training environments to support the global HFGCS users.
Production environments in this context also includes all subsystems, modules, and applications within the Systems and all future modifications, modernizations, and projects of the Systems.
Page | 3
2. OBJECTIVES: The contractor shall provide technical and support tasks required to verify the readiness state of the systems, infrastructure, and services satisfying the HFGCS mission for the identified programs. This contract is composed of the following tasks:
Task 1 – Cyber Operations Task 2 – Documentation and Analysis Services Task 3 – Code Scanning Services
2.1. Task 1: Cyber Operations
The contractor shall accomplish the following cyber operation tasks described in this PWS for the HFGCS NIPRNet and SIPRNet environments, unless otherwise specified.
In the absence of specific contract or Government requirements, the contractor shall use DoD standards and industry best practices. The contractor shall provide cyber support services such as, Intrusion Detection and Analysis, Vulnerability Scanning, and STIG validation for the HFGCS.
2.1.1. Intrustion Detection and Analysis Services
The contractor shall provide Intrusion Detection and Analysis support for the HFGCS. The contractor will utilize Splunk for Intrusion Detection and Analysis.
Splunk is a Security Information and Event Management (SIEM) suite allowing High Frequency Global Communications System (HFGCS) to capture, search, analyze, and visualize log data to detect threats and take meaningful action. The government may choose to move to a different tool, and the contractor shall use the tool provided by the government.
Due to the rapidly evolving nature of Intrusion Detection and Analysis tactics, techniques, and tools, the contractor shall keep pace with system and operational environment changes and ensure it has the appropriate skill set to effectively perform the Intrusion Detection and Analysis tasks.
The contractor shall ensure Intrusion Detection and Analysis personnel have, upon completion of the transition phase, a minimum Information Assurance (IA) certification level of Information Assurance Technician (IAT) Level II as defined in DODD 8140.01 and AFMAN 17-1303. This level of IA Certification must be maintained throughout contract performance.
The Contractor shall:
2.1.1.1. Provide technical system administration and functional support services for the Production and Non-Production intrusion detection and analysis applications software (e.g., Splunk). Examples of this type of activity include software updates, installation of software upgrades, security patch installation, and execution of STIG checklists of the application software when needed.
2.1.1.2. Support cyber events in the Non-Production and Production environments to include Inspections from higher headquarters, Cyber Protection Teams (CPT)s and other cyber tasks as required.
Page | 4
2.1.1.3. Ensure intrusion detection and analysis application software (e.g., Splunk) is configured to meet security directives for applicable software, and to comply with STIGs.
2.1.1.4. Review, install, verify, and document all patches and upgrades to the intrusion detection and analysis application software (e.g., Splunk). If patches cannot be applied within 21 calendar days of release, provide a detailed remediation timeline for Plan of Action and Milestone (POAM) creation.
2.1.1.5. Ensure intrusion detection and analysis applications software (e.g., Splunk) are compliant with Time Compliance Network Orders (TCNO), Information Assurance Vulnerability Management (IAVM) Notices and Cyber Technical Orders (CTO) and other downward directed security patches.
Download, review, install, verify, and document the installation of all patches and upgrades to the intrusion detection and analysis application software (e.g., Splunk).
2.1.1.6. Deploy, integrate, and migrate to Cloud intrusion detection and analysis technology and tools as directed by the government.
2.1.1.7. Sustain Cloud intrusion detection and analysis application software utilizing Cloud pipeline tools and processes when applicable.
2.1.1.8. Develop and deliver an intrusion detection and analysis monitoring plan (CDRL A001) outlining how the contractor is going to monitor intrusion detection and analysis applications and report identified threats and incidents.
2.1.1.9. Monitor the Production and Non-Production intrusion detection and analysis application software during normal business hours, Monday through Friday 0730 – 1630 CST
2.1.1.10. Develop and deliver a daily intrusion detection report (CDRL A002) displaying intrusion detection events and potential impact to the HFGCS. The report is to be delivered during normal business hours, Monday through Friday, and cover the time period from the last report. If daily reports indicate positive intrusion event or compromise the reports shall be made over a classified meeting with the appropriate stakeholders, to include the HFGCS Information Systems Security Manager (ISSM). Otherwise, reports will be provided to the designated HFGCS System Program Office (SPO) and Lead Command personnel via SIPR email.
2.1.1.11. Manage and process data ingested by Splunk indexer. Manage and maintain Splunk databases and logs and post logs to the HFGCS System Security SharePoint page (https://usaf.dps.mil/teams/10286/HFGCS_IA_Team/default.aspx).
2.1.1.12. Ensure the security posture of the servers and network devices is maintained.
2.1.1.13. Perform automated/continuous on-line security monitoring of all HFGCS system servers and network devices.
2.1.1.14. Ensure audit trail creation capability is deployed.
2.1.1.15. Ensure audit data is collected and retained to support technical analysis relating to misuse, penetration reconstruction, or other investigations. Upon request, provide this data to the Government ISSM or Contracting Officer Representative (COR)/Alternate COR, as part of Vulnerability Indexes Report (CDRL A003), as appropriate. Reports will be published to the HFGCS
Page | 5
System Security SharePoint page (https://usaf.dps.mil/teams/10286/HFGCS_IA_Team/default.aspx).
2.1.1.16. Ensure tools are available for the review of audit records and for report generation from audit records.
2.1.1.17. Ensure the content of the audit trails is protected against unauthorized access, modification, or deletion.
2.1.1.18. Monitor local and remote HFGCS systems for current security vulnerabilities and intrusion attempts on the system servers and network devices and immediately report findings to the Government ISSM or appropriate individual. If the current auditing tools being used cannot detect the most current vulnerabilities/intrusion signatures, the contractor shall research commercial products available to meet this requirement and provide a recommendation to the Government ISSM on tools to purchase or the cost associated with the creation of tools capable of providing the required capabilities.
2.1.1.19. Develop and deliver an Incident Response Plan annually. (CDRL A007).
2.1.1.20. Upon identification of unusual, inappropriate, or suspicious activity with potential information assurance implications, alert Government ISSM or COR/Alternate COR IAW CJCSM 6510.01 B.
2.1.1.21. Perform Incident Response Plan exercise semi-annually and provide documentation to COR within 5 calendar days of completion of exercise
(CDRL A008).
2.1.1.22. Audit/monitor continuously for suspicious activity of the information systems.
2.1.1.23. Assist with the implementation and operation of user activity monitoring services, to include software which enables the capability to conduct keystroke monitoring, fileshadowing, and screencapturing of user activity.
2.1.1.24. Assist with the implementation and operation of file integrity validation services/software.
2.1.2. Vulnerability Scanning Services
The contractor shall provide Vulnerability Scanning services for the HFGCS. The contractor will utilize Assured Compliance Assessment Solution (ACAS) for vulnerability scanning. ACAS is an integrated software solution providing automated network vulnerability scanning, configuration assessment, and network discovery. The government may choose to move to a different tool, and the contractor shall use the tool provided by the government. Due to the rapidly evolving nature of Vulnerability Scanning tactics, techniques, and tools; the contractor shall keep pace with system and operational environment changes and ensure it has the appropriate skill set to effectively perform the Vulnerability Scanning tasks. The contractor shall ensure personnel supporting vulnerability scanning must have, upon completion of the transition phase, a minimum Information Assurance (IA) certification level of Information Assurance Technician (IAT) Level II as defined in DODD 8140.01 and AFMAN 17-1303.This level of IA Certification must be maintained throughout the contract performance.
Page | 6
The Contractor shall:
2.1.2.1. Provide technical system administration and functional support services for the production and non-production vulnerability application software (e.g., ACAS).
2.1.2.2. Support cyber events in the Non-Production and Production environments to include Higher Headquarters inspections, CPTs and other cyber tasks as required.
2.1.2.3. Ensure vulnerability application software (e.g., ACAS) are configured to meet security directives, install patches for applicable software, and comply with STIGs.
2.1.2.4. Deploy, integrate, and migrate to Cloud vulnerability scanning technology and tools as directed by the government.
2.1.2.5. Sustain Cloud vulnerability scanning application software utilizing Cloud pipeline tools and processes.
2.1.2.6. Configure and schedule vulnerability scans and validate scans successfully run in accordance with Government direction.
2.1.2.7. Ensure latest Tenable data is incorporated in Security Center.
2.1.2.8. Monitor scanning process and notify COR of any issues that prevent scan completion.
2.1.2.9. Verify results through a random validation of 5 percent of scan result in All
Scans Report after each day’s scans are compiled.
2.1.2.10. Perform post-processing to generate Scans reports for the HFGCS
Program Office (AFLCMC) and the HFGCS Lead Command (ACC).
2.1.2.11. Post weekly/monthly reports to the HFGCS System Security SharePoint page (https://usaf.dps.mil/teams/10286/HFGCS_IA_Team/default.aspx) and manage archive.
2.1.2.12. Patch scanning software within 21 calendar days of release or provide detailed remediation timeline for Plan of Action and Milestones (POAM) creation.
2.1.2.13. Provide Common Vulnerability Scoring System (CVSS) report the first workday of every week.
2.1.2.14. Participate in Defense Information Systems Agency (DISA) working groups.
2.1.2.15. Incorporate latest bulletins and releases from Tenable.
2.1.2.16. Open and manage and trouble tickets with DISA/Tenable as required.
2.1.3. Security Technical Implementation Guide (STIG) Services
The contractor shall provide STIG support services for the HFGCS. The contractor shall utilize the current 90 calendar day STIG review and validation process implemented by the HFGCS. The contractor shall ensure personnel supporting STIG services have, upon completion of the transition phase, a minimum Information Assurance (IA) certification level of Information Assurance Technician (IAT) Level II as defined in DODD 8140.01 and AFMAN 17-1303.This level of IA Certification must be maintained throughout the contract performance.
The Contractor shall:
2.1.3.1. Develop and maintain required security documentation.
Page | 7
2.1.3.2. Validate/evaluate security requirements, vulnerabilities, and residual risks.
2.1.3.3. Accomplish thorough STIG assessment validation (out of cycle and quarterly) based on program needs.
2.1.3.4. Review STIG assessment results with Estimated Completion Date’s (ECD) in the current quarter (ISSM will return on the internal STIG tracking site).
2.1.3.5. Review new findings during the quarter they are released per local STIG review policy.
2.1.3.6. Create STIG matrix of applicable STIGs based on quarterly HW/SW list as provided by programs or when program requests changes due to fielding schedule.
2.1.3.7. Ensure the security posture of the servers and network devices is maintained.
2.1.3.8. Implement TCNO, CTO, Maintenance Tasking Order (MTO) or other downward directed taskings directed by the COR.
2.1.3.9. Participate in HFGCS Program Management Office (PMO) Cybersecurity weekly program meetings.
2.2. Task 2: Documentation and Analysis Services
The contractor shall provide documentation and analysis support services for the HFGCS in support of obtaining and maintaining a current Authorization to Operate (ATO) according to DODI 8510.01 Risk Management Framework (RMF) and compliance with the associated security controls as defined in DODI 8500.01 Cybersecurity. The contractor shall ensure personnel supporting Documentation and Analysis, upon completion of the transition phase, have a minimum Information Assurance (IA) certification level of Information Assurance Technician (IAT) Level II as defined in DODD 8140.01 and AFMAN 17-1303.This level of IA Certification must be maintained throughout the contract performance.
The Contractor shall:
2.2.1. Facilitate and complete the collection, organization, assessment, and management of the HFGCS RMF documentation to submit for and receive ATOs for each fielded system.
2.2.2. Coordinate and support annual security assessments conducted by the Government.
2.2.3. Review RMF control family plans as provided by the HFGCS PMO to ensure they meet all control/assessment procedure (AP) requirements as documented in National Institute of Standards and Technology (NIST) Publication 800-53 Revision 5, Chapter 3 (September 2020).
2.2.4. Enter control/AP Test Results in Enterprise Mission Assurance Support Service (eMASS) based on RMF control family plans and other Recommended Compelling Evidence.
2.2.5. Upload and maintain all required artifacts into eMASS, including STIG Checklists (CKLs) and Fortify SCA files. Ensure each artifact is properly assigned to the correct controls/APs.
Page | 8
2.2.6. Ingest STIG CKLs files into eMASS quarterly and open/update/close POAMS accordingly.
2.2.7. Ingest ACAS scans into eMASS on business days and open/update/close POAMS accordingly.
2.2.8. Ensure the applicable STIGs selected in eMASS System Categorization match ingested CKLs.
2.2.9. Ingest properly formatted HW/SW list (HFGCS PMO will provide document in the proper format with no extra hyperlinks in document).
2.2.10. Participate in weekly HFGCS PMO Cybersecurity program meetings.
2.3. Task 3: Code Scanning Services
The contractor shall provide source code security analysis and review services for the HFGCS. Currently the government tool utilized for source code security analysis is Fortify. Fortify is a Static Application Security Testing (SAST) suite providing static source code analysis.
Due to the rapidly evolving nature of source code analysis tactics, techniques, and tools; the contractor shall keep pace with system and operational environment changes and ensure it has the appropriate skill set to effectively perform the source code analysis task. The government may choose to change the tool or process used to perform source code analysis.
The contractor shall ensure personnel supporting Source Code Review Analysis have, upon completion of the transition phase, a minimum Information Assurance (IA) certification level of Information Assurance Technician (IAT) Level II as defined in DODD 8140.01 and AFMAN 17-1303. This level of IA Certification must be maintained throughout the contract performance.
The Contractor shall:
2.3.1. Provide technical system administration and functional support services for the production and non-production source code analysis application software (e.g., Fortify).
2.3.2. Review, install, verify, and document all patches and upgrades to the source code analysis application software (e.g., Fortify). If patches cannot be applied within 21 calendar days of release, provided detailed remediation timeline for POAM creation.
2.3.3. Ensure source code analysis application software (e.g., Fortify) is compliant with TCNO, IAVM, CTOs and other downward directed security patches. Download, review, install, verify, and document all patches and upgrades to the source code application software (e.g., Fortify).
2.3.4. Deploy, integrate, and migrate to Cloud source code analysis technology and tools as directed by the government.
2.3.5. Develop and deliver a source code analysis plan (CDRL A004) outlining the contractor’s approach for source code analysis.
2.3.6. Perform source code security analysis for all source code when provided by program using government provided source code analysis tool.
Page | 9
2.3.7. Provide source code security analysis findings report for each release highlighting identified findings and risk associated with fielding if not resolved.
3. PROGRAM MANAGEMENT:
3.1. The contractor shall establish and provide a qualified workforce capable of performing the required tasks in accordance with the requirements of the Labor Categories.
Certification of cyber workforce qualifications shall be provided to the HFGCS Program Office (CDRL A010). The workforce shall include a project/contract manager who will oversee all aspects of the contract. The contractor shall use key performance parameters located in the Services Summary Table below to monitor work performance, measure results, ensure delivery of contracted product deliverables and solutions, support management and decision-making and facilitate communications. The contractor shall identify risks, resolve problems, and verify effectiveness of corrective actions. The contractor shall institute and maintain a process ensuring problems and action items discussed with the Government are tracked through resolution and shall provide timely status reporting. Results of contractor actions taken to improve performance shall be tracked, and lessons learned incorporated into applicable processes. The contractor shall establish and maintain a documented set of disciplined, mature, and continuously improving processes for administering all contract efforts with an emphasis on cost-efficiency, schedule, performance, responsiveness, and consistently high-quality delivery.
3.2. The contractor shall not conduct any external meetings, conferences, or presentations, whether planned or ad hoc, with outside agencies, to discuss any program requirements, policies, etc., without first obtaining the permission of the COR.
3.3. The contractor shall provide a transition plan (CDRL A014) detailing a phase-in strategy and method of assuming responsibility for tasks described in the PWS and the strategy for acquiring qualified, certified, and cleared personnel. Immediately following the end of the one (1) month phase-in/transition period, the contractor shall assume full PWS service responsibilities. The contractor shall also provide a transition plan (CDRL A014) detailing a phase-out strategy describing the method of transferring responsibility for tasks described in the PWS. All records and other documentation developed or acquired under this contract, as well as procedures and training materials developed as part of this contract, shall be included in the phase-out effort.
4. SCHEDULE: Services shall commence upon receipt of award. The Period of Performance
(PoP) is a total of five (5) years to include one (1) base year and four (4) one-year options.
5. WORK HOURS: The average Government workweek is based on 40 hours. Normal business work hours for the Government are between the hours of 0730 and 1630, (central time zone), Monday through Friday. Government surveillance of contractor performance is required to give reasonable assurance that efficient methods and effective cost controls are being used.
Page | 10
5.1. Observance of Legal Holidays and Excused Absence
5.1.1. The Government hereby provides notice, and the contractor hereby acknowledges that Government personnel observe the listed days as holidays:
New Year’s Day Martin Luther King Jr. Day Presidents’ Day Memorial Day Juneteenth Day Independence Day Labor Day Columbus Day/Indigenous Peoples’ Day Veterans Day Thanksgiving Day Christmas Day
5.1.2. In addition to the days designated as holidays, the Government observes the following days:
Any other day designated by Federal Statute Any other day designated by Executive Order Any other day designated by a President’s Proclamation
6. SUPPLIES/MATERIALS: The contractor shall procure and provide all required supplies, tools, equipment and material needed to complete the effort outline in this PWS.
7. DELIVERABLES: The contractor shall furnish the HFGCS System Program Office with the following information/deliverables:
Intrusion Detection and Analysis Monitoring Plan (CDRL A001) Daily Intrusion Detection Report (CDRL A002) Vulnerability Indexing Report (CDRL A003) Source Code Analysis Plan (CDRL A004) Incident Response Plan (IRP) (CDRL A007) IRP exercise Report (CDRL A008) Cybersecurity Workforce certification (CDRL A010) Transition Plan – Phase-In/Phase-Out Strategy (CDRL A014)
8. SERVICES SUMMARY:
The following Services Summary identifies the performance objectives and performance thresholds for critical tasks associated with providing support services for this requirement.
The performance threshold briefly describes the minimum acceptable levels of service required for each performance objective. These thresholds are critical to mission success.
The absence of any performance objective and threshold from the Service Summary shall not detract from its enforceability or limit the Government’s rights or remedies afforded under this contract.
Page | 11
Performance Objectives
PWS
Para
Performance Thresholds Method of Surveillance
SS 1: Intrusion Detection and Analysis Services
2.1.1 Performance is acceptable when there is no
more than one valid documented complaint* (via Customer Complaint Record) per month in performance of required tasks.
All complaints are resolved not later than one (1) business day beyond the PM/contractor agreed-to time period.
Customer Compliant
SS 2:
Vulnerability Scanning Services
2.1.2 Performance is acceptable when there is no
more than one valid documented complaint* (via Customer Complaint Record) per month in performance of required tasks.
All complaints are resolved not later than one (1) business day beyond the PM/contractor agreed-to time period.
Customer Compliant
SS 3: STIG
Services
2.1.3 Performance is acceptable when there is no
more than one valid documented complaint* (via Customer Complaint Record) per month in performance of required tasks.
All complaints are resolved not later than one (1) business day beyond the PM/contractor agreed-to time period.
Customer Compliant
SS 4:
Documentation and Analysis Services
2.2 Performance is acceptable when there is no
more than one valid documented complaint* (via Customer Complaint Record) per month in performance of required tasks.
All complaints are resolved not later than one (1) business day beyond the PM/contractor agreed-to time period.
Customer Compliant
SS 5: Code Scanning Services
2.3 Performance is acceptable when there is no
more than one valid documented complaint* (via Customer Complaint Record) per month in performance of required tasks.
All complaints are resolved not later than one (1) business day beyond the PM/contractor agreed-to time period.
Customer Compliant
* A valid complaint is one that is consequential to the successful performance of the requirement for an issue that was not corrected in a reasonable amount of time and adversely impacted performance, schedule, and/or cost.
Page | 12
9. ORDER POC:
9.1. Jocelyn Johnson, Contracting Officer, 312-884-5587, email:
jocelyn.johnson.2@us.af.mil
9.2. HFGCS System Program Office contacts for this effort are:
Courtney Rachel, Contract Officer Representative, 405-734-1464, email:
courtney.rachel.2@us.af.mil
Ian Johnson, SPO Lead Engineer, 405-734-2306 or DSN 312-884-2306; email:
ian.johnson.23@us.af.mil
2nd Lt. Sara Wine, SPO Program Manager, 405-736-7770 or DSN 884-7770; email:
sara.wine@us.af.mil
Dylan Brezny, SPO Program Manager, 405-734-8892 or DSN 312-884-8892; email:
dylan.brezny.1@us.af.mil
Jacob Wheeland, CTR, SPO Information System Security Manager, 405-736-5673 or DSN 312-336-5673; email: jacob.wheeland.2.ctr@us.af.mil
10. GOVERNMENT-FURNISHED PROPERTY (GFP) AND SERVICES: None
11. APPLICABLE DOCUMENTS: None
File details come from the government source that posted it. Updated .