About this file

A6 PWS

View the file

Other files for this federal contract opportunity

Other files attached to Advisory & Assistance Services & Systems Engineering & Technical Assistance Services for Headquarters, Air Force Space Command, newest first.
File Type Posted
Amendment 9 SF30 Summary of Changes.doc DOC document
Amendment 7 Questions Responses.doc DOC document
SF30 Summary of Changes - Amendment 5.doc DOC document
CSMC RFP 25 Sep 09 Amendment 4.doc DOC document
Attachment 5 Section L Attachments Amendment 3.doc DOC document
CSMC RFP 21 Sep 09 Amendment 2.doc DOC document
Questions Responses - Amendment 1.doc DOC document
MWMD CDRLs 04 06 9 Sep 09.rtf RTF text file
CDRLS Master List MGMT 27 28.rtf RTF text file
CDRLS Master List ADMIN 7.rtf RTF text file
Attachment 5 Section L Attachments Version 3 21 Jul 09.doc DOC document
MWMD CDRLs 30 31 9 Sep 09.rtf RTF text file
CSMC 254 24 Aug 09.pdf PDF
Block 13 Continuation Sheet 2 Sep 09.docx DOCX document
Industry Day Announcement.doc DOC document
CSMC Cover Letter.doc.docx DOCX document
CSMC CDRLS 33 thru 36 3 June 09.pdf PDF
MILSATCOM 6 7 31 May 09.pdf PDF
9003-0042.doc DOC document
9003-0044.doc DOC document
Acq Strategy Release to Industry.doc DOC document
9002-0028.doc DOC document
9003-0037.doc DOC document
A9F MUA 20081106.docx DOCX document
Market Research Questions.doc DOC document
9003-0011.DOC DOC document
9003-0002.doc DOC document
9003-0014.DOC DOC document
9003-0027.doc DOC document
9003-0024.doc DOC document
9003-0028.doc DOC document
9002-0008.doc DOC document
9002-0020.doc DOC document
9002-0007.doc DOC document
9002-0013.doc DOC document
9002-0012.DOC DOC document
9001-0010.doc DOC document
9001-0029.doc DOC document
9001-0018.doc DOC document
9001-0022.doc DOC document
9000-0028.doc DOC document
9000-0004.doc DOC document
9000-0026.doc DOC document
9000-0029.doc DOC document
9000-0022.doc DOC document
9000-0024.doc DOC document
9000-0011.doc DOC document
9002-0025.doc DOC document
9003-0033.doc DOC document
Subcontractor List.xls XLS spreadsheet
Show all 50

Advisory & Assistance Services & Systems Engineering & Technical Assistance Services for Headquarters, Air Force Space Command has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK

FOR

Headquarters Air Force Space Command (HQ AFSPC) Information Assurance Support

RFTOP A6-0175

(4 June 2008)

1.0 DESCRIPTION OF SERVICES: To provide Information Assurance (IA) support to HQ AFSPC.

1.1 ORGANIZATION BEING SUPPORTED: HQ AFSPC/A6

1.1.1 MISSION: Our mission is to develop, implement, manage and maintain an Information Assurance Program (IAP) for AFSPC, primarily for DoD-appointed, multi-component space systems and AF space systems.

1.2 OVERVIEW OF SERVICES REQUIRED

1.2.1 An overview of the services requested is:

a. Provide Task Order Meeting Support and Status Reporting

b. Perform Technical Document Analysis

c. Support the Information Assurance Assessment & Assistance Program (IAAP)

d. Manage the AFSPC Emissions Security Program

e. Support the Notice and Consent Program

f. Red and Blue Vulnerability Assessment Process Management

g. Provide IA Community of Practice (CoP) Support

h. Support the Federal Information Security Management Act (FISMA)

i. Support the Certification & Accreditation Process

j. Support Quick Reaction Efforts

1.2.2 This task order entails active collaboration with a wide range of organizations, including those listed below:

a. HQ AFSPC Directorates

b. Numbered Air Forces, specifically 14th AF [Vandenberg AFB, CA] and 20th AF

[F.E. Warren AFB, WY]

c. HQ AFSPC Wings (specifically the Wing Information Assurance Offices) [CONUS]

d. HQ AFSPC Geographically Separated Units (GSUs) [Worldwide]

e. Product Centers:

1. Space and Missile Center (SMC) [Los Angeles AFB, CA]

2. Electronic Systems Center (ESC) [Hanscom AFB, MA]

3. 526th ICBM Systems Wing and 526th Acquisition Group [Hill AFB, UT]

f. HQ Air Force Communications Agency (AFCA) [Scott AFB, IL]

g. HQ AF Cyber Space Command (AFCYBER) [Location TBD] and its subordinate organizations

h. HQ United States Strategic Command (USSTRATCOM) [Offutt AFB, NE]

i. Space Innovation and Development Center (SIDC) [Schreiver AFB, CO]

j. Secretary of the Air Force for Warfighting Integration and Chief Information Office (CIO) (SAF/XC) [Washington D.C.]

k. Defense Information Systems Agency [DISA]

l. National Aeronautics and Space Administration (NASA)

m. Joint Task Force / Global Network Operations (JTF/GNO)

1.3 SPECIFIC REQUIREMENTS:

Background or Overview: According to the 21 December 2007 AFNETOPS/CC memo to AFSPC/CC, AFNETOPS acknowledged the list of 109 AFSPC core systems transitioning to HQ AFCA, while HQ AFSPC retained IA management and Certification and Accreditation responsibilities and workload for the current 330+ space specific systems.

According to the Transition Plan, the actions necessary to complete this transition are IA management workload and responsibilities for each functional area (policy, support, reports and assessments), IA disciplines (COMSEC, COMPUSEC and EMSEC) will transition based upon a pre-set sequence and strategy as outlined in the 10 January 2008 HQ AFSPC Information Assurance (IA) Management Transition Plan. Workload transfer will begin with IA administrative functions (i.e. policy, support and reports); additional HQ AFSPC workload (i.e. the Information Assurance Assistance & Assessment Program (IAAP)) will transfer incrementally as personnel and resources are provided to successfully absorb the workload. Transition timelines are developed based on availability of HQ AFCA resources and trained personnel. To date, the MOU for this transition remains unsigned. The long pole in the timeline is the IAAP, whose responsibilities shall incrementally transition from HQ AFSPC to HQ AFCA at MOU signature + 365 days.

HQ AFCA shall begin the Program Objective Memorandum (POM) process for IA program funding starting with the next POM cycle after formally assuming program responsibilities. Until that time, HQ AFSPC/A6 will maintain control of IA program funding lines and AFCA will coordinate extensively with HQ AFSPC to ensure a smooth transition of funding control and execution. HQ AFSPC will continue to POM and budget for their IA requirements. Presently, HQ AFCA has little funding to support the IA program functions.

1.3.1 REQUIREMENT 1: Task Order Meeting Support and Status Reporting.

1.3.1.1 The contractor shall perform action item evaluations, develop briefings, provide recommendations, and produce meeting minutes/trip reports (CDRL 0005) for approximately 125 information assurance working groups per year. Examples include, but aren’t limited to:

a. AEHF International Partner’s Working Group

b. GPS Quarterly Working Group

c. SMC Program Integration Planning Meeting

d. Space Radar Information Assurance Meeting

e. NSA Information Assurance Conference

f. TSAT Working Group

g. Range Security Working Group

h. COMSEC Inspection

i. EMSEC Assessment

j. System Program Offices

1.3.1.2 The contractor shall submit Weekly Activity Reports (WARs). (CDRL 0030) In addition to a summary of activities, issues and high interest items, the WAR shall include a summary of certification and accreditation assessments completed and underway and the weekly FISMA score. Reports shall be submitted to the QAE by noon each Tuesday.

1.3.1.3 The contractor shall conduct a Kickoff Meeting. (CDRL 0006)

1.3.1.4 DELIVERABLES: CDRL 0005, 0006, 0030

1.3.2 REQUIREMENT 2: Technical Document Analysis.

1.3.2.1 The contractor shall assess up to 225 information security related products, documents, staff taskings and briefings per year and provide technical recommendations to QAE. (CDRL 0037).

1.3.2.3 DELIVERABLES: CDRL 0037

1.3.3 REQUIREMENT 3: Information Assurance Assistance & Assessment Program (IAAP).

1.3.3.1 The contractor shall conduct COMSEC-only inspections for all AFSPC bases every 2 years. There will be approximately 11 inspections per year, not counting any re-inspections or Staff Assist Visits (SAVs). The contractor shall identify and track COMSEC related incidents. The contractor shall complete AF Form 4160 “Information Assurance Assessment and Assistance Program (IAAP) Criteria” (CDRL 0037), when inspecting AFSPC units, tenants, and Geographically Separated Units (GSU’s) for compliance IAW AFI 33-230, “Information Assurance Assessments and Assistance Program” (entire regulation applies). The contractor shall make recommendations to QAE based on inspection results. The contractor shall track findings through completion. The contractor shall develop the annual report to AFCA for AFSPC.

1.3.3.2 The contractor shall interpret MAJCOM/DoD/AF issuances and provide guidance to the field.

1.3.3.3 DELIVERABLES: CDRL 0037

1.3.4 REQUIREMENT 4: Emissions Security (EMSEC) Management.

1.3.4.1 The contractor shall provide a AF certified EMSEC manager(s) to provide guidance and direction for the AFSPC Emissions Security Program. The contractor shall help subordinate EMSEC manager’s process their requirements, including EMSEC waivers (AF Form 4168). The contractor shall work with the AFSPC training manager to orchestrate EMSEC training. The contractor shall make recommendations to QAE based on inspection results.

1.3.4.2 The contractor shall interpret MAJCOM/DoD/AF issuances and provide guidance to the field.

1.3.5 REQUIREMENT 5: Notice and Consent Program.

1.3.5.1 The contractor shall assist AFSPC Wings and HQ AFCA by providing liaison and tracking in accomplishment of Notice and Consent reports for AFSPC/JA approval.

1.3.6 REQUIREMENT 6: Red and Blue Vulnerability Assessment Process Management.

1.3.6.1 The contractor shall coordinate AFSPC Wing requests for Red and/or Blue Team Vulnerability Assessments. The contractor shall ensure appropriate wing commander approval is obtained prior to obtaining the appropriate Designated Authorizing Authority (DAA) approval.

1.3.7 REQUIREMENT 7: Information Assurance Community of Practice (CoP) Support.

1.3.7.1 The contractor shall update or replace content on the AFSPC Information Assurance CoP on the Air Force Knowledge Now (AFKN) portal and develop and maintain a point of presence on the AFSPC Sharepoint server.

1.3.8 REQUIREMENT 8: Federal Information Security Management Act (FISMA).

1.3.8.1 The contractor shall manage AFSPC FISMA reporting to SAF/XC. The contractor shall review each system’s FISMA compliance in the Enterprise Information Technology Data Repository (EITDR) and ensure each system is compliant with EITDR requirements.

1.3.8.2 The contractor shall produce a weekly FISMA Compliance Report (CDRL 0037). This will require the use of WebIntelligence to modify existing pre-canned reports to create AFSPC unique reports.

1.3.8.3 The contractor shall produce a quarterly tracking report identifying each system’s Plan of Actions & Milestones (POA&M) (system weakness and projected corrective actions) and prepare packages for DAA approval and deliver to the AF CIO. All POA&M activities shall be performed on the SIPRNet.

1.3.8.4 The contractor shall post the information on the Information Assurance CoP. The contractor shall report status to the QAE.

1.3.8.5 The contractor shall interpret MAJCOM/DoD/AF issuances and provide guidance to the field.

1.3.8.6 DELIVERABLES: CDRL 0037

1.3.9 REQUIREMENT 9: Certification & Accreditation.

1.3.9.1 The contractor shall assess approximately 275 certification and accreditation packages per year. The contractor shall provide a system risk assessment/recommendation to the Designated Authorizing Authority (DAA) (CDRL 0037).

1.3.9.2 This requirement is broken into two parts. The first part is certification and accreditation support for new programs, system upgrades and modifications and the second part is for certification and accreditation responsibilities for existing legacy systems.

1.3.9.3 For the first part, the contractor shall evaluate AFSPC space systems over their acquisition life cycle and provide government approved recommendations to System Program Offices (SPO) (i.e. Los Angeles AFB; Hanscom AFB and Hill AFB) with regards to implementation and design of security policy and information assurance security controls.

1.3.9.4 The contractor shall provide analysis of security controls to ensure proper implementation, operation and surety of the level of confidentiality, integrity and availability required for system operation.

1.3.9.5 The contractor shall participate in requirements and milestone reviews to identify security requirements, and document security requirements during all phases of a system’s or applications life cycle.

1.3.9.6 The contractor shall identify vulnerabilities in AFSPC systems during the complete system life cycle and develop risk mitigation strategies (technical or procedural) for those vulnerabilities.

1.3.9.7 The contractor shall provide technical analysis during each phase of the Certification and Accreditation Process (DITSCAP and/or DIACAP). The contractor shall review information assurance security plans to determine the availability, integrity, and confidentiality of the associated systems.

1.3.9.8 For part 2, legacy certification and accreditation, the contractor shall evaluate the technical validity of system certification and accreditation documentation. The contractor shall develop and staff accreditation system security risk recommendations through the AFSPC Designed Authorizing Authority Representative (DAA-R) to the AFSPC DAA.

1.3.9.9 The contractor shall identify vulnerabilities in AFSPC systems during the complete system life cycle and develop risk mitigation strategies (technical or procedural) for those vulnerabilities.

1.3.9.10 The contractor shall provide technical analysis and vulnerabilities mitigation recommendations during each phase of the Certification and Accreditation Process. The contractor shall review information assurance security plans to determine the confidentiality, availability, and integrity of the associated systems.

1.3.9.11 The contractor shall provide analysis of security controls and security controls testing to ensure proper implementation, operation and surety of the level of protection required for system operation.

1.3.9.12 DELIVERABLES: CDRL 0037

1.3.10 REQUIREMENT 10: Quick Reaction Tasking.

1.3.10.1 The nature of this task order may require the contractor to provide quick response deliverables and respond to contingencies, surge requirements, task order modifications or other quick response actions. This may require the preparation of technical, procedural, conceptual and informational papers with minimum notice. Additionally, the contractor may be required to provide technical services in the form of working groups, meetings, conferences or summit attendance. (approximate occurrence is three per week)

1.3.10.2 DELIVERABLES: CDRL 0037

1.4 ADDITIONAL DELIVERABLES: CDRL 0031: Monthly Status Report (MSR)

2.0 SERVICES SUMMARY:

Performance Objective
SOW Para.
Performance Threshold
Performance Objective
SOW Paragraph
Performance Threshold
Deliverables are completed in an accurate and timely manner
ALL
No more than one (1) late document per month and no more than five (5) days late. No more than one (1) set of corrections or edits and all corrections must be accomplished within five (5) working days.
All requirements of the Task Order are met
ALL
Contractor receives no more than 2 formal, validated customer complaints/contractor discrepancy reports per year. The contractor successfully resolves customer complaints with 10 calendar days of receipt, 100% of the time.
Deliverables satisfy customer needs and issues resolved in a timely manner
ALL
The contractor receives no more than 3 formal, validated customer complaints/contractor discrepancy reports per year. The contractor successfully resolves customer complaints with 10 calendar days of receipt, 100% of the time.

3.0 Government Furnished Property and services:

3.1 GOVERNMENT FURNISHED PROPERTY (GFP): None.

3.2 GOVERNMENT FURNISHED RESOURCES:

3.2.1 FACILITIES, SUPPLIES, AND SERVICES: The contractor shall be provided with workspace at Government-furnished facilities. The Government will furnish up to 14 workstations in the Hartinger Building on Peterson AFB. Included with the Hartinger Building workspace will be desk space, chair, and computer with access to Peak Net (NIPRNet), Secret Internet Protocol Router Network (SIPRNet), use of telephones, copiers and fax machines.

3.3 MATERIALS AND OTHER DIRECT COSTS (ODCs): None.

4.0 GENERAL INFORMATION:

4.1 SECURITY: Provisions outlined in the basic award DD 254 apply to this task order. Activities and products associated with this task order shall range from Unclassified to Top Secret and SCI. Specifically:

a. COMSEC support will require a Top Secret (TS) clearance. COMSEC personnel need to have attended the AF COMSEC course and have sufficient knowledge/experience required to provide management expertise and guidance.

b. EMSEC support will require a TS/Special Compartmented Information (SCI) clearance.

c. A minimum of two analyst will require TS/SCI clearance.

d. All other support will require a minimum of a Secret clearance.

4.1.1 The contractor shall be in compliance with DoDD 8570.1 "Information Assurance Training, Certification and Workforce Management" requirements and certifications.

4.2 ACCESS TO GOVERNMENT PROPERTY AND FACILITIES: The contractor will be allowed unescorted access to Government buildings on Peterson AFB, and other sites consistent with Task Order requirements. Access to Government facilities, documents, and systems shall be in accordance with the attached DD254.

4.3 SERVICES DURING CRISIS: The performance of these services is non-mission essential during times of crisis. Should a crisis be declared, the Contracting Officer or their representative will verbally advise the contractor if temporary suspension of work is required, followed by a written notification. A representative of the contracting officer will further notify the contractor verbally when the crisis has ended with written notification to follow. Any price changes resulting from this crisis will be negotiated in accordance with FAR clauses for “Changes”.

Travel. Any travel required to fulfill the tasks in this PWS shall be performed with the prior approval of the QAE in accordance with Federal Acquisition Regulation (FAR) Part 31. The Contractor shall be responsible for making travel arrangements for their personnel, including air travel, car rental, lodging and subsistence. Contractor employees may be required to travel to various locations within the continental United States (CONUS) and outside the continental United States (OCONUS) in performance of task orders. Estimated travel requirements are included below. All contractor travel shall be approved by the Government prior to departure. Any travel required shall be performed in accordance with FAR 31.205-46, Travel Costs.

4.4 TRAVEL: The following travel is estimated in support of this task order.

LOCATION

PURPOSE

ESTIMATED LENGTH
ESTIMATED NUMBER OF TRIPS
Cape Canaveral AFS
COMSEC IAAP
5
1
Antigua AFS
COMSEC IAAP
1
1
Ascension AFS
COMSEC IAAP
1
1
USAFA (*)
COMSEC IAAP
3
1
AEHF Schriever AFB (*)
COMSEC SAV
1
1
Vandenberg AFB / AEHF
COMSEC IAAP/

AEHF Site Visit

7
1
Malmstrom AFB
COMSEC IAAP
7
1
Diego Garcia
COMSEC IAAP
2
1
Cape Canaveral AFS
COMSEC IAAP
5
1
Antigua AFS
COMSEC IAAP
1
1
Los Angeles AFB CA
AEHF Int’l Partners WG
5
1
Los Angeles AFB CA
GPS SPO
5
2
Los Angeles AFB CA
Range System Security WG
5
2
Chantilly, VA
GPS Quarterly Review
5
1
Chantilly, VA
Space Radar IA Meeting
5
1
Baltimore, MD
TSAT Security WG
5
1
Patrick AFB FL
Range System Security WG
5
1
Los Angeles AFB, CA
SMC/PIP Planning Mtg
5
3
Chantilly, VA
NSA IA Conference
5
1
Chantilly, VA
GPS Quarterly Review
5
1
Washington DC
Information Assurance
5
2
Los Angeles CA
Information Assurance
5
2
Malmstrom AFB
EMSEC Assessment
5
2
Los Angeles AFB
EMSEC Assessment
5
2
Patrick AFB
ESMEC Assessment
5
2
Vandenberg AFB
ESMEC Assessment
5
2

(*) Local travel

1.3.1.3.2. Passports, Visas, Customs, and Travel. All contractor employees are subject to customs, processing procedures, laws, agreements, and duties of the country to which they are traveling and procedures, laws, and duties of the United States upon re-entry. The Government will supply the Contractor with letters of travel when necessary to travel by Military Airlift.

4.4.1 Any travel required to fulfill these required tasks in this SOW shall be approved by the QAE prior to actual travel and reimbursed IAW FAR 31.205-46. Local travel is defined as within 50 miles of Peterson AFB. The Contractor shall fund all local travel

4.5 PRODUCT OWNERSHIP: All products produced by the Contractor in the performance of this SOW are the property of the government.

4.6 PROPRIETARY DATA: The Contractor shall request government approval prior to the use of any proprietary data or software tools to fulfill the requirements of this SOW.

4.1. Supervision of Employees

The Government shall not supervise or otherwise direct contractor employees. The Contractor shall not supervise or otherwise direct government employees, nor shall the Contractor supervise employees of other contractors outside the Contractors’ own subcontracting/teaming arrangements.

4.2. Contractor Identification

All contractor personnel shall be required to wear company identification badges so as to distinguish themselves from government employees. These badges must be visible at all times when working with government personnel. When conversing with government personnel during business meetings, over the telephone or via electronic mail, support contractor personnel shall identify themselves as such to avoid any perception that they may be government employees and to avoid situations arising where sensitive topics might be better discussed solely between government employees. Electronic mail signature blocks shall identify contractor/company affiliation. Documents or reports produced by contractors shall be suitably marked as contractor products or contractor participation appropriately disclosed. Contractor personnel occupying collocated space in a government facility shall identify their workspace area with their name and company/contractor affiliation.

4.5.

Duty Hours

When working on government sites, the government’s normal duty hours are 0730-1630, Monday through Friday, unless otherwise specified in individual task orders. Circumstances may require the Contractor to provide services outside of normal duty hours.

4.6.

Legal Holidays

The Federal Government observes the following holidays:

New Year's Day

Martin Luther King's Birthday

President's Day

Memorial Day

Independence Day

Labor Day

Columbus Day

Veteran's Day

Thanksgiving Day

Christmas Day

4. Security Requirements.

All contractor personnel shall hold a SECRET clearance or higher. Some task orders may require security classifications up to and including TOP SECRET SCI. Additionally, contractor personnel shall possess appropriate security clearances as prescribed in individual task orders as of the task order start date. For positions requiring additional SCI clearance, contractors shall provide cleared individuals eligible for SCI at task order start. The Contractor will be given access to applicable documentation to include requirements, plans, specifications, studies, and analyses up to and including TOP SECRET SCI classification as required by individual task orders. The Contractor shall maintain accountability records/receipts for classified material to include transfer and destruction of material.

File details come from the government source that posted it. Updated .