460th_SW_CSSR_CISSO_PWS__5_Year_-_4_Sept_2014.pdf

PDF 556 KB Posted

Attached to
Contractor Special Security Representative (CSSR) and Contractor Information System Security Officer (CISSO) Services Federal contract opportunity
Solicitation number
FA2543-14-R-0006
Issued by
Department of the Air Force Space Command

About this file

460 SW CSSR CISSO PWS

View the file

Other files for this federal contract opportunity

Other files attached to Contractor Special Security Representative (CSSR) and Contractor Information System Security Officer (CISSO) Services, newest first.
File Type Posted
Amendment_2_CSSR_ _CISSO.pdf PDF
Questions_and_Answers_second_round.pdf PDF
Questions_and_Answers.pdf PDF
Amendment_1_CSSR_ _CISSO.pdf PDF
460_SW_CSSR__CISSM_PWS__5_Year_-_28_July_2014_Vrs_34.pdf PDF
Wage_determination_El_Paso_County.pdf PDF
Wage_determination_Arapahoe_County.pdf PDF
FA2543-14-R-0006_5-Year_CSSR_Solicitation.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement Contractor Special Security Representative & Contractor Information System Security

Officer Support

460 SW CSSR & CISSO PWS

4 September 2014

460TH SPACE WING

CONTRACTOR SPECIAL SECURITY REPRESENTATIVE & CONTRACTOR INFORMATION

SYSTEM SECURITY OFFICER SUPPORT

PERFORMANCE WORK STATEMENT (PWS)

DATE: 4 SEPTEMBER 2014

1.0. DESCRIPTION OF SERVICES

1.1. Mission Statement. The contractor shall assist the 460th Space Wing (460 SW) Senior Intelligence Officer

(SIO) with the execution of the 460 SW Sensitive Compartmented Information (SCI) program. The contractor shall staff, manage, and provide security office services for the 11th Space Warning Squadron (11 SWS, Schriever AFB), Office of Special Investigations (OSI) Detachment 801, Buckley AFB, 460 SW and tenant organizations including the Buckley Support Team, Buckley AFB and Missile Defense Agency personnel located at Schriever AFB (SAFB).

The contractor shall provide SCI security management for military, civilian and contractor personnel. They shall also manage the 460 SW assigned Foreign Mission Partner process at BAFB. The contractor is responsible for maintaining the Sensitive Compartmented Information Facility (SCIF) accreditations on all existing 460 SW SCIFs and is responsible for obtaining and maintaining SCIF accreditation on any future 460 SW required SCIFs to include geographically separated SCIFs. The contractor is responsible for the efficient and effective management and operation of all SCI program management functions including physical, personnel, information and industrial security; they will comply with all Intelligence Community (IC), DoD and AF standards required for SCI program management. The work to be performed is not intended to be Security Guards and Patrol Services (NAICS 561612).

There are a maximum of seven SCI billets for this contract, four at the 460 SW, Buckley AFB, Colorado and three at the 11 SWS, Schriever AFB, Colorado. The security program and all duties will be performed in accordance with all regulations, directives and policies outlined in Appendix A. At a minimum one Contractor Special Security

Representatives (CSSR) will be present during duty hours at BAFB and SAFB. Duty hours are specified as 0730 –

1630 Monday through Friday except Holidays identified in paragraph 4.3. Specific duties include, but are not limited to, the following:

1.1.1. Aides the SIO with formulation and implementation of program goals, plans, policies and procedures associated with the development and operation of wing-wide SCI protection functions and activities. (BAFB & 11

SWS Mission Control Station Backup [MCSB] Contractor Special Security Representatives [CSSR])

1.1.2. Prepares detailed and in-depth written reports of findings to include, but not limited to, security incidents, classified material incidents to the BAFB SIO for submission to the HQ AFSPC SSO, HQ AFSPC/A2, HQ AFSPC

Information Assurance Manager (IAM) and Defense Intelligence Agency (DIA). (BAFB & MCSB CSSRs)

1.1.3. Reviews new and proposed legislation, and drafts of DoD, IC and AF guidance and prepares content for revised documents when requested. Independently provides recommendations based on real world risk management experiences. (BAFB & MCSB CSSRs)

1.1.4. Provides appropriate guidance, training and recommendations to subordinate squadron level organizations, activities and units. (BAFB CSSRs; MCSB CSSRs as directed by SAFB SSO and as applicable)

1.1.5. Develops/maintains and conducts a continuing SCI security education, training and awareness program for all subordinate elements on topics relevant to the protection of national security information. Prepares and conducts approximately 20 training events per year with quarterly delivery. Ensures all SCI annual training requirements are met by base personnel in accordance with EO 13526. (BAFB CSSRs & MCSB CSSR(s))

460 SW CSSR & CISSO PWS

1.1.6. Performs Staff Assistance Visits (SAV) as requested and annual self-inspections on all 460 SW SCIFs.

Prepares and presents reports of findings with recommended corrective actions to the SIO. (MCSB CSSR only complete self-inspections, not SAVs)

1.1.7. Implements DIA SCIF accreditation standards to ensure physical separation and TEMPEST requirements are maintained on all Automated Information Systems. (BAFB & MCSB CSSRs)

1.1.8. Incorporates risk assessment and risk management techniques into managing 460 SW SCIF accreditations.

Assesses local issues and conditions, coordinating with IC, DoD and AF directives. Completes and submits all required Fixed Facility Checklists and TEMPEST Addendums required to obtain and maintain DIA SCIF

Accreditation. (BAFB & MCSB CSSRs)

1.1.9. Coordinates with HQ AFSPC SSO and DIA technical authorities to provide timely and accurate customer support when reviewing and coordinating new SCIF/system requirements. (BAFB CSSRs & MCSB CSSR complete as needed)

1.1.10. Prepares drafts, coordinates and maintains finalized co-utilization agreements, memorandums of understanding between entities and other SCIF documentation as required. (BAFB & MCSB CSSRs)

1.1.11. Monitors processes for submitting official requests for Special Access Programs (SAP) and ensures they are consistent with National, DoD, IC and AF directives. (BAFB CSSRs only)

1.1.12. Buckley AFB CSSRs support the 460 SW Foreign Mission Partner (FMP) program. Provides guidance and support to all assigned FMPs with security clearance requirements and extended visit authorizations. Provides SIO support with interpreting appropriate IC, DoD, and AF classification guidance, as well as foreign disclosure decisions to ensure FMPs are granted access to only appropriate mission information. Coordinates visit access requests, to ensure appropriate accesses are passed, received and maintained. (BAFB CSSRs only)

1.1.13. Manages and maintains security requirements for approximately 1,200 460 SW SCI billets. Ensures personnel assigned to SCI billets meet and maintain all security clearance requirements in accordance with appropriate standards.

1.1.13.1 MCSB CSSR ensures all 11 SWS personnel and supporting contractors/civilians meet and maintain all security clearance requirements in accordance with appropriate standards.

1.1.14. Creates and maintains SCI-level personnel folders on assigned military, civilian and contractor personnel.

(BAFB CSSRs & MCSB CSSR complete as needed)

1.1.15. Ensures annual visitors to the 460 SW SCIFs are properly vetted in accordance with all policies and regulations found in Appendix A before access is granted. (BAFB & MCSB CSSRs)

1.1.15.1 460 SW Protocol Office requests for Distinguished Visitor (DV) clearance will be given the highest priority. DVs include cabinet secretaries, senators and congressman, DoD and IC agency directors, general officers, O-6s and civilian equivalents. (BAFB CSSRs & MCSB CSSR complete as needed in coordination with

50 SW protocol)

1.1.16. Creates and maintains required documentation for facility badge access. (BAFB & MCSB CSSRs)

1.1.17. Ensures proper procedures are implemented for officially requesting SCI indoctrinations and debriefings;

modifies them to meet individual organizational needs and ensures proper training is administered to official requestors and assistants. (BAFB CSSRs & MCSB CSSR complete as needed)

1.1.18. Monitors the Periodic Reinvestigation Program for all personnel assigned to 460 SW units to ensure all SCI-cleared personnel process their reinvestigation every five (5) years. (BAFB CSSRs only)

1.1.19. Review all reported derogatory information on SCI-indoctrinated personnel. Recommend appropriate action as required by applicable DoD personnel security regulations described in Enclosure 1 of DoD 5105.21 M1. (BAFB

CSSRs & MCSB CSSR complete as needed)

1.1.20. Establishes Media Control Procedures to ensure media (includes, but not limited to, CDs, DVDs, hard drives, zip disks and 3.5” floppy disks) are individually virus screened and assigned media control numbers prior to entering the 460 SW SCIFs. Develop media procedures to ensure each piece of media is logged when it leaves 460

SW SCIFs or is destroyed in accordance with DoD 5105.21 M 1. (BAFB & MCSB CSSRs)

1.1.21. Ensure procedures are developed/maintained for all equipment containing memory or information retention capability is approved for entry/exit into and out of 460 SW SCIFs. (BAFB & MCSB CSSRs)

1.1.22. Provides training and ensures all assigned SCIF personnel are aware of and follow established data-transfer procedures. (MCSB CSSR does this in conjunction with MCSB Contractor Information System Security Officer

(CISSO)

1.1.23. Ensures approved procedures are in place for clearing, purging, declassifying and releasing system memory, media and output. (MCSB CSSR does this in conjunction with MCSB CISSO, usually through destruction or system overwrite)

1.1.24. Provides recommendations for the proper classification of SCI and collateral documents. Conducts investigations into the possible compromise of such documents and processes security incident inquiries. (BAFB &

MCSB CSSRs)

1.1.25. Reviews and provides recommendation for user accounts on SCI automated information systems. The Joint

Worldwide Information Communications System (JWICS) trusted agent for Wing SCIFs obtains accounts for personnel with sufficient need and mission impact. (BAFB CSSRs & MCSB CSSR in conjunction with the MCSB

CISSO/Contractor Information System Security Officer (CISSO))

1.1.26. Oversees the internal configuration of the Intrusion Detection System (IDS) and the Access Control System

(ACS) to ensure compliance with all applicable policy and regulations. (BAFB & MCSB CSSRs)

1.1.27. Recommends actions and ensures compliance with all Standard Operating Procedures (SOPs) for 460 SW

SCIFs. Noncompliance will be reported to SIO or appropriate personnel in accordance with DoD 5105.21 M1.

(BAFB/MCSB CSSRs and CISSOs)

1.1.28. Maintains in-depth involvement with every Automated Information System (AIS) and Space-Based Infrared

Systems (SBIRS) weapon system configuration change, upgrade, installation, etc. Receives, inspects, approves, and records all equipment entering and exiting the SCIFs in accordance with DoD 5105.21 M 1. Works with engineers to ensure all equipment is installed and removed in accordance with all SCI regulations and policy. (BAFB &

MCSB CSSRs and CISSO)

1.1.29. Assists with Information Assurance (IA) duties for 460 SW SCIFs, to include SCI AIS accreditation, baseline maintenance and network connectivity architecture. (BAFB/MCSB CSSRs and CISSOs)

1.1.30. Updates and maintains an AIS baseline for all 460 SW SCIFs. Updates and maintains a network diagram for each of the AIS systems within these SCIFs. (MCS/MCSB CSSRs and CISSOs)

1.1.31. The contractor shall review physical and logical architecture specifications to verify IA requirements are satisfied at an acceptable level of risk and report any issues to the Government as required. (MCSB CISSOs)

1.2. Directives, Instructions, and Regulations. The contractor shall adhere to and remain familiar with the most up-to-date documents listed in Appendix A.

1.3. Locations of Requirement. Special Security Representative and Information System Security Officer support is required at BAFB and 11 SWS located at SAFB.

1.4 Contractor Support. Prime contractor will ensure continued qualified support without a vacancy greater than two (2) weeks.

1.5 Capability. All contractors on this contract shall have the capability, skills, training, and experience necessary to fulfill the specific duties addressed throughout this PWS in accordance with DoDM 5105.21.

1.5.1 Contractor Special Security Representative(s) shall have the capability to perform the following:

Manage facets of a Sensitive Compartmented Information (SCI) program including physical, personnel, information or industrial security.

Implement necessary standards, such as Defense Intelligence Agency (DIA) SCIF accreditation standards, to ensure physical separation and TEMPEST requirements are maintained on all Automated

Information Systems (AIS).

Provide security office services, ensuring personnel assigned to SCI billets meet and maintain all security clearance requirements.

Manage the following programs/procedures: Periodic Reinvestigation Program, Media Control

Procedures, and Intrusion Detection System (IDS) and the Access Control System (ACS)

Manage personnel, visitors and visit requests in databases used by the Intelligence Community to record eligibility and access to Sensitive Compartmented Information and other caveated programs such as

Joint Personnel Adjudication System (JPAS), Scattered Castles and Air Force Space Command (SCIBS).

Maintain the Sensitive Compartmented Information Facility (SCIF) accreditations on SCIFs and SCIF accreditation on any future SCIFs to include geographically separated SCIFs.

1.5.2 Contractor Information System Security Officer(s) shall have the capability to perform the following:

Manage TS networks and ensure controlled access and updates to an SCI system.

Patching updates, and other system administration related tasks on TS networks such as GWAN, JWICS, VIAS, Blue/Red SIS, and Defense Red Switch Network (DRSN) or equivalent.

Obtain accounts for personnel with sufficient need and mission impact.

Receive, inspect, approve, and record all equipment entering and exiting SCIFs in accordance with appropriate regulations such as DoD 5105.21 M 1.

Ensuring equipment is installed and removed in accordance with all SCI regulations and policy.

Verify IA requirements are satisfied at an acceptable physical and logical architecture specifications level of risk.

2.0. SERVICE SUMMARY

Performance Objective PWS Para Performance Threshold

Maintain DIA SCIF Accreditation 1.1-1.1.32 Maintain SCIF Accreditations by fulfilling

DIA requirements 100% of the time.

Maintain CSSR presence on BAFB and

SAFB

1.1 At a minimum, one CSSR must be

available during duty hours on BAFB and

SAFB.

Security Clearance 4.5 All personnel on contract must maintain

Security Clearances 100% of the time without discrepancies.

Maintain qualified personnel 1.4 Provide continued qualified support without a vacancy greater than two (2) weeks.

Quality Control Plan 2.5 Contractor will ensure ongoing quality control per their Quality Control Plan.

2.1. Deliverables.

Support

Area

Title Date Due Description

Management Monthly Status

Reports

35 days after the official award date and provide subsequent

Monthly Status Reports the

5th duty day of each month.

Synopsis of contractor activities during the month to satisfy task requirements.

Includes hours/cost expended and any other amplifying information

Management Quality Control

Plan

Within 30 days after contract award and within 7 calendar days of any approved updated changes.

See paragraph 2.5 below for description

Management Staffing Plan Within 30 days after contract award and an updated Staffing

Plan within 7 calendar days of any approved updated changes.

Must provide qualified personnel capable of performing work as set forth in this

PWS

Management Personnel

Roster

Within 10 days after contract award and within 7 calendar days of any approved updated changes.

List of personnel and contact information

Management Media Plan Within 30 days after contract award within 7 calendar days of any approved updated changes.

See paragraph 1.1.20

Management Mission-

Essential

Contractor

Services Plan

Within 30 days after contract award within 7 calendar days of any Contracting Officer approved updated changes.

DFARS 252.237-7023 (Oct 2010)

2.2. Deliverables. All deliverables must meet professional standards and the task descriptions set forth herein. The format is subject to the approval of the Government. The contractor shall be responsible for delivering the following end items as specified in accordance with this contract. The deliverables specified herein shall be produced in hard and soft copy using media compatible with Government software applications. When required, a hard copy will be supplied to the following address:

460 OG/OGI

510 S Aspen Street, Stop 98

Buckley AFB, CO 80011

2.2.1. Monthly Status Reports. The contractor shall deliver to the Contracting Officer’s Representatives (COR)

Monthly Status Report within 35 days after the official award date and by the 5th duty day of each month thereafter which matches the table above. Each status report will cover contractor activities during the prior calendar month organized by subtask and include: (a) narrative or bullet style review of work accomplished during the reporting period and/or significant events, (b) deliverable progress, (c) problem areas, and (d) anticipated activity for the next reporting period.

2.2.2. Presentation Material/Briefing Material. Copies of presentation material shall be provided for Government approval at least five (5) working days before distribution or presentation, unless otherwise specified. Copies will be given for review in soft copy format at a minimum.

2.3. Data. The Government has unlimited rights to all deliverables of this contract.

2.4. Inspection. Deliverables will be inspected by the government within five (5) duty days of receipt. Progress meetings may be held as required.

2.5. Quality Control Program. The contractor shall develop and implement a Quality Control Plan, which describes in detail an inspection system to cover all services listed in the Service Summary, specific areas to be inspected on both a scheduled and unscheduled basis. Quality control procedures should present all aspects of quality control to include responsibility for surveillance, a description of records to be kept and methods for identifying and preventing defects in the quality of service. The records of inspections will be available to the

Government upon request. The contractor shall provide the CO the Quality Control Plan for review and approval within 30 days of contract award.

2.6. Mission-Essential Contractor Services Plan. The Government has identified services performed under this contract as essential contractor services in support of mission essential functions. See the services listed in

Appendix C, Mission-Essential Contractor Services, dated 07 March 2014. Additionally, as directed by the

Contracting Officer, the Contractor shall participate in training events, exercises, and drills associated with

Government efforts to test the effectiveness of continuity of operations procedures and practices. The contractor shall provide the CO with the Mission Essential Contractor Service plan for review and approval within 30 days of contract award.

3.0. GOVERNMENT FURNISHED PROPERTY (GFP)

3.1. Property Coincidental to Performance. The Government will provide the facilities, equipment, records, and services listed for contractor personnel. All Government property used by the contractor shall be accounted for in accordance with the Government property clause and the general provisions of the contract.

3.1.1. Telephone Service. The Government will provide SCI-level, collateral-level, local, long-distance and DSN telephone service for official business use only in support of contract requirements.

3.1.2. Facilities, Supplies and Services. The Government has historically and will continue to provide office space, supplies, computer equipment, access to military LAN services (classified and unclassified), telephone and fax (SCI-level, collateral-level, local, DSN and long distance), electronic mail, LAN support, reproduction facilities and facilities to store classified working papers and data (media disks, hard drives, etc.). The contractor shall provide a

National Agency Check for on-site employees to be granted LAN access.

3.2. Information. The Government will provide the following: access to relevant government organizations, information and documentation, manuals, texts, briefs and associated materials as required and available. Access will be granted to classified networks under the guidance of the SIO.

4.0. GENERAL INFORMATION

4.1. Place of Performance. Primary location of work performance is Buildings 1030 and 442 at Buckley AFB, CO

80011 and Building 712 at Schriever AFB, CO 80912.

4.2. Excused Absences. In the event of weather, natural disasters, riots or civil disturbances contractor personnel will conform to customer agency delayed reporting, early release and base closure requirements. All excused absences must be approved by the Contracting Officer.

4.3. Recognized Holidays. The Contractor is not required to provide services on the following days: New Year’s

Day, Martin Luther King's Birthday, Presidents' Day, Memorial Day, Independence Day, Labor Day, Columbus

Day, Veteran's Day, Thanksgiving Day, and Christmas Day.

4.4. Facility Clearance. Contractor must possess and maintain a Top Secret Facility Clearance via DD Form 254 before performance of contract and must maintain for the duration of the contract with no Government reimbursement for sponsoring clearance approvals.

4.5. Security Clearance. The individuals selected to perform this work are required to possess, at a minimum, a current TOP SECRET clearance with SCI. Visitor Group Security Agreements will be enacted and a DD Form 254 will be issued.

4.6. Personnel Roster. The contractor shall provide a personnel roster consisting of names, social security numbers, and security clearance confirmation no later than 10 calendar days after the contract award date. The personnel roster shall be updated as individuals are removed and added and within 7 calendar days of any

Contracting Officer approved updated changes.

4.7. Network Access. The contractor(s), with a valid security clearance verified through JPAS, entry access list, or validation from the on-site contractor’s security manager, shall be provided access to the hosting bases’ classified and unclassified computer networks and their inherent capabilities including, but not limited to: Internet access, electronic mail, file and print services, and dial-in network access. The contractor shall be held accountable for all actions that he or she initiates while on the network and shall conduct his or her business in accordance with all AF and local base instructions, manuals, and policies. Any conduct that does not adhere to sound or just network usage as stipulated in official guidance will cause revocation of all network privileges. All personnel having access to Air

Force program information will be required to execute non-disclosure and information protection agreements.

4.8. Travel. The Government does not anticipate any required travel for this effort. If travel is required, all costs will be incurred at the contractor’s expense. All travel will be approved by the Contracting Officer Representative

(COR) and the Contracting Officer prior to departure.

4.9. Privacy Act. Work on this project requires that personnel have access to Privacy Information. Contractor shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations.

4.10. Physical Security. Contractor shall be responsible for safeguarding all Government property in the work area.

At the close of each workday, the contractor shall secure facilities and equipment.

4.11. Key Control. The contractor shall establish and implement methods of ensuring that all keys issued by the

Government are not lost or misplaced and are not used by unauthorized persons. No keys issued to the contractor by the Government shall be duplicated. The contractor may be required to reimburse the Government for replacement of key and/or lock as a result of contractor losing keys.

4.12. Employees. Contractor personnel shall wear distinctive clothing and/or lanyard bearing the name of the company at all times while performing under this contract. Contractor employees shall identify themselves as such when answering phone calls, sending emails, and during Government meetings in order to prevent organizational conflicts of interest. The contractor shall not employ any person who is an employee of the U.S. Government to include, but not limited to, the Department of the Air Force, either military or civilian, unless such person seeks and receives approval according to DODD 5500-7, Joint Ethics Regulation.

4.13. Professional Appearance of Work Space. The contractor staff shall maintain work space areas neat and orderly to avoid safety violations.

4.14. Section 508 Compliance. The Industry Partner shall support the Government in its compliance with Section

508 throughout the development and implementation of the work to be performed. Section 508 of the Rehabilitation

Act of 1973, as amended (29 U.S.C. 794d) requires that when Federal agencies develop, procure, maintain or use electronic information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who do not have disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.

The Industry Partner should review the following websites for additional 508 information:

http://www.section508.gov/index.cfm?FuseAction=Content&ID=12 http://www.access-board.gov/508.htm http://www.w3.org/WAI/Resources

4.15. Multifunction Team. The Contract Manager may be required to meet with the CO, Contract Administrator

(CA), QA Personnel, and other Government personnel as deemed necessary. The contractor may request a meeting with the CO when the contractor believes such a meeting is necessary. If the CO or CA deems necessary, written minutes of any such meetings shall be recorded in the contract file and signed by the contractor representative and the CO or CA. If the contractor does not concur with any portion of the minutes, such non-concurrence shall be provided in writing to the CO within 10 calendar days following receipt of the minutes.

4.16. Contractor Manpower Reporting.

4.16.1. The contractor shall report ALL contract labor hours (including subcontractor labor hours) required for performance of services provided under this contract for CSSR and CISSO support services via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address: http://www.ecmra.mil/.

4.16.2. Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September. While inputs may be reported any time during the FY, all data shall be reported no later than 31 October of each calendar year. Contractors may direct questions to the

CMRA help desk at: http://www.ecmra.mil/.

4.17. OPSEC Requirements within Contracts. Contractor(s) shall comply with all provisions of AFI 10-701, AFSPC Supplement, and 460 SW policies. Key excerpts are below.

4.17.1. Contractor(s) will practice OPSEC to protect critical information for specific government contracts and subcontracts. Contractor(s) should identify OPSEC measures in their requirements documents and ensure they are identified in resulting solicitations and contracts. Contractor(s) will consider OPSEC for all contractual requirements.

4.17.2. Contractor(s) will protect critical, sensitive and for official use only (FOUO) contracted information. The user organization will provide OPSEC guidance for the contractors. The following OPSEC guidance is provided:

4.17.2.1. Organization’s critical information list

4.17.2.2. Adversaries’ collection threat information as it applies to the organization’s mission and the contract, (phishing, dumpster diving, etc.)

4.17.2.3. Operations security guidance (AFI 10-701)

4.17.2.4. Specific OPSEC measures the organization requires

4.17.2.4.1. 100% shred policy

4.17.2.4.2. Out-of-office replies/messages

4.17.2.5. E-mail guidance with respect to OPSEC

4.17.2.6. OPSEC Training

4.17.3. All required OPSEC training will be provided free to mission partners and contractors from the Government user organization OPSEC Coordinators upon contract award.

APPENDIX A: APPLICABLE PUBLICATIONS AND FORMS

1. Publications and forms applicable to this PWS are listed below. The contractor is obligated to follow those publications and use those forms coded as to the extent (specific procedure - paragraph, section, chapter or volume) specified in the PWS or in accordance with industry standards and local, state or Federal regulations.

2. It is the responsibility of the contractor to obtain and keep publications updated. Current publications can be found by accessing the Air Force Electronic Publications Library through the Internet: http://www.e-publishing.af.mil/. Other commercial related information stated in the PWS can be obtained by common commercial internet browsers. Contact the COR if found unavailable.

3. Supplements or amendments to listed publications from any organizational level may be issued during the life of the contract. The contractor shall immediately implement those changes in publications, which result in a decrease or no change in the contract price and notify the Contracting Officer (CO) in writing of such change. Should a decrease in contract price result, the contractor shall provide a proposal for a reduction in the contract price to the

CO.

4. Prior to implementing any such revision, supplement, or amendment that will result in an increase in contract price, the contractor shall submit to the CO a price proposal and obtain the prior approval of the CO. Said price proposal shall be submitted by the next workday from the date the Contractor receives notice of the revision, supplement, or amendment giving rise to the increase in cost of performance. The CO and the contractor shall negotiate the change into the contract under the provisions of the contract clause entitled “Changes”.

5. It is the contractor's responsibility to ensure compliance with applicable publications listed at appendix A at all times during performance of the contract. The most current publication(s) are located at the Air Force E-Publishing website at www.e-publishing.af.mil. Publications are updated on a continuing basis and it is the contractor’s responsibility to check for the most current version to ensure compliance.

AFH 31-602, Industrial Security Program

AFI 31-101, Integrated Defense (FOUO)

AFI 31-401, Information Security Program Management

AFI 31-501 Personnel Security Program Management

AFI 31-601, Industrial Security Program Management

AFI 33-112, Information Technology Hardware Asset Management

AFI 33-114, Software Management

AFI 33-115V1, Network Management

AFI 33-115V2, Licensing Network Users and Certifying Network Professionals

AFI 33-200, Information Assurance (IA) Management

AFI 33-201V1, Communications Security (COMSEC)

AFI 33-201V2, Communication Security (COMSEC) Users Requirements

AFI 33-201V4, Cryptographic Access Program

AFI 33-201V5, Controlled Crytrographic Items (CCI)

AFI 90-201, The Air Force Inspection System

DoD 5200.40, DoD Information Technology Security

DoD 5200.1-R, DoD Information Security Program

AFPAM 63-1701, Program Protection Planning

AFPD 10-7, Information Operations

AFPD 31-4, Information Security

AFPD 31-6, Industrial Security

AFPD 33-2, Information Assurance (IA) Program

AFPD 33-3, Information Management

AFI 10-701, Operations Security (OPSEC)

DoDR 5400.7, DoD Freedom of Information Act Program

DoDR 5400.7 AFSUP 1, DoD Freedom of Information Act Program

DODD 8000.1, Management of Defense Information Enterprise

DODD 5220.22, National Industrial Security Program (NISPOM)

DODD 8500.01, Cybersecurity

DODD 8570.01E/M, Information Assurance

DODD 8570.1, Information Assurance Training, Certification, and Workforce Management

AFMAN 33-363, Management of Records

AFMAN 36-2234, Instructional System Development

AFMAN 36-2236, GUIDEBOOK FOR AIR FORCE INSTRUCTORS

AFMAN 33-326, Preparing Official Communication

DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), March 12, 2014

ICD 2005-1 System of Intelligence Community Directives; Status of Director of Central Intelligence Directives;

Delegation to the Principal Deputy Director of National Intelligence, April 21, 2005

ICD 1 Policy Directive for Intelligence Community Leadership, May 1, 2006

ICD 101 Intelligence Community Policy System, January 16, 2009

ICPG 101-1 Intelligence Community Directives and Policy Guidance, January 16, 2009

ICPG 101-2 Intelligence Community Standards, January 16, 2009

ICD 102 Process for Developing Interpretive Principles and Proposing Amendments to Attorney General Guidelines

Governing the Collection, Retention, and Dissemination of Information Regarding U.S. Persons, November 19, 2007 (formerly ICD 153)

ICD 103 Intelligence Enterprise Exercise Program, July 14, 2008

ICD 104 National Intelligence Program (NIP) Budget Formulation and Justification, Execution, and Performance

Evaluation, April 30, 2013

ICD 106 Intelligence Community Strategic Enterprise Management, November 20, 2008 (rescinded and superseded by ICD 116)

ICD 107 Civil Liberties and Privacy, August 31, 2012

ICD 108 Intelligence Community History Programs, August 29, 2007

ICD 109 Independent Cost Estimates, April 26, 2010

ICD 110 Intelligence Community Equal Employment Opportunity and Diversity, July 1, 2009

ICD 111 Accountability Reviews, August 4, 2011

ICD 112 Congressional Notification, November 16, 2011

ICD 113 Functional Managers, May 19, 2009

ICD 114 Comptroller General Access to Intelligence Community Information, June 30, 2011

ICD 115 Intelligence Community Capability Requirements Process, December 21, 2012

ICD 116 Intelligence Planning, Programming, Budgeting, and Evaluation System, September 14, 2011

ICD 117 Outside Employment, June 9, 2013

ICD 118 Intelligence Community Continuity Program, November 12, 2013

ICD 119 Media Contacts, March 20, 2014

ICD 120 Intelligence Community Whistleblower Protection, March 20, 2014

ICD 200 Management, Integration, and Oversight of Intelligence Community Analysis, January 8, 2007

ICD 201 National Foreign Intelligence Warning System (Redacted), June 6, 2006

ICD 202 National Intelligence Board, July 16, 2007

ICD 203 Analytic Standards, June 21, 2007

ICD 204 Roles and Responsibilities for the National Intelligence Priorities Framework, September 13, 2007

ICD 205 Analytic Outreach, July 16, 2008

ICD 206 Sourcing Requirements for Disseminated Analytic Products, October 17, 2007

ICD 207 National Intelligence Council, June 9, 2008

ICD 208 Write for Maximum Utility, December 17, 2008

ICD 209 Tearline Production and Dissemination, September 6, 2012

ICD 300 Management, Integration, and Oversight of Intelligence Collection and Covert Action, October 3, 2006

ICD 301 National Open Source Enterprise, July 11, 2006

ICD 302 Document and Media Exploitation, July 6, 2007

ICD 304 Human Intelligence, March 6, 2008, amended July 9, 2009

ICD 404 Executive Branch Intelligence Customers, July 22, 2013

ICD 500 DNI Chief Information Officer, August 7, 2008

ICPG 500.2 Attribute-Based Authorization and Access Management, November 23, 2010

ICD 501 Discovery and Dissemination or Retrieval of Information Within the Intelligence Community, January 21, ICPG 501.1 Exemption of Information From Discovery, May 26, 2009

ICPG 501.2 Sensitive Review Board and Information Sharing Dispute Resolution Process, May 26, 2009

ICPG 501.3 Subsequent Use of Information, May 20, 2010

ICD 502 Integrated Defense of the Intelligence Community Information Environment, March 11, 2011

ICD 503 Intelligence Community Information Technology Systems Security: Risk Management, Certification and

Accreditation, September 15, 2008

ICD 601 Human Capital - Joint Intelligence Community Duty Assignments, May 16, 2006 (amended September 4, 2009)

ICPG 601.1 Intelligence Community Civilian Joint Duty Program: Implementing Instructions, Intelligence

Community Policy Guidance, June 25, 2007 (amended September 4, 2009)

ICD 602 Human Capital - Intelligence Community Critical Pay Positions, August 16, 2006

ICD 610 Competency Directories for the Intelligence Community Workforce, September 1, 2008, amended October

4, 2010

ICD 612 Intelligence Community Core Contract Personnel, October 30, 2009

ICD 623 Appointment of Highly Qualified Experts, October 16, 2008

ICD 630 Intelligence Community Foreign Language Capability, May 14, 2012

ICD 650 National Intelligence Civilian Compensation Program: Guiding Principles and Framework, April 28, 2008

ICD 651 Performance Management System Requirements for the Intelligence Community Civilian Workforce, November 28, 2007 (updated April 4, 2012)

ICD 652 Occupational Structure for the Intelligence Community Civilian Workforce, April 28, 2008

ICD 653 Pay-Setting and Administration Policies for the Intelligence Community Civilian Workforce, May 14, ICD 654 Performance-Based Pay for the Intelligence Community Civilian Workforce, April 28, 2008

ICD 655 National Intelligence Awards Program, May 23, 2007 (amended February 9, 2012)

ICD 656 Performance Management System Requirements for Intelligence Community Senior Civilian Officers, April 28, 2008 (amended April 4, 2012)

ICD 660 Intelligence Community Civilian Joint Duty Program, February 11, 2013

ICD 700 Protection of National Intelligence, June 7, 2012

ICPG 700.1 Security Glossary

ICPG 700.2 Security Governance

ICD 701 Security Policy Directive for Unauthorized Disclosures of Classified Information, March 14, 2007

ICD 702 Technical Surveillance Countermeasures, February 18, 2008

ICPG 702.1 TSCM

ICD 703 Protection of Classified National Intelligence, Including SCI

ICPG 703.1 Continuing Reporting

ICPG 703.2 SCI Management

ICPG 703.3 Non-Title 50

ICPG 703.4 Foreign Partners

ICPG 703.5 Dissemination Controls

ICPG 703.6 Risk Management

ICD 704 Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented

Information and Other Controlled Access Program Information, October 1, 2008

ICPG 704.1 Personnel Security Investigative Standards and Procedures Governing Eligibility for Access to SCI and

Other Controlled Access Program Information, October 2, 2008

ICPG 704.2 Personnel Security Adjudicative Guidelines for Determining Eligibility for Access to Sensitive

Compartmented Information and Other Controlled Access Program Information, October 2, 2008

ICPG 704.3 Denial or Revocation of Access to Sensitive Compartmented Information, Other Controlled Access

Program Information, and Appeals Processes, October 2, 2008

ICPG 704.4 Reciprocity of Personnel Security Clearance and Access Determinations, October 2, 2008

ICPG 704.5 Intelligence Community Personnel Security Database Scattered Castles, October 2, 2008

ICD 705 Sensitive Compartmented Information Facilities, May 26, 2010

ICS 705.1 Physical and Technical Security Standards for SCIFS, September 17, 2010

ICS 705.2 Standards for the Accreditation and Reciprocal Use of SCI, September 17, 2010

ICD/ICS 705 Technical Specifications for Construction and Management of SCIFS, Version 1.2, April 23, 2012

ICD 706 Controlled Access Program Oversight Committee (CAPOC)

ICPG 706.1 CAP Governance/Management

ICD 707 Center for Security Evaluation, October 17, 2008

ICPG 707.1 Center for Security Evaluation Construction Security Review Board, June 12, 2008

ICD 708 TEMPEST

ICD 709 Reciprocity for Intelligence Community Employee Mobility, June 10, 2009

ICD 710 Classification Management and Control Markings System, June 21, 2013

ICD 731 Supply Chain Risk Management, December 7, 2013

ICD 732 Damage Assessments, June 27, 2014

ICD 801 Acquisition, August 15, 2006 (amended August 16, 2009)

ICPG 801.1 Acquisition, July 12, 2007

ICPG 801.2 Contracting and Procurement Policy, September 20, 2008

ICPG 801.3 Acquisition Workforce, October 21, 2011

ICD 900 Mission Management, December 21, 2006

ICD 901 Program Management Posture Adjustment Notification, June 23, 2008

ICD 902 Global Maritime and Air Intelligence Integration, January 14, 2009

APPENDIX B: ESTIMATED WORKLOAD DATA

ESTIMATED WORKLOAD DATA

Location Buckley

AFB

Buckley

AFB

Buckley

AFB

Buckley

AFB

Schriever

AFB

Schriever

AFB

Schriever

AFB

Senior

CSSR

CSSR -

Personnel

Security

CSSR –

Information

Security

CSSR -

Physical

Security

CSSR CISSO CISSO

Hours 1880 1880 1880 1880 1880 1880 1880

Total Estimated Hours 13,160

INCREMENT TWO TRANSITION

This contract will encompass the Increment Two transition which may include a potential influx in the number of personnel operating in 460 Space Wing SCIFs. The following represents a general timetable for the transition:

1) Fiscal Years (FY) 15 & 16 – A slight influx in personnel occupying the 460 SW SCIFs may occur. While the initial influx is planned to occur during FY 15 & 16, the number of personnel should remain constant throughout the remainder of the contract. This influx is not believed to impose any additional work outside of the responsibilities identified in paragraphs 1.1.1 through 1.1.32 of the PWS.

2) Fiscal Year 17 – Equipment upgrades and installations should be completed by the end of FY 17.

APPENDIX C: Mission-Essential Contractor Services

File details come from the government source that posted it. Updated .