Atch_2_-_MDT_PWS.docx

DOCX document 31 KB Posted

Attached to
Mission Defense Teams (MDT) Skills Enablement Training Federal contract opportunity
Solicitation number
FA4452-19-Q-A007
Issued by
Department of the Air Force Air Mobility Command

About this file

Attachment 2 - Performance Work Statement

View the file

Other files for this federal contract opportunity

Other files attached to Mission Defense Teams (MDT) Skills Enablement Training, newest first.
File Type Posted
Atch_1_-_Info_Sheet.docx DOCX document
Atch_3_-_Provisions_and_Clauses.pdf PDF
SAQR_MDT_Cyber_Training_Cover_Letter_Final.pdf PDF
Atch_4_-_MDT_SET_Course_Requirement_Document.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

MISSION DEFENSE TEAM

SKILLS ENABLEMENT TRAINING

PERFORMANCE WORK STATEMENT (PWS)

3 May 2019

1. DESCRIPTION OF SERVICE

1.1. Scope of Work

As the Air Force transitions postures for the 21st century, the Cyber Squadron Initiative has produced Mission Defense Teams (MDTs) to be at the front lines of cyber defense. The development and readiness of these MDTs are crucial to the success of the mission.

This Performance Work Statement (PWS) represents an understanding of the needs and readiness training requirements. This document serves as a starting point and may assist HQ AMC/A6N to enable the cyber workforce development through the customization, delivery and validation of skill-based enablement.

In lieu of an Air Force schoolhouse training curriculum, industry is required to fill the gap and provide cyber security training for the Air Force 3DXXX airmen resulting in a truly resilient MDT to meet the AMC requirements for training 3DXXX core MDT teams and develop the talent required.

1.1.1. The contractor shall provide the following five modules as part of a single 5-week course:

1.1.1.1. Network Traffic Analysis

1.1.1.2. Windows System Analysis

1.1.1.3. Behavioral Malware Analysis

1.1.1.4. Malicious Network Traffic Analysis

1.1.1.5. Cyber Threats Detection & Mitigation

1.2. Specific Support Services

1.2.1. Task 1 – Network Traffic Analysis.

1.2.1.1. The contractor will teach the Air Force students to differentiate between normal and abnormal network traffic, understand how packets flow through a network and enable them to attribute conversations and actions taken over a network segment to specific hosts or users.

This course focuses on research, filtering and comparative analysis to identify and attribute the different types of activity on a network. Students will learn how to follow conversations across a wide range of protocols and through redirection, as well as how to develop custom filters for non-dissected protocols.

1.2.1.2. The contractor will teach this module as 70% hands-on and 30% classroom instruction.

1.2.2. Task 2 – Windows System Analysis.

1.2.2.1. The contractor will teach and train the students on how to use the technology to assist in performing this task. The contractor will also teach the students how to identify abnormal activities and investigate a running system that may have been compromised where the students will learn the most useful commands, tools and techniques that can be employed during investigation to reveal the significant indicators of infiltration, as well as how to create a system baseline to be used for future analysis. The contractor will focus primarily on the Windows 10 operating system, with many tools and techniques that also apply to Windows 7 as well as recent versions of Windows Servers.

1.2.2.2. The contractor will teach this module as 70% hands-on and 30% classroom instruction.

1.2.3. Task 3 – Behavioral Malware Analysis.

1.2.3.1. The contractor will teach and train students all the fundamental skills necessary to analyze malicious software from a behavioral perspective. Using system monitoring tools and analytic software, the contractor will teach students how to observe malware in a controlled environment to quickly analyze its effects to the system. From simple key loggers to massive botnets, contractors will teach students a wide variety of current threats from today’s Internet with actual samples being analyzed in the training environment. With the majority of the module being hands-on, contractors will facilitate a learning environment where each student will be issued a computer with a secure environment to learn the skills and essential methodologies required to be an effective malware analyst.

1.2.3.2. The contractor will teach the module as 70% hands-on and 30% classroom instruction.

1.2.4. Task 4 – Malicious Network Traffic Analysis.

1.2.4.1. The contractor will teach students how to analyze, detect, and understand the network-based attacks which may impact the Air Force Network (AFNET) and Air Force mission and/or weapon systems operating on it.

1.2.4.2. The contractor will teach the students the skills needed to perform critical, real-time analysis in a production environment.

1.2.4.3. The contractor will teach the students Malicious Network Traffic Analysis and employ several traffic analysis tools to show students how to detect and analyze network attacks.

1.2.4.4. The contractor will teach the module as 70% hands-on and 30% classroom instruction.

1.2.5. Task 5 – Cyber Threats Detection & Mitigation.

1.2.5.1. The contractor will teach students about an Intrusion Detection/Prevention System (IDS/IPS) and how it affords security administrators with different abilities.

1.2.5.2. The contractor will teach the students how to defend large-scale network infrastructures by building and maintaining a mock IDS/IPS and mastering advanced signature-writing techniques.

1.2.5.2. The contractor will teach the module as 70% hands-on and 30% classroom instruction.

1.2.6. Task 6 – Validation.

1.2.6.1. The contractor will provide each student with both a written and a practical evaluation.

1.2.6.2. The contractor will facilitate a learning environment for students which culminates in a course examination detecting the various stages and attributes of a complex, multi-stage intrusion. The course examination process will produce a course certification of completion for those students who pass.

1.2.6.3. The contractor will provide HQ AMC/A6N (Chief Lance Power, email: lance.power@us.af.mil) with a similar course certificate for each student who does not pass the course examination.

1.3. General Information.

1.3.1. Contractor Knowledge.

1.3.1.1. The contractor will be required to have extensive working knowledge in cyberspace security workforce development through the customization, delivery, and validation of skill-based enablement.

1.3.1.2. The contractor will be required to have primary skill areas in systems analysis in a Windows environment and network security analysis.

1.3.1.3. The contractor will also have the skills and the ability to investigate and mitigate a broad range of intrusion and malware types in a Windows environment, analyze and respond to network-based intrusions, and build and maintain effective network defenses through the skilled use of technologies such as Intrusion Detection/Prevention Systems.

1.3.2. Hardware.

1.3.2.1. The contractor will provide all computer-based hardware and resources required on-site to teach the class, including operationally ready computers, servers, and other needed systems available for student use during the entirety of the module.

1.3.2.2. The contractor shall provide fourteen (14) individual computer workstations, keyboards and mouse peripherals to allow students to participate in the training.

1.3.2.3. The contractor shall provide a local network environment to provide for students to complete the necessary training.

1.3.2.3.1. The contractor will not connect any training resources to the Air Force Network presence at Joint Base Andrews (JBA).

1.3.3. Class Documentation.

1.3.3.1 The contractor will provide training for the students. The contractor will notify the contracting officer and HQ AMC/A6N (Chief Lance Power, email: lance.power@us.af.mil)if there are updates required.

1.3.4. Student Materials.

1.3.4.1. The contractor will provide each student with a copy of training presentations, any technical documents used during the training period and in conducting the training referenced in this PWS, to each student before the end of the class.

1.3.4.2. The contract will provide the data in para 1.3.4.1. in Portable Data Format (PDF) , using a digital optical disc storage format (i.e., DVD-ROM). Industry format is acceptable.

1.3.3.2. The contractor will advise all students of any preliminary student course work required to be completed as a prerequisite to this course. If this training has prerequisites required, the contractor will provide access to any prerequisite training necessary in advance of the course being taught and with enough time for student completion.

1.3.3.3. The contractor will make student course critiques available at the end of the course to offer feedback from the trainees in detail, to both the contractor and the Government.

1.4. Place of Performance

1.4.1. The contractor will complete this course at 89 Communications Squadron (CS), Bldg. 1558, Alabama Avenue, JBA, Maryland.

1.5. Travel

1.5.1. The contractor will travel to JBA, Maryland in performance of this PWS.

1.5.2. The contractor is responsible for all travel, hotel and rental car reservations.

1.6. Hours of Work.

1.6.1. Normal duty hours are 0730 - 1630 EST for Government employees and work weeks are Monday through Friday, excluding Federal holidays. All Federal holidays observed consist of the following: New Year's Day, Martin Luther King Day, Presidents Day, Memorial Day, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, and Christmas Day. If the holiday falls on a Saturday, it is observed on Friday. If the holiday falls on Sunday, it is observed on Monday.

1.6.2. The contractor shall ensure continuity of operations during this training period.

1.6.3. The contractor will facilitate the entirety of the single course over five consecutive weeks (5-week course).

1.7. Security Requirements.

1.7.1. Base Access (Joint Base Andrews).

1.7.1.1. All contractor personnel assigned to this task will be required to stop at the JBA Visitor Control Center to gain an authorized pass to enter the base.

1.7.1.2. During higher FPCONs, access to the base may be curtailed for extended periods.

1.7.2. Clearances.

1.7.2.1. Contractor personnel assigned are not allowed to access sensitive or classified systems during this training therefore there are no security clearances required.

1.7.3. Badges.

1.7.3.1. The contractor is required to provide identification badges for their employees who will facilitate instruction during the training course. All contractor personnel who are instructing students shall wear these badges while on duty on JBA. Badges are required to identify the individual, company name, and be clearly and distinctly marked as “contractor.” The contractor’s identification badge will not be used as an entry requirement for installation entry or into any Government designated controlled or restricted area.

File details come from the government source that posted it.