Attachment_07_-_Scenario_PWS.pdf
PDF 185 KB Posted
- Attached to
- Information Security Support Services Federal contract opportunity
- Solicitation number
- FA7037-19-R-A001
About this file
This performance work statement outlines information security support services required by the Department of the Air Force Air Combat Command. The contractor shall provide cybersecurity assessments, engineering, plans and policies, and program management support. Key tasks include conducting security control assessments on Air Force Intelligence Community systems using NIST and CNSS standards, performing vulnerability scanning and remediation, and implementing the Risk Management Framework. The contractor must have TS/SCI clearance and personnel must hold certifications including IAT Level II, IAM Level II/III, and specialized certifications for tasks like auditing and incident response. The period of performance is one year with the possibility of extensions. The work will take place primarily at Brighttown AFB in Texas but may require up to 85% travel to other locations as needed to support intelligence, surveillance, and reconnaissance missions.
This is the technical scenario PWS AND IS NOT the IDIQ PWS. See Exhibit 1 for the PWS associated with this requirement action. Additional "made up" information has been added to this PWS for the purposes of simulation of requirements in order to assure that all offerors across Industry can make similar assumptions.
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 07 – Scenario PWS
PERFORMANCE WORK STATEMENT (PWS) FOR
AIR FORCE (AF) INTELLIGENCE COMMUNITY (IC) ENTERPRISE
CYBERSECURITY RISK MANAGEMENT FRAMEWORK (RMF)
Brighttown1 AFB Program Management
Office Support 1 June 2019
1 Brighttown AFB is a fictional location located in the Texas Panhandle for purposes of this example PWS.
1.0 DESCRIPTION OF SERVICES.
1.1 Introduction.
1.1.1 The cybersecurity and information technology (IT) security services described in this Performance Work Statement (PWS) support the Air Force (AF) Intelligence Community (IC) Chief Information Officer (CIO), Chief Information Security Officer (CISO) and the Authorizing Official (AO) efforts to manage risk and protect Intelligence, Surveillance, and Reconnaissance (ISR) missions and resources. External customers are across all major commands (MAJCOMS) throughout the Air Force.
1.1.2 This is a non-personal services contract. The Government will neither supervise contractor employees nor control the method by which the contractor performs the required tasks. The contractor shall manage its employees and guard against any actions that are of the nature of personal services or give the perception of personal services. The contractor shall notify the Contracting Officer (CO) immediately if they perceive any actions that constitute personal services. These services shall not be used to perform any Inherently Governmental Functions.
1.2 Background.
1.2.1 The increase in responsibilities, our customer base, and Quick Reaction Capability (QRC) operational needs have resulted in our need to obtain contract services support. On 1 Aug 2016, the AF Intelligence, Surveillance and Reconnaissance Chief Information Officer (AF ISR CIO) appointed Chief of the HQ ACC/A2 Intelligence, Surveillance and Reconnaissance Division (ACC/A2Y) as the AF IC CISO. In coordination with the AF ISR CIO, the AF IC CISO shall ensure compliance with AF and IC information technology (IT) systems security risk management, assessments, authorization guidelines, and Federal Information Security Management Act (FISMA) compliance and reporting. The AF IC CISO became independent of other intelligence organizations and now serves as the voting member at intelligence forums and councils for the AF ISR Element.
1.2.2 The AF IC CIO, AF IC CISO and AF IC AO scope of authority applies to Sensitive Compartmented Information (SCI), Guest SCI, Collateral (Top Secret and below), and Intelligence, Surveillance and Reconnaissance (ISR) (regardless of classification) data, systems and resources. These authorities are responsible to the Air Combat Command (ACC)/A2, AF/A2, the AF Chief Information Officer (CIO), and the Office of the Director of National Intelligence (ODNI) to manage risk for the AF IC Enterprise. They are required to implement, manage and report the status of various Risk Management Program responsibilities such as Risk Management Framework (RMF), Computer Network Defense (CND), Audit Collection and Sharing.
1.2.3 The AF IC AO is responsible for managing risk and determines the authorization decisions to provide or not provide an Authorization to Operate (ATO). AO authorization decisions consider security standards, the defense against threats, the confidentiality, integrity and availability category levels for information assets, and the ability to achieve vital, national-security missions. The AO is also responsible for ensuring AF IC cybersecurity training of military, civilian and contractors in the positions supporting the ICD 502 and ICD 503 implementation is met.
1.2.4 The AF IC CIO, AF IC CISO and AF IC AO responsibilities require the implementation of Intelligence Community Directive (ICD) 502, “Integrated Defense of the Intelligence Community Information Environment,” and ICD 503, “Information Technology Systems Security Risk Management Certification and Accreditation,”
1.2.5 ICD 501, “Discovery and Dissemination or Retrieval of Information within the Intelligence Community,” and Intelligence Community Standard (ICS) 500-27, “Collection and Sharing of Audit Data,” and progress is monitored by the ODNI and HAF/A2. The RMF and AF IC integrated defense processes must be integrated throughout the lifecycle of SCI, ISR, and Department of Defense Intelligence Information System networks, systems, databases and applications. The AO works closely with the AF Office of Special Investigation (AFOSI) to implement and maintain the AF IC Computer Network Defense (CND) Program; the AF Distributed Common Ground System (DCGS) Program Management Office (PMO); the AF Joint Worldwide Intelligence Communications System (JWICS) PMO; and other ISR PMOs.
1.3 Scope.
The tasks described in this PWS support the AF IC CIO, CISO and AO in sustaining, integrating, protecting, and advancing AF IC communications capabilities; Cybersecurity management;
protections; defenses; engineering; compliance; and assessments by providing timely, reliable support to the current and future AF IC missions. IT security services support AF IC networks, systems, applications, databases, classified as SCI and ISR (regardless of classification) and support the Air National Guard systems. Services shall be performed at Brighttown AFB, Texas and others areas as needed where ISR is conducted. All tasks described in section two (2) below must be conducted by personnel who are certified according to Appendix B; those DOD 8570.1 certification requirements outlined in Appendix B begin on day one of the period of performance and run throughout the life of the contract. Tasks shall include management of the AF IC Federal Information Security Management Act (FISMA) records and reporting, a Congressionally-levied program.
1.4 Period of Performance.
The Period of Performance (POP) for this Task Order shall be for a one (1) year period.
2.0 SPECIFIC TASKS.
The contractor shall provide the following TO cybersecurity tasks in support of the AF IC CIO, CISO, AO and Risk Executive Function (REF) requirement to manage risk and protect the confidentiality, integrity, availability of our AF IC missions and resources.
2.1. Program Management for Implementing AF IC Enterprise Cybersecurity Solutions.
RESERVED
2.2. IT Security Control Assessments.
2.2.1 The contractor shall serve as a security control assessor (SCA). A SCA shall meet the minimum qualification requirements as identified by AF and IC security control assessment polices (in accordance with PWS attachment Appendix B); and shall be appointed in writing by the AO.
The SCA shall complete required reports for a risk decision from the AO or CISO. The contractor shall adhere to USAF and IC laws, standards, policies and procedures. The contractor shall conduct comprehensive IT security control assessments on systems identified within the scope of this contract.
Systems at Brighttown AFB
# of Systems to be annually assessed
Large Complex Systems 4
Medium Semi-Complex Systems 50
Small Semi-Complex Systems 25
All assessments will be conducted at Brighttown AFB, Texas. Assessments shall determine the condition of the management, operational, and technical security controls employed within or inherited by an information system to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). The contractor shall provide an assessment on the severity of weaknesses or deficiencies discovered in the information system and its environment of operation and recommend corrective actions to address identified vulnerabilities. The contractor shall create, maintain and dispose of only those Government required records and supporting documentation that are specifically cited in this Performance Work Statement (PWS) or required by the provisions of a mandatory directive. The contractor shall create, maintain and dispose of only those Government required records and supporting documentation that are specifically cited in this Performance Work Statement (PWS) or required by the provisions of a mandatory directive ( A013)
2.2.2 The contractor shall review the System Security Plan (SSP), prior to initiating the security control assessment and ensure the plan provides a set of security controls for the information system that meet the stated security requirements. Assessments shall include the review and validation of the message types authorized and the parsing of the data utilizing rule sets implemented within the Cross Domain Solutions (CDS) application to validate authorized processing of data and elimination of the possible spillage of classified information.
2.2.3 The contractor shall:
2.2.3.1 Advise the Information System Owner (ISO) concerning the impact values for confidentiality, integrity, and availability for the information on a system;
2.2.3.2 Evaluate threats and vulnerabilities to information systems to ascertain the need for additional safeguards;
2.2.3.3 Review and approve the information system security assessment plan, which is comprised of the SSP, the Security Controls Traceability Matrix (SCTM), and the Security Control Assessment Procedures;
2.2.3.4 Ensure security control assessments are completed for each information system and ensure controls are working as intended and these controls protect the confidentiality, integrity and availability of IT resources at the appropriate levels;
2.2.3.5 Prepare the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity; (A013)
2.2.3.6 Ensure a Plan of Action and Milestones (POA&M) is initiated by the ISSO for the information system based on findings and recommendations from the SAR; (A007)
2.2.3.7 Evaluate security control assessment documentation and provide written recommendations for security authorization to the AO; (A013)
2.2.3.8 Assemble and submit the security authorization artifacts to the AO (consisting of, at a minimum, the SSP, the SAR, the POA&M, and a Risk Assessment Report (RAR); (A007, A013)
2.2.3.9 Assess the proposed changes to information systems, their environment of operation, and mission needs to determine if they are security-relevant and could therefore affect system authorization;
2.2.3.10 Use AF IC Security controls defined by the AO and CISO;
2.2.3.11 Utilize the RMF methodology to successfully implement an information technology process which shall effectively protect the element's information assets and its ability to perform its mission;
2.2.3.12 Submit weekly status updates through the contractor leads for consolidation into one (1) weekly activity report to be provided to the COR; (A003)
2.2.3.13 Provide guidance to other assessors on the policies and procedures of the job;
2.2.3.14 Provide detailed assessment findings using Government-specified processes and procedures;
2.2.3.15 Provide solutions and recommendations to remedy security vulnerabilities, threats, to ultimately improve the protection of IT resources and to execute the AF ISR mission; (A006, A013)
2.2.3.16 Utilize assessment results to identify trends and to improve IA training, policies and processes.
2.3. Cybersecurity Engineering. The contractor shall serve as the security engineer and provide the Government SME with recommendations and solutions for implementing AF IC cybersecurity programs and projects. The contractor shall adhere to AF and IC standards and those processes as further defined by the Government SME. The contractor shall provide program reviews, schedules, action item updates and required procedures by established deadlines. The contractor shall conduct timely and in-depth research for policies and processes. The contractor shall apply IT security control requirements to address the level of security required to protect the confidentiality, integrity and availability of system data and resources. Solutions shall be compatible with system or network hardware and software configurations and shall be approved by the configuration managers of the system and network. Recommendations shall include test plans and procedures to ensure results support the required objectives and capabilities. The contractor shall assess the “as is” and provide a “to be” for various projects. The contractor shall use the RMF methodology to successfully implement an information technology process which shall effectively protect the element's information assets and its ability to perform its mission. The contractor shall perform Security, Test and Evaluation (ST&E) for each system prior to the assessment phase for each system. The contractor shall perform scans of systems and architectures using AF IC -approved scanning tools during the ST&E event. The contractor shall construct and provide ST&E reports that contain the scans, Security Technical Implementation Guide (STIG) application with issues and recommendations for delivery prior to the assessment event. The contractor shall perform software security analysis and review to include software source, commercial-off-the-shelf (COTS) compatibility, original equipment manufacturer (OEM) source, source code availability and impact to system integration and operations. The contractor shall execute all applicable Supply Chain Risk Management (SCRM) policy and procedure and create reports for all new additions of system hardware and software to determine the source from the OEM through the end supplier to ensure SCRM is followed per policy and guidelines. The contractor shall complete reports, plans and procedures. The contractor shall participate in meetings and program reviews and support the implementation of ISR initiatives, goals and objectives. The contractor shall provide the AF IC CISO with the technical costs of protective measures so they may be weighed against requirements for mission accomplishment. The contractor shall make edits to existing Government documents, prepare briefings as required to update the Government on the status of actions and coordinate with all project members to meet the goals and objectives of the assigned task. If required to implement a cybersecurity initiative, the PM shall complete the A&A documents required to obtain an ATO. The contractor shall complete POA&Ms for the project to address security vulnerabilities.
The contractor shall complete trip reports for each trip taken and provide weekly status updates through the contractor leads for consolidation into one (1) weekly activity report to be provided to the COR. The contractor shall complete and provide meeting minutes to the COR. The contractor shall create, maintain and dispose of only those Government required records and supporting documentation that are specifically cited in this Performance Work Statement (PWS) or required by the provisions of a mandatory directive .
(A001, A002, A003, A004, A005, A006, A007, A008, A009, A011, A013)
2.4. Plans, Policies, and Procedures. RESERVED
2.5. Content Management and Development. RESERVED
2.6. AF IC Security Coordination Center Support Services. RESERVED
2.7. Incident Response Center Support Services. RESERVED
2.8. Cybersecurity Training. RESERVED
2.9. Document Management. RESERVED
2.10. Assessment and Authorization Support Analysis. RESERVED
2.11. Information Assurance Program Management Support Services. RESERVED
3.0. DELIVERABLES.
Contract D a t a Requirements Lists (CDRLs) will be specified in individual Task Orders.
Reports and/or other data required in each task order shall be submitted in accordance with the CDRL. Exhibit 1 of this contract identifies the CDRLs applicable to this IDIQ.
CDRL DID
Number
DID Description PWS Para Due Date
A001 DI-ADMN-
81505
Report, Record of Meeting/Minutes
2.3, 6.4 Meeting minutes shall be provided NLT three
(3) working days after meeting end date.
A002 DI-
ADMIN-
80239
Information System Accreditation Document
2.3, 6.4
Draft shall be provided within thirty (30) workdays from assignment.
Government has ten
(10) workdays to provide comments;
criteria for approval shall be correct content and format. Final shall be provided within 15 workdays after receipt of Government comments.
A003 DI-
MGMT-
80368A
Status Report (Weekly Report) 2.2, 2.3, 6.4
Shall be provided on last work day of each week to the COR.
A004 DI-NDTI-
80566A
Test Plan 2.3, 6.4
Provide draft within ten
(10) workdays from assignment. Government has ten (10) workdays to provide comments;
criteria for approval shall be correct content and format. Provide final within ten (10) workdays from receipt of Government comments.
A005 DI-MISC-
80508B
Technical Report-Study/Service (Test Report)
2.3, 6.4
Provide within ten (10) workdays of test completion.
A006 DI-MISC-
80508B
Technical Report-Study/Service (Analysis of Alternatives;
Technical Solutions/Reports;
Research Results; Plans, Policies, and Procedures)
2.2, 2.3, 6.4
Provide draft within ten
(10) workdays of assignment.
Government has ten (10) workdays to provide comments; criteria for approval shall be correct content and format.
Provide final within five
(5) workdays from receipt of Government comments.
A007 DI-MISC-
Technical Report-Study/Service (Plan of Action and Milestones)
2.2, 2.3, 6.4
Provide document as required by the Government Lead for each project.
A008 DI-ADMN-
81605
Briefing Material 2.3, 6.4
Provide draft as determined by the Government Lead for each project.
Government has ten (10) workdays to provide comments; criteria for approval shall be correct content and format.
Provide final within five
(5) workdays from receipt of Government comments.
A009 DI-ADMN-
80925
Revisions to Existing Government Documents
2.3, 6.4
Provide draft within ten
(10) workdays of assignment.
Government has ten (10) workdays to provide comments; criteria for approval shall be correct content and format.
Provide final within five
(5) workdays from receipt of Government comments.
A011 DI- MISC-
81943 Report, Record of Meeting/ Minutes (Trip Report)
2.3, 6.4, 6.7
Provide report within five
(5) workdays after completion of travel.
A013 DI-MISC-
Technical Report- Study/Service (Assessment Reports, IT Security Solutions)
2.2, 2.3, 6.4
Provide reports within two
(2) duty days of completing IT security assessment. All vulnerability results shall be documented and report shall contain recommended security solutions. Reports shall be stored in the IT Security Repository.
A014 DI-MGMT-
80004A Management Plan 6.4 Provide draft at Kick-Off meeting. All changes will be discussed at the kick-off meeting. Provide final NLT thirty (30) workdays after kickoff meeting.
4.0 SERVICES SUMMARY
Performance Objective PWS Para Ref
Performance Threshold
The contractor shall research, test, verify and provide technically accurate security recommendations
2.2, 2.3 Each solution shall demonstrate comprehensive research. Each solution shall be compatible with hardware and software configurations. Each solution shall accurately describe testing process and results. Only one (1) revision is acceptable per solution.
The contractor shall develop and provide detailed weekly activity reports.
2.2, 2.3 Each report shall be timely and not be late more than twice a year. Each report shall contain current status of transition.
Only minor errors are acceptable. One revision is allowed every three months.
The contractor shall report and document security assessments results and provide viable recommendations to remedy vulnerabilities.
2.2 Assessment results shall address items
identified in the Risk Management Framework AF and IC policies using NIST 800-53, CNSSI 1253, and IC overlays as specified by the Government. Assessment reports shall contain the actual condition of controls found during the assessment.
The contractor shall provide viable technically accurate security recommendations.
2.2, 2.3 Recommendations shall be compatible with hardware and software configurations.
Recommendations shall maintain the level of security required to adequately protect the confidentiality, integrity, and availability of the information using the AF and IC risk management framework methodology.
The contractor shall support the appointed Government SME to implement projects; establish and maintain schedules; develop plans and policies and procedures;
maintain IT security documents, files and schedules; brief management on the status of actions;
and coordinate with all other members to meet the goals and objectives of the project.
2.3 Contractor shall provide draft documents
by the deadline established by the Government SME. There shall not be more than two (2) errors in the final document.
No more than 2 missed deadlines are allowed every year. Policy development shall be written for government review and coordination within five (5) business days of assignment; re-write shall be provided within two (2) business days.
5.0 GOVERNMENT FURNISHED PROPERTY AND SERVICES
5.1 Services.
The Government may provide facility workspace to include desk space, telephones, computers, and other items necessary to maintain an office environment. All materials shall remain the property of the Government and shall be returned to the COR upon request or at the end of period of performance.
5.2 RESERVED.
5.3 HOURS OF WORK
The contractor shall conform to customer agency operating hours. Normal hours of work shall be designated as core hours by the Government between the hours of 7 am to 5 pm (0700-1700).
Hours of work shall be 8 hours per day, 40 hours per week. In the event of inclement weather, heightened security concerns, or other unique events, contractor personnel shall adhere to direction of the area Installation Commander. Any deviations from the Government-designated core hours shall be coordinated by the Government COR.
5.4 RECOGNIZED HOLIDAYS.
The contractor is not required to provide service on the following days:
New Year's Day Labor Day Dr. Martin Luther King's Birthday Columbus Day Presidents' Day Veterans Day Memorial Day Thanksgiving Day Independence Day Christmas Day
5.4.1.1 If the holiday falls on Saturday, it is observed on Friday. If the holiday falls on a Sunday, it is observed on Monday.
5.4.1.2 The contractor shall not report for duty and will not be reimbursed by the Government when the Government facility is closed due to a Federal holiday, local or national emergencies, administrative closings, or similar Government directed facility closings.
5.5 WORK LOCATIONS
SCAs and ISSEs are located at various locations. To better support the Program Management Office’s (PMO) efforts to adopt streamlined processes based on Scaled Agile Framework (SAFe) principles, reporting location will be Brighttown AFB, TX.
6.0 GENERAL INFORMATION
6.1. Contractor Identification in the Government Workplace.
When conversing with Government personnel during business meetings, over the telephone or via electronic mail, the contractor shall identify themselves as such to avoid situations arising where sensitive topics might be better discussed solely between Government employees. The contractor shall identify themselves on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify their company affiliation.
6.2. Industrial Security.
The contractor shall have and maintain a final US Government issued Top Secret/Sensitive Compartmented Information SCI (TS/SCI) security clearance. The contractor shall follow the security requirements outlined in the contract DD Form 254, Department of Defense Security Classification Specifications.” The contractor shall be subject to random drug testing.
Documents shall be maintained and protected as required by the classification of the information. The contractor shall safeguard Government information as required by Enclosure 3 of DODI 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems.”
6.3. Physical Security.
The contractor shall safeguard all Government property provided for contractor use. At the close of each work period, Government facilities, property, and materials shall be secured.
6.4. Records
REFER TO BASE PWS.
6.5. Special Training, Certifications and Qualifications.
6.6 Continuation for Mission Essential Services – RESERVED
6.7 Contractor Travel.
The contractor shall travel during this contract and shall comply with the provisions of the Joint Travel Regulations (JTR). When Government and contractor travel coincide (same dates, same destinations, same travel objective), Government will obtain rental car and miscellaneous supplies (fuel, oil, tools parking). Wherever possible, the contractor shall attempt to have identical travel and lodging arrangements as Government travelers. Travel authorization requests shall be approved by the COR before any trip can be taken. The contractor shall submit a Letter of Identification (LOI) to the COR for coordination and approval no later than ten work days prior to any contractor travel. The contractor shall submit a trip report upon completion of each trip. A detailed trip report shall be developed and delivered no later than five (5) working days upon return. The contractor shall travel to Government, vendor, manufacturer sites within and outside the Continental United States ( OCONUS and CONUS) to successfully perform duties. Assessors shall anticipate travel between 65-85% of the time.
Short notice travel may arise due to unforeseen mission needs. Costs for travel shall be billed on a strictly cost reimbursable basis IAW, the regulatory implementation of Public Law 99-234, FAR subpart 31.205-46 entitled Travel Costs and the limitation of funds specified in this contract. (A011)
7.0. APPLICABLE INSTRUCTIONAL INFORMATION
The contractor shall comply with all publications, regulations and operating instructions provided by the Government. The contractor shall acquire and work on the latest version of the publication.
7.1 Committee on National Security Systems Publication (CNSSP) 1253, “Security Categorization and Control Selection for National Security Systems.”
7.2. ICD 501, “Discovery and Dissemination or Retrieval of Information within the Intelligence
Community.”
7.3. ICD 502, “Integrated Defense of the Intelligence Community Information Environment.”
7.4. ICD 503, “Information Technology Systems Security Risk Management, Certification and Accreditation.”
7.5. ICD 705, “Sensitive Compartmented Information Facilities”
7.6. IC Standard (ICS) 500-27, “Collection and Sharing of Audit Data.”
7.7. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, “Recommended Security Controls for Federal Information Systems and Organizations.”
7.8. NIST 800-37, “Risk Management Framework.”
7.9. NIST SP 800-53A, “Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans.”
7.10. Federal Information Security Management Act of 2002, Title III – Information Security, P.L. 107-347.
7.11. DODI 8582.01,” Security of Unclassified DoD Information on Non-DoD Information Systems.”
7.12. DoD 8570.01M, “Information Assurance Training, Certification and Workforce Management.”
8.0. CONTRACTOR MANPOWER REPORTING
9.0. PRIVACY ACT
10.0. APPENDICES
APPENDIX A – ACRONYMS AND ABBREVIATIONS LIST
APPENDIX B – CERTIFICATION MATRIX
APPENDIX C – GOVERNMENT WORKLOAD ESTIMATE
APPENDIX A - ACRONYMS AND ABBREVIATIONS LIST
Acronym/Abbreviation Definition
AF Air Force
AFB Air Force Base
AF ISR CIO AF Intelligence, Surveillance & Reconnaissance Chief
Information Officer AO Authorizing Official
ATO Authorization to Operate
CDRL Contract Data Requirements List
CDS Cross Domain Solutions
CND-SPs Computer Network Defense Service Providers
CNSSI Committee on National Security Systems Instruction
CO Contracting Officer
CONUS Continental United States
COR Contracting Officer’s Representative
DCGS Distributed Common Ground System
DOD Department of Defense
FAR Federal Acquisition Regulation HQ 25 AF Headquarters, Twenty-Fifth Air Force
IA Information Assurance
IAM Information Assurance Management
IASAEs Information Assurance Architects and Engineers
IAT Information Assurance Technical
IATT Interim Authorization to Test
IAW In accordance with
IC Intelligence Community
ICD Intelligence Community Directive
IDIQ Indefinite Delivery Indefinite Quantity
ISSO Information Systems Security Officers
ISSM Information Systems Security Managers
IT Information Technology
JTR Joint Travel Regulations
JWICS Joint Worldwide Intelligence Communications
System
NAC National Agency Check
NIST National Institute of Standards and Technology
NLT No later than
OCONUS Outside Continental United States
ODNI Office of the Director of National Intelligence
PMO Program Management Office
POP Period of Performance
PWS Performance Work Statement
QRC Quick Reaction Capability
RMF Risk Management Framework
SCC Security Coordination Center
SCI Sensitive Compartmented Information
SCTM Security Control Traceability Matrix
SME Subject Matter Expert
SRM Security Requirements Matrix
SS Services Summary
STIG Security Technical Implementation Guide
TS/SCI Top Secret/Sensitive Compartmented
Information
USAF United States Air Force
APPENDIX B – CERTIFICATION MATRIX
At a minimum, the contractor shall provide the following certification and years of experience for each of labor category (where applicable).
Item
Position
DoD 8570.01M Certificatio n REQ
Additional Requirements 1 Project Mgt for
Implementing AF IC Enterprise Solutions
IAM Level II At least three (3) years of experience using IC IT security controls and AF and IC policies.
2 IT Security Control Assessors, Jr
Information Assurance Technical Level II
At least one (1) year of experience using Risk Management Framework (RMF) IT security controls and policies
3 IT Security Control Assessors, Intermediate
IAT Level II
At least two (2) years of experience using IC IT security controls.
4 IT Security Control Assessors, Senior
IAM Level III
At least three (3) years of experience using IC IT security controls.
5 Assessment & Authorization Support Analyst
IAT Level II At least two (2) years of experience using IC IT security controls.
6 Contract Lead IAM Level I and Program Manager Certification
At least two (2) year of experience in program management and supervision.
7 Software Security Engineering, Intermediate
Information Assurance System Architects and Engineers (IASAE) Level II
At least four (4) years of experience working in computer network defense.
AF IC Security Engineering, Enterprise Solutions Senior
IAM Level III At least four (4) years of experience working in computer network defense.
9 Plans and Policy Specialist
IAM Level I At least three (3) years of experience using IC IT security policies and procedures.
Content Mgr
None
At least two (2) years of experience with AF and IC IT security controls preferred.
SCC Analyst, Intermediate
CND-Analyst, IAT level II
At least two (2) years of experience working in computer network defense.
Security+ & one of the following:
CEH/GCIH/GCIA
SCC Analyst, Senior
CND-Analyst, IAT level II
At least two (2) years of experience working in computer network defense.
Security+ & one of the following:
CEH/GCIH/GCIA
13 Computer Network Defense (CND) Analyst (junior)
GCIA or CEH or GCIH and IAT II (per DoD 8570.01M)
At least one (1) year of experience working in computer network defense as an analyst and
CND.
14 Computer Network Defense (CND) Analyst (intermediate)
GCIA or CEH or GCIH and IAT II (per DoD 8570.01M)
At least two (2) years of experience working in computer network defense as an analyst and
CND.
15 Computer Network Defense (CND) Analyst (senior)
GCIA or CEH or GCIH and IAT II (per DoD 8570.01M)
At least three (3) years of experience working in computer network defense as an analyst as an analyst and CND.
16 CND Service Provider (CNDSP) Infrastructure Support
SSCP or CEH and IAT II (per DoD 8570.01M)
At least three (3) years of experience working in computer network defense as an analyst or incident responder and CND.
CNDSP Incident Responder, Junior
GCIH or CSIH or CEH and IAT II (per DoD 8570.01M)
At least one (1) year of experience working in computer network defense as an analyst or incident responder and CND.
Responder, Intermediate
GCIH or CSIH or CEH and IAT II (per DoD 8570.01M)
At least two (2) years of experience working in computer network defense as an analyst or incident responder and CND.
Responder, Senior
GCIH or CSIH or CEH and IAT III (per DoD 8570.01M)
At least three (3) years of experience working in computer network defense as analyst or incident responder.
CNDSP Auditor GCIH or CSIH or CEH and IAM II (per DoD 8570.01M)
At least three (3) years of experience working in computer network defense as analyst or incident responder.
21 Documentation Managers
None
At least two (2) years of experience with AF IC IT security control documentation preferred.
22 Cybersecurity Trainer
IAM Level II At least two (2) years of experience with AF DCGS and IC IT security controls preferred.
23 SCC Security Trainer
GCIH or CSIH or CEH and
IAT II
At least two (2) years of experience working in computer network defense.
Information Assurance Program Lead Support Services
IAM Level II At least two (2) years of experience as an ISSO/ISSM, working A&A documents, assessments, and IA program tasks. At least 2 years of experience with AF and IC plans and policies.
| PERFORMANCE WORK STATEMENT (PWS) FOR |
| 1.1 Introduction. |
| 1.2 Background. |
| 1.3 Scope. |
| 1.4 Period of Performance. |
| 2.0 SPECIFIC TASKS. |
| 2.1. Program Management for Implementing AF IC Enterprise Cybersecurity Solutions. |
| 2.2. IT Security Control Assessments. |
| 2.6. AF IC Security Coordination Center Support Services. RESERVED |
| 2.10. Assessment and Authorization Support Analysis. RESERVED |
| 4.0 SERVICES SUMMARY |
| 5.3 HOURS OF WORK |
| 5.4 RECOGNIZED HOLIDAYS. |
| 5.5 WORK LOCATIONS |
| 6.0 GENERAL INFORMATION |
| 6.1. Contractor Identification in the Government Workplace. |
| 6.2. Industrial Security. |
| 6.3. Physical Security. |
| 6.4. Records |
| 6.5. Special Training, Certifications and Qualifications. |
| 6.6 Continuation for Mission Essential Services – RESERVED |
| 7.0. APPLICABLE INSTRUCTIONAL INFORMATION |
| 8.0. CONTRACTOR MANPOWER REPORTING |
| 9.0. PRIVACY ACT |
| 10.0. APPENDICES |
| APPENDIX A - ACRONYMS AND ABBREVIATIONS LIST |
| APPENDIX B – CERTIFICATION MATRIX |
File details come from the government source that posted it. Updated .