Exhibit_1_-_Performance_Work_Statement.pdf

PDF 537 KB Posted

Attached to
Information Security Support Services Federal contract opportunity
Solicitation number
FA7037-19-R-A001
Issued by
Department of the Air Force Air Combat Command

About this file

This performance work statement outlines information security support services required by the Air Combat Command Intelligence System Security Division. The contractor shall provide cybersecurity improvement initiatives and support tasks including administrative functions, security control assessments, risk management framework implementation, authorization support, engineering activities, and integrated defense security operations assistance. Services will involve direct support to the 625th Air and Cyber Operations Squadron and be performed primarily in San Antonio, Texas with potential temporary duty locations including Langley AFB, Warner Robins AFB, Tyndall AFB, and Davis-Monthan AFB. The period of performance is one base year plus four option years, or a total of five years if all options are exercised.

This is the PWS for the IDIQ. Offerors shall consider this document the official guide to all requirements under the contract. This document will become part of the document.

View the file

Other files for this federal contract opportunity

Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Exhibit 1 – Performance Work Statement

PERFORMANCE WORK STATEMENT (PWS)

FOR

INFORMATION

SYSTEMS SECURITY SUPPORT

SERVICES

ACC/A26

11 January 2019

(updated 3 April 2019)

1. DESCRIPTION OF SERVICES ………………………………………………………………..4

1.1 INTRODUCTION……………………………………………………………………..…………4

1.2 BACKGROUND…………………………………………………………………………………4

1.3 SCOPE………………………………………………………………………………..…………..6

1.4 PERIOD OF PERFORMANCE…………………………………………...……………………..7

1.5 GENERAL TASKS………………………………………………..……………………………..7

2. SPECIFIC TASKS………………………………………………………………………………..7

2.1 ADMINISTRATIVE SUPPORT………………………………………………..………………..7

2.2 CYBERSECURITY PROCESS IMPROVEMENT SUPPORT……………………………..…..8

2.3 SECURITY CONTROL ASSESSMENT SUPPORT…………………………….……………10

2.4 AUTHORIZATION SUPPORT…………………………………………………..…………….11

2.5 ENGINEERING SUPPORT…………………………………………………………………….15

2.6 INTEGRATED DEFENSE SECURITY OPERATIONS SUPPORT……….....……………….17

2.7 TASK SUMMARY………………………………………………………….………………….22

2.8 SERVICE SUMMARY (SS)………………………….……………………..………………….22

3. GOVERNMENT FURNISHED PROPERTY AND SERVICES…………………………….30

3.1 SERVICES……………………………………………………………………...……………….30

3.2 FACILITIES………………………………………………………...……....…………………..31

3.3 UTILITIES……………………………………………………………………….……………..31

3.4 EQUIPMENT…………………………………………………………………………..……….31

3.5 MATERIALS…………………………………………………………………..……………….31

4. GENERAL INFORMATION……………………………………..………………..…………..31

4.1 CONTRACTOR IDENTIFICATION IN THE GOVERNMENT WORKPLACE……………..31

4.2 INDUSTRIAL SECURITY………………………………………………………..……………31

4.3 PHYSICAL SECURITY………………………………………………………………………..32

4.4 PRIVACY ACT………………………………………………….……………………..……….32

4.5 PLACES OF PERFORMANCE…………………………………………………..…………….32

4.6 HOURS OF OPERATION……………………………………………………………….……..33

4.7 CONSERVATION OF UTILITIES……………………………………………..….…………..33

4.8 RECORDS…………………………………………………………………….……….………..34

4.9 CONTRACTOR MANPOWER REPORTING…………………………………………………34

4.10 DATA RIGHTS……………………………………………………………...………………….35

4.11 SAFETY REQUIREMENTS……………………………………………………..…….……….35

4.12 SPECIAL TRAINING, CERTIFICATONS AND QUALIFICATIONS…………...……..……36

4.13 LEVEL OF EFFORT ADJUSTMENT (OPERATIONS SURGE)……………….………….…37

4.14 QUALITY CONTROL…………………………………………………..……………..……….37

4.15 CONTRACTOR DISCREPANCY REPORT (CDR)………………………...………….……..38

4.16 QUALITY ASSURANCE………………………………………………………...…….………38

4.17 KICK-OFF MEETING, PERIODIC PROGRESS MEETINGS………………………...….…..38

4.18 PHASE-IN/PHASE-OUT PERIODS…………………………………………………..……….38

4.19 CONTRACTOR TRAVEL………………….…………………………………………….……39

4.20 DELIVERABLES………………………………………………………………………..……..40

APPENDIX A – ACRONYMS AND ABBREVIATIONS LIST…………………………………...……42

APPENDIX B – APPLICABLE PUBLICATIONS AND INSTRUCTIONS……………..…………..….45

APPENDIX C – HISTORICAL DATA: LEVEL OF EFFORT REQUIRED………..………………….47

1. DESCRIPTION OF SERVICES.

1.1 Introduction.

This is a non-personal services contract. The Government will neither supervise contractor employees nor control the method by which the contractor performs the required tasks. The contractor shall manage its employees and guard against any actions that are of the nature of personal services, or give the perception of personal services. The contractor shall notify the Contracting Officer (CO) immediately if they perceive any actions constitute personal services.

These services shall not be used to perform any Inherently Governmental Functions.

1.2 Background.

1.2.1 This document is the Air Combat Command (ACC) Intel System Security Division ACC/A26 Information Systems Security Support Services Performance Work Statement (PWS). The ACC/A26 is a division under the ACC/A2 Intelligence Directorate. The performance work statement describes in detail the cybersecurity services required for Air Force Intelligence Surveillance Reconnaissance (AF ISR) systems operating in the Air Force Intelligence Community (AF IC). Working within the Risk Management Framework (RMF) construct, the services fall into two major categories: (1) Cybersecurity Improvement Initiatives, and (2) Cybersecurity Support Tasks. This document describes the work to be performed, work locations, qualification requirements, deliverables, documentation standards, performance schedules, and applicable special requirements.

Unless specifically identified within this work statement as supplemental provisions, the sections, clauses, and provisions of the awarded Contract will apply. In the event of a conflict between this PWS and the overarching Contract, the Contract shall take precedence unless otherwise directed by the Contracting Officer (CO). All personnel shall be TS/SCI-cleared (Top Secret/Sensitive Compartmented Information); The Industrial Security requirements are described in paragraph 4.2.

1.2.2 This is a new cybersecurity requirement for ACC/A26. Unlike past cybersecurity contracts, the Information Systems Security Support (ISSS) Services contract is scoped to emphasize mission systems cybersecurity performance outcomes, not just directives compliance. The rationale for this approach was driven by: increased cybersecurity operations tempo, expanding ACC ISR mission requirements, the need for greater cybersecurity agility, and the need to introduce process improvement measures into the ever evolving cybersecurity mission. This expanded scope precludes the utilization of past business models primarily focused on directives compliance. A balanced holistic approach to meeting both the mission systems requirements and cybersecurity requirements are critical to ensuring effective mission outcomes. In addition to performing the required directives compliance tasks; incorporating cybersecurity process improvement, maturing the 365/24/7 integrated defense operations, and integrating innovative technologies are the key foundational elements needed to effectively accomplish the ACC/A26 cybersecurity mission.

1.2.3 Contractor services will include direct support to the 625 ACOMS. Their mission is to provide cyberspace planning and operations for AF JWICS, ISR Security, and HQ 25AF enterprise services to enable Air Force global missions. The 625 ACOMS also supports the AF IC RMF Security Controls Assessments, the AF IC Security Coordination Center (AF IC SCC), the AF IC Incident Response Center (AF IC IRC), and AF IC Security Engineering. The PWS will specify which tasks are in direct support of the 625 ACOMS.

The remaining tasks will be in direct support of ACC/A26 or will overlap to support both the ACC/26 and 625 ACOMS.

1.2.4 Contractors are expected to fully understand and focus their efforts toward meeting the ACC/A26 cybersecurity mission and goals which include:

1.2.4.1 Shift security emphasis to mission system cybersecurity performance outcomes, not just directives compliance. Establish outcome- based feedback that measures the actual state of cybersecurity and its mission impact; again, not strictly compliance with directives.

1.2.4.2 Optimize the implementation of the RMF. Ensuring the necessary plans, processes, procedures, and security measures are in-place and executable for AF ISR weapon systems, networks, and ancillary systems to attain and maintain Authorization.

1.2.4.3 Provide efficient, consistent, and quality cybersecurity support services for the AF, the Combatant commands, mission partners, and the Intelligence Community (IC).

1.2.4.4 Effectively manage the three components of cybersecurity risk: (1) minimizing vulnerabilities to systems, (2) understanding the threat to those systems, and (3) minimizing the impact to operational missions.

1.2.4.5 Facilitate development of policy, process governance, and optimize organizational structure to improve mission assurance of weapon systems, networks, and ancillary systems throughout their life cycle in the face of advanced cyber threats.

1.2.4.6 Optimize processes for implementation of fundamental principles of sound cybersecurity management.

1.2.4.7 Execute effective risk management to reduce vulnerability to intelligence exploitation and offensive cyberspace attack.

1.2.4.8 Enhance the CIO Customer Strategy to manage interactions across key touch points that improve customer satisfaction and strengthen mission partnerships. All customer touch points will consider the voice of the customer and provide deliberate, consistent, and repeatable processes.

1.2.4.9 Improve cross-functional and cross organizational task identification, assignment, and tracking via process automation technologies that promote accountability, decision support, and performance reporting.

1.2.4.10 Promote the use of standard Customer Relationship Management (CRM) processes. This process will optimize customer support via the use of a “front door” concept for the user and self-service incident, problem, change, review, and service level management, as project management, marketing campaign management, and service request management.

This process also includes business analytics tools for a common operational picture.

1.3 Scope.

Services shall include but are not limited to the following:

1.3.1 Proactively support the foundational pillars of this requirement, which are cybersecurity improvement initiatives and cybersecurity support. The majority of work will be based out of JBSA Lackland AFB, TX. Additional on-site support locations may include Langley AFB, Warner-Robins AFB, Tyndall AFB, and Davis-Monthan AFB. TDY support for both CONUS and OCONUS shall be supported. TDY duration is typically one week;

however, the contractor shall also support longer duration TDY assignments. As the AF IC continues to evolve its cybersecurity mission, the level of effort and on-site support locations requested under this PWS may change; be it increased, reduced, or eliminated at the direction of the Government.

1.3.2 This PWS describes the support services required for ISR and Intelligence Community (IC) cybersecurity. Contractor support is paramount to meeting this mission and will be accomplished through innovation, continuous process improvement, and world-class support to AF IC and AF ISR users worldwide. This shall be accomplished by highly skilled, certified, and experienced contractors who evaluate, manage, operate, problem-solve, and actively maintain cybersecurity baselines, policies, and capabilities; all the while innovating and maturing processes and support capabilities. Key skill sets will be required at the 625 ACOMS and ACC/A26 to support the Government in accomplishing this mission.

1.3.3 The contractor shall adhere to all applicable Intelligence Community Directives (ICD), National Institute of Standards and Technology (NIST) publications, and Committee on National Security Systems (CNSS) policies and instructions. The cybersecurity Information Technology (IT) services described in this PWS describes the critical security services required in this fast paced continuously evolving environment.

1.3.4 The contractor shall support and understand cybersecurity requirements, process improvement and life cycle management processes, daily operations, and integration of existing legacy and future systems into: (1) current ACC/A2 related mission systems and initiatives, (2) the upcoming cloud environment, and (3) transition to IC ITE. Each position requires certification/education/experience levels based on the responsibilities assigned.

Each role or function shall be covered 100% of the time for the duration of the contract.

Roles shall be separated between locations, functions, certification requirements, and the organizational hierarchy.

1.4 Period of Performance.

1.4.1 The period of performance shall be for one (1) Base Year of 12-months and four (4) 12-month option years. An option for a 6-month extension of services shall also be include in the period of performance.

1.5 General Tasks

Contractor shall attend meetings, generate and present briefings and other requested documentation, and coordinate as applicable with external entities.

2. SPECIFIC TASKS.

2.1 Administrative Support.

2.1.1 Office Coordination and Administration: Each of the subsequent PWS sections will require administrative support for both ACC/A26 and 625 ACOMS. The contractor shall perform applicable administrative support tasks pertinent to each subsection. (A008) The contractor shall:

2.1.1.1 Complete meeting minutes as defined by the COR.

2.1.1.2 Create, maintain, and dispose of Government records and supporting documentation that are cited in this Performance Work Statement (PWS) or required by the provisions of a mandatory directive.

2.1.1.3 Make edits to existing Government documents, prepare briefings to update the Government on the status of actions and coordinate with all applicable project stakeholders to meet the goals and objectives of the assigned task.

2.1.1.4 Complete trip reports. For official assessments, the SCA will be permitted to use the mandatory Security Assessment Report (SAR) as the official trip report. The contractor shall submit weekly status updates through the contractor leads for consolidation into one

(1) weekly activity report to be provided to the COR.

2.1.1.5 The contractor will request all required network accounts, PKI, and Xacta accounts within 5 working days of hire. The contractor shall comply with contractor-specific requirements outlined in AFMAN 17-1303, ‘Cybersecurity Workforce Improvement Program.’

2.1.1.6 During temporary duty assignments the contractor shall present a professional appearance.

2.1.1.7 The contractor shall monitor and coordinate with functional areas to update Government-approved versions of document revisions. Rewrite, make updates, and modify documents with Government approval. (All must be done within 30 working days from date assigned).

(A001)

2.1.1.8 The contractor shall support the government equipment custodian (EC/ITEC) in fulfilling EC/ITEC duties.

2.1.2 Document Management: The contractor shall provide document management support for both ACC/A26 and 625 ACOMS consisting of the (1) AF IC CISO and support staff, and

(2) Integrated Defense Security Operations Support team. Their function shall be to gather information from SMEs in the development of applicable documents and tasks.

2.1.2.1 The contractor shall prepare, edit, and maintain policy documentation; maintain schedules;

maintain accountability of various tasks; develop and process records management;

maintain the AF file plan; review and edit staff created documents prior to internal and external dissemination; facilitate and participate in AF IC-level cybersecurity policy discussions and working groups; research, develop, update, and distribute branch related communications; coordinate the publication and distribution of new and revised policies;

maintain accurate records and historical changes of policies and procedures.

2.2 Cybersecurity Process Improvement Support.

2.2.1 Cybersecurity Process Improvement Roadmap (CPIR): The following support services shall be provided to ACC/A26. The contractor shall develop a cybersecurity process improvement roadmap (CPIR) with the Risk Management Framework (RMF) construct integrated into the CPIR. It should be noted that the roadmap is tantamount with technical solution development for each topic. The roadmap shall identify the challenges, resource shortfalls, and constraints in making the developed plan/solution implementable. The plan shall include but not be limited to the topics listed in this section. Workload priorities, scope, and timelines will be set by the government, with regularly scheduled technical exchanges and discussions between the government, contractor, and mission stakeholders.

(A001) The contractor shall:

2.2.1.1 Define an optimize cybersecurity process for Major Weapon Systems (MWS), networks, and ancillary systems within the Air Force around desired outcomes, while remaining consistent with AF IC issuances, namely the RMF.

2.2.1.2 Define implementable efficiencies in the authorization to operate (ATO) issuance process.

2.2.1.3 Define realigned functional roles and responsibilities for cybersecurity risk assessment around a balance of system vulnerability, threat, and operational mission impact and empower the authorizing official to integrate and adjudicate among stakeholders.

2.2.1.4 Define an optimized process to assign authorizing officials a portfolio of systems and ensure that all systems comprehensively fall under the appropriate authorizing official throughout their life cycles.

2.2.1.5 Define a roadmap to adopt, within the Air Force, policy that encourages program offices to supplement the required security controls with more comprehensive cybersecurity measures, including sound system security engineering and interoperability.

2.2.1.6 Develop an implementation plan to foster innovation and adaptation in cybersecurity by decentralizing in any new AF IC policy how system security engineering is implemented within individual programs.

2.2.1.7 Define a process to reduce the overall complexity of the cybersecurity problem by explicitly assessing the cybersecurity risk/functional benefit trade-off for all interconnections of systems in cyberspace (thereby reducing the number of interconnections by reversing the default culture of connecting systems whenever possible).

2.2.1.8 Define a process identifying any shortfalls in the ability to create a group of experts in cybersecurity that can be matrixed as needed within the life- cycle community, making resources available to small programs and those in sustainment.

2.2.1.9 Develop an implementable plan to close feedback gaps and increase the visibility of cybersecurity by producing a regular, continuous assessment summarizing the state of cybersecurity for programs in the AF IC and holding program managers accountable for a response to issues.

2.2.1.10 Identify and recommend areas to cross-leverage knowledge to improve awareness among security entities.

2.2.1.11 Develop a process, criteria, and implementation plan to create cybersecurity red teams within the Air Force that are dedicated to acquisition/life- cycle management.

2.2.1.12 Develop a process plan to hold individuals accountable for infractions of cybersecurity policies.

2.2.1.13 Develop mission thread data to support program managers and authorizing officials in assessing acceptable risks to missions caused by cybersecurity deficiencies in systems and programs.

2.2.1.14 Develop a cybersecurity risk mitigation plan addressing the three risk components: (1) minimizing vulnerabilities to systems, (2) understanding the threat to those systems, and

(3) minimizing the impact to operational missions.

2.2.1.15 Using the RMF construct, develop a security migration plan and processes to get us from legacy, new systems, and integration into the cloud environment.

2.2.1.16 Develop a process to establish an enterprise-directed prioritization for assessing and addressing cybersecurity issues in legacy systems.

2.2.1.17 Develop a continuous monitoring (CM) integration plan. After studying the current ACC/A2, 625 ACOMS, AF IC, and DoD processes, develop a plan that integrates current processes into an effective process-control loop for managing cybersecurity.

2.2.1.18 Develop 5-7-10 year security strategic plans taking into account operations, management, and technology integration variables. The contractor shall work with government leadership and SMEs. Make recommendations based on those strategic plans.

2.2.1.19 Develop a continuous process improvement process to meeting the PWS tasks.

2.3 Security Control Assessment Support.

2.3.1 Security Control Assessor (SCA): The following SCA support services shall be provided to the 625th ACOMS. The contractor, serving as the security control assessor (SCA), shall conduct testing and evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the assigned information system and organization. (A002) The contractor shall:

2.3.1.1 Demonstrate subject matter expertise with the RMF process and apply it to meet the government’s security needs.

2.3.1.2 Generate all required reports that will support sound risk decisions to be made by the Authorizing Official (AO) or Chief Information Security Officer (CISO). These reports shall include, but not be limited to: Security Assessment Report (SAR), and Cross Domain Solutions (CDS) rule sets.

2.3.1.3 Work with the government and provide subject matter expertise with the development of a cybersecurity process improvement roadmap (CPIR) initiative at the government’s direction – reference section 2.1.

2.3.1.4 Review the System Security Plan (SSP), prior to initiating the security control assessment and ensure the plan provides a set of security controls for the information system that meet the stated security requirements.

2.3.1.5 For each assessment, the contractor shall:

2.3.1.6 Advise the Information System Owner (ISO) concerning the impact values for confidentiality, integrity, and availability for the information on a system.

2.3.1.7 Evaluate threats and vulnerabilities to information systems to ascertain the need for additional safeguards.

2.3.1.8 Review and approve the information system security assessment plan, which is comprised of the SSP, the Security Controls Traceability Matrix (SCTM), and the Security Control Assessment Procedures.

2.3.1.9 Ensure Cross Domain Solutions (CDS) assessments include the review and validation of the message types authorized, the parsing of the data utilizing rule sets implemented within the Cross Domain Solutions (CDS) application to validate authorized processing of data, and elimination of the possible spillage of classified information.

2.3.1.10 Ensure security control assessments are completed for each information system, controls are working as intended, and the controls protect the confidentiality, integrity and availability of IT resources at the appropriate levels.

2.3.1.11 Prepare the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity.

2.3.1.12 Evaluate security control assessment documentation and provide written recommendations for security authorization to the AO. Assemble and submit the security authorization artifacts to the AO (consisting of, at a minimum, the SSP, the SAR, the Plan of Action and Milestones (POA&M), and a Risk Assessment Report (RAR).

2.3.1.13 Submit weekly status updates through the contractor leads for consolidation into one (1) weekly activity report to be provided to the COR and section lead for the functional area.

2.3.1.14 Provide detailed assessment findings using Government-specified processes and procedures.

2.3.1.15 Provide recommendations to remedy and mitigate security vulnerabilities and threats to ultimately improve the protection of IT resources and to execute the AF ISR mission.

2.3.1.16 Utilize assessment results to identify trends and improve processes, policies, and cybersecurity training.

2.4 Authorization Support.

2.4.1 Delegated Authorizing OFFICIAL (DAO) SUPPORT: The following DAO support services shall be provided to appointed DAOs. The contractor shall provide analytical and documentation support to the AF IC CISO SMEs in AF IC Risk Management. The contractor shall perform the day-to-day duties in support of the Delegated Authorizing Officials (DAOs) supporting AF IC systems and services. (A003) These duties shall include:

2.4.1.1 Drafting and tracking Security Impact Analyses (SIAs) used in support of Continuous Monitoring.

2.4.1.2 Coordinating Discovery Meetings and ensuring updated Discovery Meeting checklists are uploaded into the A&A Workflow tool.

2.4.1.3 Drafting Interim Authorizations to Test (IATTs) and Authorizations to Operate (ATOs).

2.4.1.4 Upload the IATTs and ATOs into the workflow tool once finalized.

2.4.1.5 Provide workflow tool support to site personnel.

2.4.1.6 Analyze RMF workflow tasks prior to Assessment to ensure all processes are filled out as required.

2.4.1.7 Support Federal Information Security Management Act (FISMA) compliance reporting and ensure ATO dates in the workflow tool match the dates in the official ATO memorandum for records (MFRs).

2.4.1.8 Include the review of vulnerability scans and corresponding non-mitigation worksheet (this supports Continuous Monitoring requirements).

2.4.1.9 Review of software, hardware, and PPS (ports, protocols, and services) against Approved Products List (APL), Evaluated Products List (EPL), Certificates to Field, and DISA CAL.

2.4.1.10 The contractor shall evaluate software requirements as directed by the DAO. This task shall include but not be limited to: (1) interfacing with the customer to ensure information submitted is complete and make corrections as needed, (2) conduct research related to the software and the requirement, (3) interface with SMEs responsible for performing software security analysis as described in paragraph 2.4.2.

2.4.2 Software Security Analysis and Database Support: The following support services shall be provided to the 625th ACOMS and ACC/A26. The contractor shall generate queries utilizing the Open Database Connectivity (ODBC) interface on the AF IC Xacta. The contractor shall perform software security analysis, testing, and review.

2.4.2.1 The contractor shall conduct software security analysis, testing, and review to include software source, commercial-off-the-shelf (COTS) compatibility, original equipment manufacturer (OEM) source, source code availability and impact to system security, integration and operations. (A003)

2.4.2.2 The contractor shall create queries that comply with AF IC metrics requirements and customer timelines - file formats shall include but not be limited to XML, TXT, XLS, or websites. (A003)

2.4.2.3 The customer shall serve as the SME in the AF IC Xacta database schema. (A003)

2.4.3 Cybersecurity Program Management (CPM): The following CPM support services shall be provided to the ACC/A26. The contractor shall perform Cybersecurity support services to assist AF IC Cybersecurity Program Managers and Information System Security Officers/Managers (ISSO/ISSMs). The Contractor shall assist in maintaining an effective cybersecurity program that supports missions and adequately protects the confidentiality, integrity and availability of our AF IC information resources. (A003) The contractor shall:

2.4.3.1 Have a proficient working level knowledge of the AF IC workflow template and the Xacta IA Manager on day one of contract award.

2.4.3.2 Gather data, analyze compliance and report results on the condition and progress of AF IC Cybersecurity programs, security plans, Risk Assessment Reports (RARs), plan of action and milestones (POA&Ms), accreditation and authorization (A&A) workflow tools data, patch management, information assurance vulnerability alerts (IAVA), DoD Directive 8140 (8570) certifications FISMA compliance requirements, and ATOs.

2.4.3.3 Conduct trend analysis on the security tools, perform root cause analysis on compliance and non-compliance, and offer recommended fix actions as required.

2.4.3.4 Interact with Unit ISSOs/ISSMs and commanders to provide cybersecurity guidance, complete cybersecurity assessment reports and provide solutions to commanders on how to improve their cybersecurity programs.

2.4.3.5 Support the Cybersecurity trainers with updated information and materials for their area of responsibility for compliance with USAF, DoD, IC and other national agency standards.

2.4.4 Governance and Management (GM) Support: The following GM support services shall be provided to the ACC/A26 and 625 ACOMS. The contractor shall provide GM support to the Integrated Defense Security Operations team and AF IC level CISO; specifically in the areas of: (a) plans and policies, (b) cybersecurity training, and (c) content management and development.

2.4.4.1 Plans and Policies: The contractor shall research, analyze, develop and provide well defined plans, policies, agreements and procedures applicable to IC and AF cybersecurity mandates and security control requirements. (A004) The contractor shall:

2.4.4.1.1 Conduct in-depth policy analysis at the Federal, DoD, ODNI, USAF, AF IC, PMO, and site levels.

2.4.4.1.2 Focus on policy development, security controls compliance policies, and update AF IC existing policies and plans as needed.

2.4.4.1.3 Coordinate with and solicit SME support as required.

2.4.4.1.4 Create a policy development process and submit it to the government for approval. Once approved, the contractor shall comply with said process. The process shall include, but not be limited to the following:

2.4.4.1.4.1 Receive request from the government.

2.4.4.1.4.2 Conduct research. Utilize all relevant resources such as existing policies, standards, instructions, directives, mission related standard operating procedures (SOP), NIST documentation, mission partners, and SMEs.

2.4.4.1.4.3 Develop draft document, citing all relevant resources, and submit to government requestor for initial review.

2.4.4.1.4.4 Coordinate and setup meeting or telecom with key stakeholders to review and solicit inputs.

2.4.4.1.4.5 Prepare final document. Incorporate applicable inputs, format per appropriate standards.

2.4.4.1.4.6 Submit final copy to government for approval and upload for AF and IC member access.

2.4.4.1.4.7 Provide any follow-on support to policy as required: receive any questions from customers, coordinate with SME, develop response, and submit response to customers.

2.4.4.1.4.8 Professionally interact with managers and site personnel and present oral and written process solutions.

2.4.4.1.4.9 Research, develop, review, edit, comment, analyze documents and recommend corrections and changes. Provide improvement recommendations when in regards to technologies, or processes used under this role or function supporting the organizational missions; to include lessons learned.

2.4.4.2 Cybersecurity Training: The contractor shall conduct technical and managerial level training on information system security, security tools and A&A workflow tools.

Cybersecurity exercise development shall be performed in support of Integrated Defense Security Operations function (reference para 2.6). (A005)

2.4.4.2.1 The contractor shall develop additional technical and managerial cybersecurity training plans, guides, materials and curriculum to enable compliance with USAF, DoD, IC and other national agency standards.

2.4.4.2.2 This training shall familiarize AF IC IT security professionals with the applicable IT security tools, policies and procedures required to protect resources and meet standards.

2.4.4.2.3 Cybersecurity Exercise Development: Operating procedures shall be developed in coordination and review by government Integrated Defense Security Operations teams (ref para 2.6).

2.4.4.2.4 The contractor shall coordinate with appropriate contractor SMEs to provide exercise development recommendations that include test plans and procedures to ensure results support the required objectives and capabilities. (A005)

2.4.4.2.5 Training critiques shall be used to assess the instructor performance and update training materials.

2.4.4.3 Content Management and Development: The contractor shall expertly manage and maintain the AF IC cybersecurity collaborative environments for successful day-to-day business operations on networks at the UNCLASSIFIED, SECRET and TOP SECRET security levels. The contractor shall:

2.4.4.3.1 Maintain SharePoint and websites allowing customer access to needed cybersecurity information. The customers will include, but not be limited to the AF IC CISO, AO and their SMEs, and general customers.

2.4.4.3.2 Implement high quality, scalable, and extendable SharePoint solutions using the .NET Framework, ASP.net, SharePoint (currently using version 2013) and other advanced components of Microsoft technology.

2.4.4.3.3 Publish databases to SharePoint and develop custom forms. Expert knowledge of hypertext markup language (HTML) and JavaScript are required to create custom web parts.

2.4.4.3.4 Utilize Microsoft SharePoint Designer to customize sites and create custom workflows.

The contractor shall have a solid grasp of the permissions hierarchy of the SharePoint application. The contractor shall transform customer requirements into viable SharePoint-involved solutions.

2.4.4.3.5 Address possible solutions and timeframes for completion with the customer for each tasking. Once the solution is implemented, access to the site, library, or object shall be controlled through permissions provided by the particular Government SME.

2.4.4.3.6 Test all content management solutions followed by the end user before being deployed to production.

2.4.4.3.7 Field all SharePoint-related questions concerning the sites they manage including requests for site access.

2.5 Engineering Support.

2.5.1 Cybersecurity Engineering: The following cybersecurity engineering support services shall be provided to the ACC/A26 and 625 ACOMS. The contractor shall serve as the cybersecurity engineer and provide the Government SME with recommendations and solutions for implementing AF IC cybersecurity programs, ISR systems, Integrated Defense Security Operations capabilities, and AF IC RMF implementation. (A006) The contractor shall:

2.5.1.1 Use the RMF methodology to successfully implement applicable information technologies, which shall effectively protect the element's information assets and its ability to perform its mission.

2.5.1.2 Provide program reviews, schedules, action item updates and required procedures by established deadlines.

2.5.1.3 Coordinate with the plans and policies POC, and conduct timely and in-depth research for policies and processes applicable to security engineering.

2.5.1.4 Apply IT security control requirements to address the level of security required to protect the confidentiality, integrity and availability of system data and resources. Solutions shall be compatible with system or network hardware and software configurations and shall be approved by the configuration managers of the system and network. Recommendations shall include test plans and procedures to ensure results support the required objectives and capabilities.

2.5.1.5 The contractor shall perform scans of systems and architectures using AF IC -approved scanning tools during the security test and evaluation (ST&E) event. The contractor shall construct and provide ST&E reports that contain the scans, Security Technical Implementation Guide (STIG) application with issues and recommendations for delivery prior to the assessment event.

2.5.1.6 Execute all applicable Supply Chain Risk Management (SCRM) policy and procedure and create reports for all new additions of system hardware and software to determine the source from the OEM through the end supplier to ensure SCRM is followed per policy and guidelines.

2.5.1.7 Participate in meetings and program reviews and support the implementation of ISR initiatives, goals and objectives; providing reports, plans, and procedures as required.

2.5.1.8 Provide the AF IC CISO with the technical costs of protective measures so they may be weighed against requirements for mission accomplishment.

2.5.1.9 Make edits to existing Government documents, prepare briefings as required to update the Government on the status of actions and coordinate with all project members to meet the goals and objectives of the assigned task. If required to implement a cybersecurity initiative, the PM shall complete the A&A documents required to obtain an ATO.

2.5.1.10 When applicable, complete POA&Ms for the project to address security vulnerabilities.

2.5.2 Assessment Support Engineering: The following cybersecurity engineering support services shall be provided to the ACC/A26 and 625 ACOMS. The contractor shall provide support to the DAOs and SCAs by performing the tasks in section 2.5.1 and this section.

(A006) The contractor shall:

2.5.2.1 Provide technical assistance to the SCA during the POA&Ms development phase of the project.

2.5.2.2 Perform applicable Assessment Engineer review and approval tasks within the A&A workflow tool.

2.5.2.3 Review Security Impact Analysis (SIA) submissions and provide recommendations to DAOs as part of the continuous monitoring stage of the RMF.

2.5.2.4 Perform technical analysis of all assessment and authorization documentation to ensure validity and accuracy as it relates to the development and operational implementation of AF IC and ISR systems and networks.

2.5.2.5 Review and provide cybersecurity recommendation to AO/DAO as it relates to security impact analysis of AF IC and ISR systems and networks.

2.5.2.6 Analyze and provide cybersecurity recommendations for information protection throughout the development and acquisition lifecycle as it relates to AF IC and ISR systems and networks.

2.5.2.7 Assess the security risk, research and recommend security best practices in accordance with AF IC policy and guidance.

2.5.2.8 Analyze ports, protocol, and services to ensure compliance with DoD and AF IC policy and guidance.

2.5.3 Integrated Defense Engineering: The following cybersecurity engineering support services shall be provided to the ACC/A26 and 625 ACOMS. The contractor shall serve as the cybersecurity engineer and provide the Government SME with recommendations and solutions as related to Integrated Defense Security Operations programs and projects.

(A006) The contractor shall:

2.5.3.1 Have expert knowledge of professional security engineering concepts, principles, practices, standards, methods, techniques, and procedures; and ability to implement enterprise level security standards and execute sound techniques to solve complex interrelated problems.

2.5.3.2 Have a high degree of skill in applying analytical and evaluative techniques to identify, investigate, and resolve complex engineering issues or problems as they relate to security.

2.5.3.3 Have in-depth knowledge of agency, AF, DoD and national-level doctrine, regulations, policies, guidelines, requirements, and initiatives related to assigned programs and projects.

2.6 Integrated Defense Security Operations Support.

The following cybersecurity engineering support services shall be provided to the 625 ACOMS.

The contractor shall provide support services to the AF IC SCC and AF IC IRC which fall under the umbrella of the Air Force Intelligence Community Information Environment (AF IC IE).

Note that the AF JWICS is part of the AF IC IE. The contractor shall fulfill all requirements levied upon the AF IC SCC, AF IC IRC and associated elements by Defense Information Agency, 625 ACOMS, and other authoritative DoD elements to meet all reporting, coordination, process development, improvement and other mandated actions that support their enterprise functions. Services shall include: exercise planning (see also para 2.4), continuous network monitoring, intrusion detection, intrusion prevention, continuous improvement recommendations, and incident response services for the network, systems, applications, and infrastructure.

2.6.1 AF IC SECURITY COORDINATION CENTER (AF IC SCC): The contractor shall provide support to the AF IC SCC. (A007) The contractor shall:

2.6.1.1 Manage command and control (C2) services to the AF IC CISO and the Risk Executive Function (REF) and appointed Government SMEs for situational awareness, analysis and reporting on the integrated defense risk for SCI and ISR resources to ODNI, AF/A2 and

AF/A6.

2.6.1.2 Provide 24/7 365 coverage. Coverage period shall be able to support 24/7 shifts in accordance with (IAW) duties and responsibility commensurate with Federal, DoD, and Air Force security policies and measures as defined by the government. The contractor shall adjust coverage as needed to account for future surges or world event driven circumstances.

2.6.1.3 Provide services that include research, development and release of AF IC Task Orders (TASKORDS) and notifications to the AF IC. The contractor shall comply with coordination processes and approvals, formats and reporting requirements as defined by the Government.

2.6.1.4 Develop and provide on-the-job training to Government, contractor and military personnel on various IT security tools, policies and procedures required to protect resources and meet standards. This is not formal training, but informal office training.

2.6.1.5 Exercise Planning: Plan, organize, manage, and coordinate the AF IC participation in cybersecurity exercises to include both IC and national-level exercises as per ODNI Concept of Operations for the Integrated Defense Security Operations of the IC Information Environment. The contractor shall provide informal training (e.g. exercise roles and responsibilities) to AF IC participants as necessary and provide status reports to include but not limited to an after action report.

2.6.1.6 Make edits to existing Government documents, prepare briefings to update the Government on the status of actions and coordinate with all project members to meet the goals and objectives of the assigned task. Provide approved situational reports to the AF IC CISO, A2 and ODNI.

2.6.1.7 Develop standard operating procedures (SOPs) and provide training on existing and new technologies to government personnel. Provide subject matter expertise necessary to drive documentation and requirements to include but not limited to AF IC SCC SOPs, workflows, appropriate process aids and frameworks, and their interdependencies to support customer’s current and future security technology implementation and sustainment.

2.6.1.8 Respond to and process task orders (TASKORDS) as directed by the 625 ACOMS.

2.6.1.9 Provide inputs for the development of Concepts of Operation, Implementation plans, and Special Instructions for various AF IC projects.

2.6.1.10 Support AF IC IE vulnerability management report compliance to DIA as defined by the Government.

2.6.1.11 Provide feasibility studies, quick turnaround systems analysis, and independent evaluations of contractor proposals and emerging technologies and concepts. Coordinate and report with/to applicable AF IC cyber elements as necessary for the improvement of confidentiality, integrity, and availability of related cyber and ISR capabilities. (A002)

2.6.2 AF IC INCIDENT RESPONSE CENTER (AF IC IRC): The contractor shall provide 24/7 365 services to support integrated defense security operations functions. These services include: Incident Response Infrastructure Support (IRIS), continuous network monitoring, intrusion detection and incident response services for systems within the scope of authority of the AF IC CIO, AF IC AO and AF IC CISO. (A007) The contractor shall:

2.6.2.1 Provide 24/7 365 support to monitor, protect, and maintain situational awareness of the Enterprise.

2.6.2.2 Apply the appropriate techniques and skills to protect the AF IC IE domain by containing and eradicating incidents based on the processes outlined in the current CJCSM 6510, Cyber Incident Handling Program (dated 10 July 2012 or later).

2.6.2.3 Document, track, and report incidents from initial detection through resolution using standard AF IC IE incident reporting channels and methods (IAW the CONOPS for Integrated Defense Security Operations for AF IC IE and the current CJCSM 6510.01B, Cyber Incident Handling Program (dated 10 Jul 2012 or later).

2.6.2.4 Collect and analyze network intrusion data from a variety of sources to include but not be limited to logs, system images, and packet captures to enable mitigation of network incidents within the AF IC to include AF JWICS.

2.6.2.5 Perform incident triage to determine scope, urgency, and potential operational impact by identifying the specific vulnerability and making recommendations, which enable rapid remediation or mitigation at the AF JWICS and AF IC level.

2.6.2.6 Upon resolution of network incidents, create custom signatures or correlation rules to detect future incidents as well as make AF IC IE protection recommendations to enhance resistance to future attack.

2.6.2.7 Serve as technical experts and liaisons to external incident response personnel and brief incident details as necessary.

2.6.2.8 Provide AF IC-wide incident handling support such as forensics collections, intrusion correlation tracking, threat analysis, and direct system remediation tasks to appropriate personnel.

2.6.2.9 Develop and publish incident response guidance and high quality incident reports to appropriate audiences.

2.6.2.10 Develop standard operating procedures (SOPs) and workflows integrating applicable new technologies. Provide training on current and new technologies to government personnel to service support. This is informal office training. Complete SCC/IRC mission qualification training; plan to establish and maintain proficiencies; provide testing results to 625 ACOMS. (A003) (A006)

2.6.2.11 Perform heuristic analysis on event data to discover subtle patterns, low-and-slow attacks, and advanced persistent threats: analyze and respond to real-time and near real-time security events. Perform real-time alerting and problem resolution.

2.6.2.12 Perform high-performance interactive searches.

2.6.2.13 Provide comprehensive drill-down reports and incident handling capabilities.

2.6.2.14 Prioritize remediation efforts using reliable threat intelligence.

2.6.2.15 Monitor and protect the security of the AF Intelligence Enterprise from internal and external computer network defense threats.

2.6.2.16 Support Enterprise vulnerability management programs and report events to the appropriate program manager for processing as defined by the Government.

2.6.2.17 Process and release task orders (TASKORDS) as directed by the 625 ACOMS Government Lead.

2.6.2.18 Provide input to vulnerability management policies and procedures as required by the Government. Provide input needed to posture the AF IC IRC to meet current and future security needs arising from leadership strategic vision/vector and environmental constraints.

2.6.2.19 Make all required edits to existing Government documents, prepare briefings to update the Government on the status of actions and coordinate with all other members to meet the goals and objectives of the assigned task.

2.6.2.20 Review and edit documents and recommend corrections and changes to existing Government documents.

2.6.2.21 Provide AF IC SCC situational reports as approved by the AF IC CISO to ODNI and A2.

2.6.2.22 Utilize computer network defense (CND) and Security Information and Event Management capabilities and mapping, and host based systems to correlate and analyze events, respond to anomalous activities on AF IC IE network and information resources, and defend the networks from threats.

2.6.2.23 Evaluate the security posture of infrastructure to include but not be limited to firewalls, intrusion detection system (IDS), network intrusion detection/prevention system (NIDS/NIPS), routers, crypto equipment, and switches.

2.6.2.24 Provide comprehensive drill-down vulnerability analysis reports. (A002)

2.6.2.25 Document network security procedures: prepare status reports, maintain status reports, and brief the information to inform leadership.

2.6.2.26 When directed by the Government Lead, mitigate/remediate system vulnerabilities and report compliance status to applicable personnel. Also ensure appropriate notifications and mission impact assessments are accomplished.

2.6.2.27 Create/execute security related scripting and perform performance assessments.

2.6.2.28 Provide technical support in the evaluation, testing, installation, and integration of AF IC ITE CND software and hardware capabilities.

2.6.2.29 Remain abreast of the IC IE in order to integrate network information systems security with other security disciplines.

2.6.2.30 Maintain a thorough understanding of NIST Risk Management Framework (RMF) processes to certify systems or network accreditation.

2.6.2.31 Respond to, draft, and process task orders (TASKORDS) as directed by the 625 ACOMS Government Lead. Send TASKORDS to the AF IC SCC for release.

2.6.2.32 Provide input to vulnerability management policies and procedures.

2.6.2.33 Develop documentation that describes AF JWICS CND cyber security posture, techniques, and procedures.

2.6.2.34 Correlate, analyze, and report audit results. Process, format, filter, and share the auditable event data with incident responders.

2.6.2.35 Implement modifications to the Intelligence Community Information Technology Enterprise (IC ITE) to generate, collect, share, store and retain audit data.

2.6.2.36 Provide recommendations to modify and enhance existing CND capabilities to augment and complement AF IC SCC CND program. Implement approved modifications to CND systems. Implement the Enterprise Audit Conceptual Framework as defined by ICS 500- 27.

2.6.2.37 Perform CND system health checks IAW operational guidance and policy.

2.6.2.38 The contractor shall prepare and present briefings as subject matter expert as required.

2.7 Task Summary.

The figure below summarizes the tasks described in sections 2.1-2.6 by showing functional requirements for ACC/A2 and 625th ACOMS. This is not a manning matrix.

TABLE 2.7.1 TASK SUMMARY TABLE

2.8 SERVICES SUMMARY (SS)

The contract service requirements are summarized in performance objectives that relate directly to mission essential items. The performance threshold briefly describes the minimally acceptable levels of service required for each requirement. The Services Summary (SS) provides information on contract requirements and the expected level of contractor performance to be

PWS Para No. DESCRIPTION ACC/A26 625 ACOMS

2.1 ADMINISTRATIVE SUPPORT

2.1.1 Office Coordination and Administration X X

2.1.2 Document Manager X

2.2 CYBERSECURITY PROCESS IMPROVEMENT SUPPORT

2.2.1 Process Improvement Development and Engineering X

2.3 SECURITY CONTROLS ASSESSMENT (SCA) SUPPORT

2.3.1 Security Control Assessor X

2.4 AUTHORIZATION SUPPORT

2.4.1 Designated Authorizing Official (DAO) Support X

2.4.2 DAO Software Security Analysis and Database Support X X

2.4.3 Cybersecurity Program Manager (CPM) X

2.4.4 Governance and Management (GM) Support:

2.4.4.1 Plans and Policies X X

2.4.4.2 Cybersecurity Training X X

Cybersecuri…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .