Atch_2_-_ATS_CAP.pdf

PDF 155 KB Posted

Attached to
AFOTEC Test Services (ATS) Federal contract opportunity
Solicitation number
FA7046-16-R-0003
Issued by
Department of the Air Force Materiel Command Test Center

About this file

ATS TO CAP Amend 2.

View the file

Other files for this federal contract opportunity

Other files attached to AFOTEC Test Services (ATS), newest first.
File Type Posted
Follow_up_ATS_Amend_3&4_Q&As.pdf PDF
Final_ATS_Labor_Category_Rate_Matrix.xlsx XLSX spreadsheet
FA7046-16-R-0003_Amd_4_Final_Copy.pdf PDF
ATS_Amend_3_Q&As.pdf PDF
Final_ATS_Basic_PWS_28_June_2017.pdf PDF
Amendment_3-ATS-FA7046-16-R-0003.pdf PDF
Final_ATS_Labor_Category_Rate_Matrix.xlsx XLSX spreadsheet
ATS_RFP_Amend_2_Q&As.pdf PDF
Atch_11_-_ATS_TO_Evaluation_Factors.pdf PDF
FA7046-16-R-0003_Amd_2_Conformed_Copy.pdf PDF
Atch_3_-_ATS_C2ISR.pdf PDF
Atch_10_-_ATS_TO_1_-_Post_Award_PWS.pdf PDF
ATS_RFP_-_16-R-0003_Amd_1.pdf PDF
ATS_TO_0003_CAP-_Revised_5_Jan_17.pdf PDF
Final_RFP_Q&As.pdf PDF
ppi_tool.accdb —
Atch_5_-_ATS_RFP_DD_Form_254.pdf PDF
RFP_ATS_FA7046-16-R-0003.pdf PDF
Atch_1_-_Section_L__Atch_1-5.pdf PDF
Atch_8_-_ATS_Basic_PWS.pdf PDF
Atch_2_-_ATS_TO_0003_CAP.pdf PDF
Atch_3_-_ATS_TO_0002_C2ISR.pdf PDF
Atch_4_-_ATS_TO_0001_NukDEW_12_Nov_2016.pdf PDF
Atch_9_-_ATS_RFP_Acronym_Listing.pdf PDF
https //www.fbo.gov/fedteds/ATSFA945116R0003 —
D5_C2ISR_TO_(12_Jul_16).doc DOC document
Basic_ATS_PWS_(12_Jul_16).doc DOC document
ATS_Draft_RFP_Acronyms_list.doc DOC document
NukDEW_TO_1_(12_Jul_16).doc DOC document
ATS_CDRLs_(Exhibit_A).doc DOC document
ATS_Draft_RFP_29_Aug_16.docx DOCX document
OL-KT_TO_(12_July_16).docx DOCX document
DRAFT_DD_Form_254_for_ATS_Request_for_Proposal.pdf PDF
ATS_Industry_Day_WebEx_Attendees.xlsx XLSX spreadsheet
ATS_Industry_Day_Q A.docx DOCX document
ATS_Brief_for_Industry_Final-_Post.pdf PDF
ATS_Agenda_9_Jun_15.pdf PDF
ATS_Agenda_9_Jun_15.pdf PDF
ATS_Q A_2_June_16.docx DOCX document
DRAFT_ATS_PWS.docx DOCX document
ABQ_Map_of_PTi__Sunport__Collaboration_Center.pdf PDF
ATS_Questions_and_Answers_14_Apr_2016.docx DOCX document
D5_C2ISR_TO_(12_Jul_16).doc DOC document
ATS_CDRLs_(Exhibit_A).doc DOC document
DRAFT_DD_Form_254_for_ATS_Request_for_Proposal.pdf PDF
ATS_SSS-RFI_-_1_Apr_16_Final.docx DOCX document
NukDEW_TO_1_(12_Jul_16).doc DOC document
SECTION_L_ATTACHMENTS_L1_-_L5.pdf PDF
ATS_Draft_RFP_Acronyms_list.doc DOC document
ATS_Draft_RFP_29_Aug_16.docx DOCX document
Show all 50

AFOTEC Test Services (ATS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AIR FORCE OPERATIONAL TEST & EVALUATION CENTER

TEST SERVICES (ATS)

AIR FORCE CYBERSECURITY ASSESSMENT PROGRAM (CAP)

2 March 2017

1.0 SCOPE

This effort shall be conducted pursuant to the provisions of the Air Force Operational Test and Evaluation Center (AFOTEC) Test Services (ATS) contract Performance Work Statement (PWS), Paragraph 3.0. The objective of the task order is to provide technical, scientific, and engineering services for the conduct of Cybersecurity Assessment Program (CAP) assessments on behalf of designated Combatant Commands (CCMD) and the United States Air Force (USAF). The contractor shall provide in-depth technical and operational knowledge as related to cybersecurity (CS) and Information Technology (IT), Multidisciplinary Security, Joint Exercises, Joint Planning, exercise training objective development, and Joint Lessons Learned. The contractor shall provide engineering experience sufficient to conduct assessments and mathematical and statistical knowledge sufficient to develop assessment metrics. The contractor shall provide Joint and Service-level training exercise assessments in accordance with (IAW) the Office of the Secretary of Defense, Director, Operational Test and Evaluation (DOT&E) Cybersecurity Assessment Program Handbook and the Common Methodologies Document series (reference paragraph 2.0). Contractor personnel shall be fully capable of conducting assessments in all aspects of cybersecurity, which includes interoperability, mission assurance and exercise mission areas.

The contractor shall participate in planning, execution and reporting of these events and assessments to include: network vulnerability verification and validation reviews, vulnerability remediation events, reporting of exercise-based cybersecurity assessments, the development of methods and metrics to guide these efforts, scheduling and management of assessment tasks, and deliverable documents; and provide IT support for CAP assessment activities.

All assessment deliverables will be routed through AFOTEC Operating Location Kelly Field TX (OL-KT) government personnel. The contractor shall participate in the sharing of information to include: best practices, lessons learned, and common methodologies with other Operational Test Agencies (OTAs) and DOT&E. Activities will be divided between OL-KT, San Antonio, TX, NORAD-USNORTHCOM (N-NC), Colorado Springs, CO and USPACOM, Camp Smith, HI, Kirtland AFB, NM and will require other exercise locations as well. Worldwide exercise participation may be required annually.

1.1 BACKGROUND

As designated, AFOTEC/OL-KT will perform CAP Assessments IAW AFOTEC and DOT&E guidance, Congressional language in the October 2002 Defense Authorization Act (HR 5010 /

Report 197-523) and Common Methodologies Document series. The Congressional directive requires each CCMD and Service to ensure robust command, control, communication, computers, intelligence, surveillance, and reconnaissance (C4ISR) functionality is included annually within at least one of its major exercises. The language further directs operational assessments of cybersecurity and mission assurance be conducted during these exercises and charges the operational test community, along with the National Security Agency (NSA) and Service information warfare centers, to participate in the planning, conduct and evaluation of these operational assessments.

OL-KT is tasked to manage the CAP program on behalf of AFOTEC. All tasks accomplished under the program are performed IAW the DOT&E Cybersecurity Assessment Program Handbook and the Common Methodologies Document series (Paragraph 2.0 below) which provide detailed guidance on the scope of all assessments as well as the specific methods to be employed in the accomplishment of assessment tasks (see paragraphs 3.3 and 3.4).

2.0 APPLICABLE DOCUMENTS

In addition to the test and evaluation guidance contained in the Basic contract PWS, Section 2.0, the following documents are applicable to this task order.

DOT&E Cybersecurity Assessment Program Guidebook, version 2 1 Oct 2016

DoD 8570.01-M Information Assurance Workforce Improvement Program, Change 4, 10 Nov 2015

Chairman of the Joint Chiefs of Staff Instruction (CJCSI) 6510.01F Information Assurance (IA) and Support to Computer Network Defense (CND) 9 Jun 2015

Secretary of Defense, Maintaining Readiness to Operate in the Cyberspace Domain, Dec 2012

Chairman of the Joint Chiefs of Staff Instruction (CJCSI) Execute Order to Incorporate Realistic Cyberspace Conditions into Major DoD Exercises, 11 Feb 2011

2.1 Records Management

2.1.1 Air Force Manual (AFMAN) 33-363 Management of Records, 21 Jul 16;

Chapters 2, 3 and 4 in their entirety, Paragraph 6.4.

2.1.2 Air Force Instruction (AFI) 33-364 Records Disposition – Procedures and Responsibilities, 9 Apr 15; Paragraphs 1.1.1, 1.1.2, 1.2.2, 2.1.1, 2.10 through 2.10.1.3;

Chapter 3 in its entirety, 4.1 through 4.1.7, 4.4 through 4.4.1, 5.1, 5.1.1, 5.1.2, 5.5, 5.5.2, 5.5.3, 5.6, 5.6.1, 8.1 and 8.1.1.

2.2 Security References - The contractor must follow the established security regulations and procedures. The documents listed in Attachment 1 are provided for reference only.

3.0 PERFORMANCE REQUIREMENTS – Applicable to the total basic effort.

Contractors may be called upon to participate with other DoD agencies in the performance of duties listed below. Performance will be required in three focus major areas listed below.

SpecifiedTeamLeadshouldbedefinedforeachAssessmentoperatinglocationtothe
Government’spointofcontact.

3.0.1 Cybersecurity (CS) Assessments. (Paragraph 3.3) - The CS assessments focus on the attributes of a system or network that ensure the availability, integrity, authenticity, confidentiality, and non-repudiation of the data handled by that system, system of systems, or network. Cybersecurity is primarily focused upon information security, and is the primary area of concern for these assessments. The contractor shall provide plans, reports, briefings, and matrices in accordance with DOT&E CAP and Cybersecurity processes and guidance as specified in paragraph 3.3.

3.0.2 Mission Assurance (MA) Analysis. (Paragraph 3.3) - MA analysis focuses on the contribution, both positive and negative, to identified missions, mission tasks, and mission processes resulting from the support provided by the systems and networks assigned to those functions. It is primarily focused on operations, and is a secondary area of concern for these assessments as it establishes both context and helps establish the criticality of CS observations.

3.0.3 Vulnerability Remediation. (Paragraph 3.4) - Often referred to as Green Team or Staff Assistance Visits, vulnerability remediation supports CS and MA assessments while benefitting the assessed organizations at the same time. These events may occur post- baseline (Blue Team assessment) providing assistance and support to the network administrators and technicians to repair and mitigate identified vulnerabilities. Green Team events will be included in the overall assessment analysis and evaluation if the assessed Service or CCMD has previously requested remediation assistance and have provided a vulnerability shortfall matrix identifying areas requiring remediation.

3.1 Management. The contractor shall provide a management structure to accomplish this task order in compliance with the provisions in Basic PWS Section 3.1 (A001, A002, A004).

3.1.1 Assessment Capabilities. The contractor shall:

3.1.2 Metrics and Methodology Development and Statistical Support. The contractor shall provide expertise in the creation of meaningful metrics for all AFOTEC-led CAP assessments. Metrics required for all assessments are published by DOT&E and maintained by the Common Methodology Working Group (CMWG). The contractor shall conform to new metrics as adopted by DOT&E and provide recommendations to the government to further the metrics and methods employed. (A016, A021)

3.1.2.1 The contractor shall employ statistical means to ensure assessment data is properly analyzed and conclusions drawn from the assessment are statistically justified. Sample populations will be identified when statistical analysis is required in order to better understand how much confidence can be assigned to the data.

3.1.3 Develop Event Proposal(s) and Capstone Event Plan(s). All CAP assessments rely heavily on the assessment plan used during the exercise. The contractor shall develop assessment plans.

3.1.3.1 Planning begins with the development of initial concepts and a corresponding briefing. As the planning information matures, this forms the basis for the Assessment Plans and their support briefings AFOTEC generates and distributes. The contractor shall attend program meetings, review system configuration and threat documents, coordinate assessment concepts, operational/maintenance concepts, and other documentation required to be knowledgeable about a specific program. The contractor shall develop task oriented objectives and assessment measures, assessment procedures, exercise scenarios, analysis methods, data targets to be collected along with descriptions of the associated collection methods, instrumentation, and schedules. The contractor shall identify candidate operational exercise opportunities and additional events to help provide a realistic evaluation. The contractor shall make recommendations for assessment data management. The contractor shall develop plans and procedures to verify the correctness and completeness of the raw data and to transfer data from the initial collection media to a form readily accessible and usable for the analysis. (A003, A004, A005, A012, A016)

3.1.4 Participate in DOT&E Common Methodologies Working Group (CMWG).

The CMWG is held periodically by DOT&E. All Operational Test Agencies participate in these events which are generally conducted via teleconference. When remediation or green team methodologies are included in the agenda, the contractor shall participate and provide lessons-learned and best practices. Occasionally, these working groups are conducted as part of a DOT&E summit. When requested, the contractor shall travel to the summit location to participate. The contractor shall attend all DOT&E-sponsored metrics development events/summits and participate in all CMWG teleconferences. The contractor shall offer ideas to improve current methodologies in these forums. (A003)

3.1.5 Lead Assessment/Observation Effort. The contractor shall be the contract lead Assessor/Observer for a given assessment. The contractor shall communicate with all assigned assessors/observers to ensure data is being collected at the appropriate sites.

When exercise events hinder observations, the contractor shall coordinate with the exercise control cell to resolve these issues. (A003, A004, A016, A021)

3.1.6 Operational Test Agency (OTA) Support. The contractor shall be in contact with the other OTA and Standing, Test, Assessment & Rehearsal Team (START) counterparts to ensure opportunities for Air Force service-level events are capitalized upon. Efforts should be made to ensure DOT&E is notified of potential Air Force collection and observations efforts across the other CCMDs. At DOT&E request and AFOTEC approval, contractors can be able to support other OTA efforts within the CAP scope.

3.2 Cybersecurity & Mission Assurance Assessment Plan.

3.2.1 Planning. The contractor shall:

3.2.1.1 Develop Event Proposal(s) and Capstone Event Plan(s). The contractor shall develop the assessment proposal/plan IAW DOT&E policies and guidance and shall be prepared in the format specified by the CAP lead(s). The assessment proposal/plan includes CS and MA and details the methods in which assessors/observers will conduct each aspect of the CAP assessment, collect and analyze data. The observation plan (described below in paragraph 3.3.1.3) is the cornerstone of the assessment plan and must be carefully coordinated to ensure adequate data collectors are available who possess the appropriate experience and security clearance requirements. The contractor shall perform and document planning activities under the direction of the lead analyst. The contractor shall develop the event proposal or initial draft and final Capstone Event Plan and provide them IAW Paragraph 5.4.8. The contractor shall review the event proposal(s) to conduct the CRC Event and ensure the plan is within guidance IAW Paragraph 5.4.8.

(A003, A004, A005, A012, A016)

3.2.1.2 Event Supporting Assessment. Review is an assessment of CS policy, compliance with training and certification guidance, Operations Security (OPSEC), physical security, emergency actions and contingency plans, relocation plans, and risk- management practices. Event assessments are generally prior to the start of the capstone assessment. (A014, A016, A021)

3.2.1.3. Develop the Observation Plan. The contractor shall develop the observation/assessor placement plan IAW DOT&E policies and guidance and shall be prepared in the format prescribed in Assessment Plan Format which is provided as an attachment to the overall event proposal or Capstone Event Plan document.

The observation plan is the cornerstone of the event proposal/assessment plan and must be carefully coordinated to ensure adequate assessors are available who possess the appropriate operational experience and security clearance requirements.

The contractor shall perform and document planning activities under the direction of the lead CAP analyst. The contractor shall develop an event proposal for CRC events and an initial draft and a final draft Capstone Event Plan and provide them IAW Paragraph 5.4.8. (A003, A004, A005, A012, A016)

3.2.2 CS and MA Assessment Execution. The contractor shall:

3.2.2.1 Conduct Assessment. Cybersecurity is conducted as part of the overall assessment as outlined in paragraph 3.3.2. Assessment may take place at multiple sites and will generally begin and end on or about the same dates as the start and end of the exercise or as outlined in the CRC. The contractor shall perform assessor/observer duties during the assessment. All contractor assessment activities, to include observations, shall be in accordance with the assessment plan and local rules of engagement (ROE) as contained in the exercise Operations Order (OPORD) or Execution Order (EXORD) and the Designated Approval Authority (DAA) letter.

(A003, A004, A016, A021)

3.2.2.2 Event Assessments. Event assessments are generally conducted prior to the capstone assessment. They can consist of training, technical and non-technical components. The non-technical portion of the assessment focuses on CS policy, compliance with training and certification guidance, OPSEC, physical security, emergency action and contingency plans, relocation plans, and risk-management practices. These build Green Team agendas for follow-on events. (A003, A004, A016, A021)

3.2.2.3 Collect Tactics Techniques and Procedures (TTPs). If requested and supported, the contractor shall collect TTPs when applicable during verification validation review assessment events. Remediation events are generally interactive in nature. Often they are fertile ground for the identification of new tactics to be employed both at the Joint and service levels. The contractor shall provide Tactic Improvement Proposals (TIP) to all assessment events (reference DoDI 8500.01, 14 Mar 14). The contractor shall include TIPs collected during remediation events in both the event quick look report(s) and final cybersecurity assessment report(s). The contractor shall submit TTP recommendations through AFOTEC/OL-KT. (A003, A004, A016, A021)

3.2.2.4 Conduct MA Assessment During Exercise. The MA assessment will take place in conjunction with the CAP assessments, at multiple sites and will generally begin and end on or about the same dates as the start and end of the exercise or as outlined in the CRC. The contractor shall perform data collection during the assessment. All contractor assessment activities to include data collection shall be in accordance with the event proposal(s) and Capstone Event Plan(s) and local ROE as contained in the exercise OPORD or EXORD and the DAA letter. (A003, A004, A016, A021)

3.2.3 CS and MA Assessment Evaluation. The contractor shall:

3.2.3.1 Analyze Results of Event Assessments. Results of technical network vulnerability and validation review assessments are provided in the form of an event quick look report(s), and a cybersecurity assessment report(s). The results shall be carefully analyzed to identify and develop remediation strategies for deficiencies found. Common examples include patch management, password security, firewall, and intrusion detection/prevention system configuration, information assurance policy, building access/physical security, detection of anomalous network behavior, administrative access controls and account management. Analysis shall categorize vulnerabilities based on the likely corrective measure. For example, vulnerabilities requiring purchase of additional equipment, hiring of additional personnel, or upgrading software should be categorized separately from vulnerabilities which can be addressed via training and remediation during a Green Team follow-on event.

(A004, A016, A021)

3.2.3.2 Analyze Results of Persistent Cyber Opposing Forces Data. Technical vulnerabilities identified in the action mapping of the various attack vectors are provided in the form of Action Map-like diagrams and are included in event quick look report(s) and the cybersecurity assessment report(s). The results shall be carefully analyzed to identify and develop remediation strategies for deficiencies found. Common examples include patch management, password security, firewall, and intrusion detection/prevention system configuration, information assurance policy, building access/physical security, detection of anomalous network behavior, administrative access controls and account management. Analysis shall categorize vulnerabilities based on the likely corrective measure. For example, vulnerabilities requiring purchase of additional equipment, hiring of additional personnel, or upgrading software should be categorized separately from vulnerabilities which can be addressed via training and remediation. (A004, A016, A021)

3.2.4 CS and MA Assessment Reporting. The contractor shall:

3.2.4.1 Prepare Event Quick Look Report(s) and Cybersecurity Assessment Report(s) draft and final. The results of the assessment are detailed in the event quick look report(s) and cybersecurity assessment report(s). At the discretion of the CAP lead, the CAP non-technical report may be combined with the technical assessment report. When this is the case, the contractor shall provide non-technical inputs to the technical assessment report writer. When the team lead requests a separate review event quick look report, the contractor shall prepare the initial draft and submit it electronically to the team lead. The contractor shall provide the report in the format specified by the CAP lead. (A003, A004, A005, A012, A016, A021)

3.2.4.1.1 Prepare Event Quick Look Report(s) and Cybersecurity Assessment Report(s). The contractor shall perform a thorough analysis of the data collected during the assessment and develop the final report. The contractor shall develop the initial draft and a final draft event quick look report(s) and cybersecurity assessment report(s) and provide them IAW Paragraph 5.4.8. (A003, A004, A005, A012, A016, A021)

3.2.4.2 Prepare Quick Look Briefing. The immediate results of the CS assessment are briefed either at the exercise hot wash or similar forum or at the assessed CCMDs or Services request. The briefing highlights both positive and negative CS and MA emerging results and suggests possible courses of action to achieve enhanced cybersecurity. The contractor shall prepare the draft briefing as well as work with the Persistent Cyber Opposing Forces to provide key details in the briefing. The government team lead must deliver the briefing to the CCMD or USAF customer. If at all possible, the Quick Look Briefing should be delivered prior to departing the customer’s site at the conclusion of the exercise. If the Briefing is part of a CRC, the CCMD or Service can request the brief prior to departure or receive the brief and report via video teleconference (VTC), secure chat methods or other specified format. The contractor shall prepare the initial draft and final draft Briefing and provide them IAW Paragraph 5.4.5 and 5.4.8. (A004, A005, A012, A016, A021)

3.3 Vulnerability Remediation. The contractor shall:

3.3.1 Develop Vulnerability Remediation Recommendations. Once vulnerabilities have been identified and categorized, the contractor shall work with the assessment lead and Persistent Cyber Opposing Forces to develop and write the actionable and/or attributable remediation recommendations. Vulnerability remediation shall focus on those high-priority vulnerabilities reported. The recommendations are included in the event quick report(s) and cybersecurity assessment report(s). The assessment report(s) will be finalized by government personnel. (A004, A016, A021)

3.3.1.1 Conduct Vulnerability Remediation Events. Remediation events, commonly known as Green Team events. During these events the remediation materials are presented to the CCMD or Service. The contractor shall conduct the remediation review. The contractor shall at no time alter active network configurations or settings. (A004, A016, A021)

3.3.1.2 Create Actionable Recommendations. Recommendations developed and researched by the team need to be realistic and actionable. Actions attributable to all levels, for example from user password awareness up to program management office or event congressional actions should be considered. (A004, A016, A021)

3.3.1.3 Develop Lessons Learned Handbook. The contractor shall compile and record the historical sum of the remediation events from all supported exercises into a Lessons Learned handbook. Contractor determined format for the lessons learned handbook is acceptable, but the timing for the handbook and all handbook updates should correspond to the annual requirement to DOT&E generation by

AFOTEC. (A004, A016, A021)

3.4 Forward Presence. NORAD-USNORTHCOM Colorado Springs, CO location and USPACOM Camp Smith, HI location. The contractor shall provide a dedicated forward presence to facilitate assessment planning, coordination, execution, reporting and closeout of various CAP-related exercises and assessment activities. Activities will be centered in the Colorado Springs, CO area, within the NORAD-USNORTHCOM mission areas and in the Camp Smith, HI area within the USPACOM mission areas, respectively. The contractor shall:

3.4.1 Conduct CAP-specific planning and status reporting via both written and verbal presentations

3.4.2 Organize and facilitate coordination meetings

3.4.3 Participate with AFOTEC analysts, CCMD, Joint and coalition partners and the Information Operations (IO) community to identify mission systems to assess

3.4.3.1 Assist AFOTEC in analyzing and prioritizing CCMD’s cyber CAP assessment support requirements

3.4.3.2 Assist AFOTEC in analyzing and prioritizing CCMD’s training requirements to be assessed against CS and MA

3.4.3.3 Assist AFOTEC in analyzing and prioritizing CCMD’s mission essential tasks to meet CCMD training requirements for the CS and MA assessment

3.4.4 Identify resources required to support AFOTEC planning, execution, analysis and reporting of assessment activities

3.4.5 Support planning meetings and conferences related to the exercise/assessment of CCMD cyber and IO programs

3.4.6 Support CAP assessment planning, analysis and out brief meetings

3.4.7 Assist AFOTEC in the development of CAP assessment plans for legacy and developmental mission systems

3.4.8 Optimize data collection teams to collect ground truth data in support of CAP assessments of fielded mission systems in their employed operational context

3.4.8.1 Develop thorough Cybersecurity data collection forms for the assessment to ensure collection teams collect ground truth data

3.4.8.2 Develop thorough MA data collection forms for the MA elements of the assessment to ensure collection teams collect ground truth data and capture mission thread success or failure

3.4.9 Augment Exercise Control Teams (White Teams) and or perform data collection during the assessment

3.4.10 Participate with AFOTEC development of immediate assessment results for presentation at the exercise hot wash or other forums

3.4.11 Participate with AFOTEC development of Quick Look briefs and reports at the end of the assessment

3.4.12 Perform thorough analysis of the data collected during the assessment and assist in the development of the final reports

3.4.13 Participate with AFOTEC in the consolidation of assessment results and drafting the assessment reports

3.4.14 Conduct trend analysis and review CCMD remediation efforts of deficiencies identified during assessments

3.4.15 Participate with AFOTEC in developing methodologies for assessing the CAP of mission systems to include critical operational issues (COI), measures of effectiveness (MOE), etc.

3.4.16 Work with Persistent Cyber Opposing Forces to perform thorough analysis of the aggressor data collected during the assessment and assist in the development of the final reports.

3.4.17 Participate in DOT&E’s CMWG. CMWG is held periodically by DOT&E. All OTAs participate in these events which are generally conducted via teleconference. When remediation or green team methodologies are included in the agenda, the contractor shall participate and provide lessons-learned and best practices.

Occasionally, these working groups are conducted as part of a DOT&E summit.

When requested, the contractor shall travel to the summit location to participate.

3.5 Information Technology Support. Contractor shall provide IT support to maintain workstations and various equipment connected to NIPR, SIPR and JWICS.

3.5.1 The contractor shall provide onsite IT support in the manor of system administrator for NIPR, SIPR and JWICS (to include Org box maintenance, some SharePoint administration and portal support.

3.5.2 Contractor shall provide onsite IT Support to maintain up to 70 workstations connected to NIPR and SIPR networks and up to 5 workstations connected to JWICS network.

3.5.3 Contractor shall provide onsite IT support to maintain secure and non-secure voice and video on NIPR, SIPR and JWICS networks.

3.5.4 The contractor will not be required to install cable runs, or perform system administrator duties and maintenance on network servers. There is no requirement for maintaining a help desk.

3.6 Recommended personnel qualification requirements to fulfill Task Order.

3.6.1 CYBER PLANNING/ASSESSMENT SME

3.6.1.1 Must have knowledge Must be knowledgeable of the CND and CNE environments

3.6.1.2 Must have minimum IAT level II certification

3.6.1.3 Must have knowledge of military decision making process

3.6.1.4 Desire Bachelor’s Degree or 13-18 years’ experience

3.6.1.5 Desire operational experience in CND or CNE

3.6.1.6 Desire exercise planning or cybersecurity assessments experience

3.6.2 ANALYST SERVICES

3.6.2.1 Must be knowledgeable of the CND and CNE environments

3.6.2.2 Must have minimum IAT level II certification

3.6.2.3 Desire Bachelor’s Degree or 13-18 years’ experience

3.6.2.4 Desire experience in mission assurance analysis

3.6.2.5 Desire experience in military operations

3.6.2.6 Desire experience in technical writing

3.6.3 ENGINEERING SERVICES

3.6.3.1 Must have experience in CND or CNE environments

3.6.3.2 Must have minimum IAT level II certification

3.6.3.3 Must Bachelor’s Degree Information Systems or Computer Science

3.6.3.4 Desire cyber exercise planning or cybersecurity assessments experience

3.6.3.5 Desire experience in network interoperability

3.6.3.6 Desire logical/infrastructure networking experience

3.6.4 COMPUTER SUPPORT

3.6.4.1 Must have CompTIA Security+ Certification

3.6.4.2 Desire 2 years’ experience as client systems administrator

3.6.4.3 Desire experience in security management

3.6.4.4 Desire experience in facility management

4.0 SURVEILLANCE MATRIX

Contracting Officer Representatives (COR) will use Table 4.1 as a guide when identifying a surveillance matrix in task orders.

Table 4.1 Surveillance Matrix

Performance Objective

PWS

Ref

Performance Threshold

Method of Assessment

Item 1: Provide responsive Task Order (TO)/team management including quick response to contingencies, to include timely and accurate TO document and report requirements, customer interaction and feedback, contributions to meetings and reviews, and TO modifications and Change Orders.

All Clear, consistent, and timely written and verbal communication (i.e., returns phone calls, emails or other communication attempts within 24 hours) with no customer complaints.

Unsatisfactory performance must be resolved within 5 working days.

Customer complaint as validated by COR and

PCO.

Item 2: The contractor must effectively monitor funding on each individual TO and effectively control the expenditures of all Other Direct Costs (ODCs).

5.4.1 Actual task order expenditures shall be

within 10% (COR determined) of approved projected budget.

Meets TO schedule requirements.

Monthly Status and/or Funds and Man-Hours Expenditure reports.

Item 3: The contractor must be responsive to Government requirements, ensure PWS compliant performance, provide prompt identification and resolution of problems, effectively communicate concerns with the COR and meet the delivery schedule required in the Contract Data Requirements List

(CDRL).

All Within each TO, no more than one late document per month and no more than three total customer complaints, to include timely CDRL delivery, per assessment period.

Unsatisfactory performance must be resolved within 5 working days.

Customer complaint as validated by COR and PCO.

Item 4: Comply with applicable portions of the DD Form 254 for Task Order requirements.

All Compliance is mandatory; failure to meet security requirements are unacceptable. Each security incident, inadvertent disclosure and violation must be repor ted to the government within 1 working day and violations resolved within 30 working days to the government’s satisfaction.

Customer complaint as validated by COR, PCO and cognizant security authority.

Item 5: Overall Quality of Performance: the contractor must efficiently perform all PWS tasks, including those requiring contributions to meetings and reviews.

All Contractor receives no more than three formal discrepancy reports per year.

Customer complaint as validated by COR and PCO.

Item 6: AFOTEC Safety Requirements: the contractor(s) shall ensure their employees and subcontractors comply with all applicable Occupational Safety and Health Administration (OSHA) standards, identify and mitigate hazards, and report pertinent facts regarding mishaps involving damage or injury. Contractors will cooperate in any safety investigation, to include toxicology testing.

7.5 Compliance is mandatory. The

contractor must meet minimum OSHA requirements. Per quarter, the contractor must have zero willful OSHA violations; zero serious violations; no more than 2 other than serious violations (“violation” is defined in OSHA standards).

Each OSHA violation must be resolved to the government’s satisfaction within 3 working days, except imminent danger situations which must be mitigated or resolved and reported immediately.

Incidents as reported in Status Reports, or violations reported to/observed by customer or COR.

5.0 SCHEDULE, DATA ITEMS, AND OTHER DELIVERABLES

5.1 Base Support/Government Furnished Property (GFP)/Government Furnished Information (GFI). The Government will provide working spaces, computer workstations, support equipment, special test and analysis equipment and software, and administrative equipment for personnel at Joint Base San Antonio, TX; at Peterson AFB, CO; Camp Smith, HI; and Kirtland AFB, NM.

5.2 Travel Requirements

Travel will be required for a variety of tasks called out in this task order. All travel shall be coordinated with the COR no later than one week, prior to departure. Additionally, during exercise execution, the contractor will be required to travel to the exercise execution locations for the duration of the exercise. The travel ceiling for this task order, inclusive of all indirect costs, is $490K per year.

5.3 Transition

It is anticipated that some important work will be in progress through the phase-in and phase-out periods of this contract. Interruptions or delays to the work would impact the mission. It is essential that attention be given to minimizing any interruption; therefore, the contract must provide for maximum cooperation between successor and incumbent, while also insuring that no work receives inadequate attention during phase-in/phase-out. The contractor shall plan for the transfer of work control, delineating the method for processing and assigning tasks, during phase-in/phase-out.

5.3.1 Phase-In/Phase Out. As a successor, the contractor shall insure a smooth transition with the incumbent contractor(s) during the phase-in period. There will be no phase-in if the successor contractor subcontracts to an incumbent. The contractor shall develop plans for assumption of awarded TOs. The contractor must provide an orderly transition of work acceptance and accomplishment such that any impact to a program is minimized. The phase-in time period is 30 days and is the first month of the period of performance. The phase-out period will be the last 30 days of the current period of performance.

5.4 Program Deliverables. Technical Data--All documents shall be marked with:

Export Control Warning: WARNING- This document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751, et. seq.) or the Export Administration Act of 1979, as amended, Title 50, U.S.C., App. 2401 et. seq. Violations of these export laws are subject to severe criminal penalties. Classified deliverables shall be marked in accordance with Executive Order 13526, DoD 5200.1-R, DoDM 5200.01 Vol 3-8, DoDI 5210.02, AFI 31-401, AFI 31-407, and ISSO Marking Classification Handbook.

Disseminate in accordance with provisions of DoD Directive 5230.25.

Delivery shall be made by electronic means to the Chief, OL-KT, and the COR using the DOT&E approved Assessment Database or SharePoint site. All reports shall meet OL-KT standards for structure and content. The contractor shall provide deliverables via established AFOTEC/OL- KT guidance to:

Current Location:

AFOTEC/OL-KT

102 Hall Blvd Bldg. 2000, Suite 345 San Antonio TX 78243-7026

Future Location:

AFOTEC/OL-KT

300 Medina Base Road Joint Base San Antonio Lackland, TX 78236-5307

5.4.1 Funds and Manpower Expenditure Report (A001) – Contractor format acceptable, but must be approved by AFOTEC/A-7K, A-7R and COR, (first submission only).

Reports are due 15 calendar days after end of each calendar month reporting period.

5.4.2 Monthly Status Reports (MSR) (A002) – Reports are due 15 days after the end of the prime contractor’s month accounting period by electronic means, delivered to AFOTEC/A-7K, A-7R and COR.

5.4.3 Event/Conference Minutes (A003) – A summary of all interchanges shall be documented in Event/Conference Report or Trip Report and submitted to the COR.

Minutes are due five (5) workdays after end of local area events and seven (7) workdays after the end of all other events.

5.4.4 Data Accession List (A004) – A listing of all documents produced shall be provided. The listing may be provided as an attachment to Status Reports (A002).

5.4.5 DoD Architecture Framework (DoDAF) (A005) – DoDAF documentation will be used to illustrate critical mission systems/mission threads identified to be assessed during CCMD and service level exercises and events. DoDAF documentation shall be delivered to the COR

5.4.6 Briefing Material (A012) – During assessment planning, execution, and reporting, various briefings are required to AFOTEC, MAJCOM, Air Staff, OSD, DOT&E and DoD organizations. Briefings will use the standard AFOTEC templates available on the AFOTEC SharePoint and include content as directed in the briefing guides also available on the AFOTEC SharePoint. For each assessment assigned under this task order, the contractor shall annually review scheduled events and provide comments to the COR.

Reference Paragraph 5.4.12.

5.4.7 Technical Reports-Study/Services (A016) – During assessment planning, the contractor will be required to review technical reports on factors related to assessment planning to support assessment planning options. During assessment reporting, contractors shall provide data analysis for inclusion into the final report. In both cases, format will be approved by the COR. Assessment plans; CS, Mission Assurance Analysis and miscellaneous technical reports will be submitted to the COR using the approved guidance. All submitted assessment plans and reports will be reviewed and approved through the normal AFOTEC planning and reporting process. Reproduction copies are not required. Reference Paragraph 5.4.12.

5.4.8 Critical Task Analysis (A021) – It is critical that the assessment event describe the results of analyses of mission critical tasks performed by the operational community employing the command and control (C2) systems. A primary tenant of the Mission Assurance component of these assessments is the assessment of C2 and operational support systems during all phases of mission execution, under normal and degraded modes of operation. The CAP CRC Event Quick Look report(s) and Cybersecurity Assessment report(s) must articulate the functional consequences of operator/maintainer critical tasks with respect to the effects upon both system (system of systems) functions and mission. Reference Paragraph 5.4.12.

5.4.9 Cybersecurity Assessment Master Plan (CAMP). (A016) – The CAMP is an annually updated high-level, three to five-year plan of CCMD-level events, assessment focus areas, and strategies for each Combatant Command. Each CAMP addresses the current year (via CRCs more to follow) and the next two to five fiscal years. The CAMP is staffed by the DOT&E CCMD lead through its respective CCMD and signed by DOT&E. This provides the CCMD an approved approach to assessing the CCMD.

The CAMP outlines a three to five year plan for CCMD assessments, states high-level planning events, identifies event assessment teams for each event, outlines the Red/Blue/Green Team assessment events.

5.4.10 Cyber Readiness Campaign (CRC). (A016) – A CRC is composed of multiple focused events throughout a year culminating in an exercise-based Cybersecurity Assessment Report. The CRC’s are one year of assessment activity per area of responsibility (AOR); one for USPACOM, one for N-NC and one for Air Force service level assessments. CRC’s are accomplished in conjunction and prior to the AOR’s capstone exercise. OL-KT develops CRC Event Proposals and Quick Look Reports for each CRC outlined event as well as the C a p s t o n e E v e n t Plan and Cybersecurity assessment report for the CAPSTONE event ending the CRC series. CRC events are annexes in the corresponding exercise-based Cybersecurity Assessment report.

5.4.11 Monthly Assessment Status Report (MASR) (A016) – The MASR is a document outlining planned travel/products due for DOT&E approved assessments AFOTEC/OL- KT plans to perform. An updated MASR is provided to the DOT&E Deputy Director on a monthly basis. DOT&E sets the standard data, timeline and format.

5.4.12 Delivery Timelines for CDRLs A012, A016 and A021. Several deliverables require staffing through AFOTEC Headquarters and require contractors to deliver products to OL-KT government personnel as outlined in table 5.1 below.

NOTE: Deliverables requiring the AFOTEC Commander’s signature will require no less than 19 but no more than 22 days to staff through the headquarters. For deliverables requiring A3 signature/release, 11 days will be required. Deliverables requiring A3 review will take no more than one full business day. All deliverables and their associated staffing timelines are included in the following CAP Deliverables & Suspense table.

Table 5.1 Delivery Timelines

CDRL

Initial draft due to OL-KT Government (Calendar Days)

Final draft due to OL-KT Chief (Calendar Days)

A012 CRC Event Proposal

34 days prior to CRC Event

STARTEX

32 days prior to CRC Event

STARTEX

A012 Capstone Event Concept Brief

(CECB)

2 Days after MPE or 185 days prior to Capstone SARTEX

4 Days after MPE or 183 days prior to Capstone STARTEX

A012 Other Briefing Material

12 Days before scheduled presentation

5 Days before scheduled presentation

A016 Draft Capstone Assessment Plan 90 Days before STARTEX to DOT&E

106 Days before Capstone

STARTEX

101 Days before Capstone

STARTEX

A016 Final Capstone Assessment Plan and Brief 45 Days before STARTEX to DOT&E

72 Days before Capstone

STARTEX

67 Days before Capstone

STARTEX

A012 Quick Look Brief 96 hours after CAPSTONE ENDEX to DOT&E

6 Hours after ENDEX 12 Hours after ENDEX

A021 Cybersecurity Assessment Report and Brief 90 Days after ENDEX to DOT&E

63 Days after Capstone Event ENDEX

68 Days after Capstone Event ENDEX

A021 CRC Event Quick Look Report

41 Days after CRC Event ENDEX 43 Days after CRC Event ENDEX

A016 CAMP input 15 July for next year 1 August annually A016 CRC plan 1 October to DOT&E

6 September annually 8 September annually

A016 MASR Monthly 13 of each month or first business day if on the weekend

15 of each month, review

*Government schedule will dictate final scheduling requirements

5.5 Schedule/Period of Performance: Ordering Period is DOA plus 60 months.

6.0 SECURITY REQUIREMENTS

6.1 Security

6.1.1 The contractor shall comply with all security requirements in accordance with DD Form 254, DoD Contractor Security Classification Specification.

6.1.2 The contractor will require access to classified and Special Access Program source data up to and including Top Secret Special Compartmental Information (SCI).

The contractor must have a Top Secret Security Clearance current within five years and be SAP and SCI eligible. The contractor must have a current clearance in place by the first day of the task order.

6.1.3 The contractor shall provide the Government with required information for program access requests to include justifications, letters of compelling need, and any other information to support program access packages. The contractor must ensure they are accurate and complete IAW applicable guidance.

6.1.4 The contractor submits classified visit requests via the Joint Personnel Adjudication System (JPAS) in support of tasks within the DoD. Classified visits outside of the DoD require Visit Authorization Letters in accordance with the National Industrial Security Program Operating Manual. Direct requests must be approved by AFOTEC with coordination by the COR/test manager prior to travel.

6.1.5 Report to an appropriate authority any information or circumstances of which they are aware may pose a threat to the security of DoD personnel, contractor personnel, resources and classified or unclassified defense information. Contractor employees shall be briefed by their immediate supervisor upon initial on-base assignment.

6.1.6 Any failure to adhere to security regulations will result in a security incident and will be processed according to DoDM 5200.01, Volume 3, SAF/AQ Security Pamphlet 5, AFI 31-401, AFMAN 14-304, JAFAN 6.0, 1-301a (10), and/or DoD 5105.21-M-1.

6.1.7 Safeguarding Information. The contractor shall:

6.1.7.1 Comply with DoD 5400.7-R, Chapter 4, DoD Freedom of Information Act Program, and AFI 33 332, Privacy Act Program requirements. These regulations set policies and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding official material.

6.1.7.2 Report to an appropriate authority any information or circumstances, of which they are aware, that may pose a threat to the security of DoD personnel, contractor personnel, resources, and/or classified or unclassified defense information. Contractor employees shall be briefed by their immediate contractor supervisor upon their initial on-base assignment. Government personnel do not supervise contract employees.

6.1.7.3 The contractor is prohibited from attaching any computer hardware to the Air Force network, or running any computer software unless it has been certified and accredited according to current USAF Instructions. Any such requests for reconfiguration, upgrade, or addition of computer hardware or software must be approved by the USAF Designated Approval Authority (DAA) representative via the contractor's submission of a written request to the COR. Contractor use of computer modems, thumb drives, and external hard drives on any machine attached to the USAF network is prohibited. Use of commercial internet service providers is prohibited.

6.1.7.4 Contractor personnel using computer assets shall comply with all computer security requirements. In addition, should contractor personnel require access to computer networks or databases, they shall inform the COR or Alternate COR, who will arrange for the contractor personnel to complete the required documentation for a new computer account. IAW 5352.242-9001. The contractor shall notify the COR or Alternate COR of any contractor personnel who no longer require an open account.

6.1.7.5 All contractor personnel who will be using C4 systems belonging to the federal government to generate, process, store, transfer, or communicate information shall attend mandatory C4 systems security training. The format for the training may be either the Air Force C4 Systems Security Awareness Training program format or an in-house contractor program that meets DOD requirements, subject to agreement by the COR. The training must be completed within the first thirty calendar days of the start of the contract or within the first 10 calendar days for contracts that have duration of 60 days or less. The contractor shall inform the COR when the training has been completed. The notice shall include the contract number and any applicable task order number, names of contractor personnel who attended and dates of training.

6.1.7.6 The contractor shall immediately notify the COR of any government C4 system problems or issues which come to their attention which may impact the contractor's or the government's ability to access the systems.

6.1.7.7 All contractor personnel who require access to C4 systems are required to obtain a National Agency Check (NAC) consistent with Public Trust Positions (Standard Form 85P or most current form). The contractor may submit a request to the COR that the government grant contractor employee(s) interim access to the C4 network while awaiting the results of a NAC. Interim access to the C4 network will only be granted after the contractor employees obtain at least a local background files check, and have submitted the appropriate documentation to obtain a NAC. These requests will be processed in accordance with government information security regulations and policy, and must include Security Office and DAA Representative Approval. These requests may be subject to disapproval. In no case will a contractor be given access to the network, including a group account, until a favorable NAC has been completed or interim access granted by the DAA representative. Any interim accesses granted may be rescinded at any time by the PCO, COR, Directorate Security Office or DAA representative at the government’s discretion. Any individual who subsequently does not pass the requirements for a full NAC shall not be authorized to work under this effort.

7.0 ATTACHMENTS/MISCELLANEOUS INFORMATION

7.1 Environmental Controls. The contractor shall comply with all environmental requirements imposed by the Federal Government, the USAF, and at locations where services are being performed. Such requirements are delineated in USAF Policy Directive 32-70, “Environmental Quality”, and other laws and regulations.

7.2 Administrative Dismissal for Safety Reasons. The contractor will provide alternate work sites for personnel during local emergency situations when the Base Commander has declared an emergency and has stated personnel should not report to base or should leave the base during a workday. Local emergency conditions include inclement weather (i.e., snow, tornados, earthquakes, hurricanes, etc.). NOTE: Only the Base, AFOTEC or Site Commander can declare such an emergency (not a Government Director, Division Chief, Program Manager, COR, PCO, etc.).

7.3 Performance of Services during crisis declared by the President of the United States, the Secretary of Defense, or Overseas Combatant Commander. The performance of these services is not considered to be mission essential during time of crisis. Should a crisis be declared, the PCO or his/her representative will verbally advise the contractor of the revised requirements, followed by written direction.

7.4 Conflict of Interest. In accepting and performing the work required by this task order, and all amendments thereto, the contractor certifies that the requirements of clause AFFARS 5352.209-9000, Organizational Conflict of Interest (OCI) have been or will be adhered to.

The contractor must immediately bring any OCI issues to the attention of the PCO for a determination of whether a mitigation plan is required.

7.5 AFOTEC Safety Requirements. It is the contractor’s responsibility to ensure its employees and managers have a comprehensive understanding of and full compliance with Occupational Safety and Health Administration (OSHA) requirements. Detailed information is available on the OSHA website at http://www.osha.gov/desp/vpp/index.html.

8.0 CONTRACTOR FULL-TIME EQUIVALENT REPORTING ADDENDUM

Contractor Full-Time Equivalent reporting: The contractor shall report all contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for AFOTEC via a secure…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .