CSAIC_BCO_RFP_Amendment_3_30Jan17.docx
DOCX document 398 KB Posted
- Attached to
- Cyber Security and Information Systems Information Analysis Center (CSIAC) Basic Center Operations (BCO) Federal contract opportunity
- Solicitation number
- FA8075-16-R-0002
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CSIAC_BCO_RFP_Vendor_Questions_DTIC_Response_23_Jan_17.xlsx | XLSX spreadsheet | |
| CSAIC_BCO_RFP_Amendment_2_23Jan17.docx | DOCX document | |
| CSAIC_BCO_RFP_Amendment_1_19Jan17.docx | DOCX document | |
| CSIAC_BCO_RFP_Vendor_Questions_DTIC_Response_19_Jan_17.xlsx | XLSX spreadsheet | |
| CSIAC_BCO_RFP.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA8075-16-R-0002
FA8075-16-R-0002
SECTION SF 30 BLOCK 14 CONTINUATION PAGE
The following items are applicable to this modification:
1. The purpose of this Amendment is to revise the solicitation, and supporting documents, as reflected below.
| Section |
| Change |
| RFP, Section C,1.8.2 (2) |
| Revised the first sentence. Sentence is as follows: “The prime contractor or teaming partner shall possess a Top Secret Facility Clearance with a facility cleared to store classified (top secret) information, within 90 days of award.”. |
| RFP, Section L4.4.4 |
| Revised the second sentence. Sentence is as follows: “The Government will validate at time of proposal that the Offeror will possess a Facility Clearance and has a cleared facility authorized to store classified materials at the Top Secret level within 90 days of award.”. |
| RFP, Section M 3.2.3.2.5 |
| Revised the second sentence. Sentence is as follows: “The Government will validate at time of proposal that the Offeror will possess a Facility Clearance and has a cleared facility authorized to store classified materials at the Top Secret level within 90 days of award, via the Defense Security Service.”. |
1. The conformed RFP is embedded herein.
1. All other terms and conditions remain unchanged.
SUMMARY OF CHANGES
SECTION C - DESCRIPTIONS AND SPECIFICATIONS
The following have been modified:
PERFORMANCE WORK STATEMENT (PWS)
Cyber Security and Information Systems Information Analysis Center (CSIAC) Basic Center Operations (BCO)
Defense Technical Information Center (DTIC) Information Analysis Centers Program Management Office (DTIC-I)
TABLE OF CONTENTS
SECTION 1 DESCRIPTION OF SERVICES
| 1.1 | Introduction and Mission |
| 1.2 | Purpose and Scope |
| 1.3 | Contract Objectives/Contractor Responsibilities - General |
| 1.4 | Task Requirements |
| 1.5 | Service Charge System |
| 1.6 | Categories of User Services and Ordering Process |
| 1.7 | General Information/Administration |
| 1.8 | Security Requirements |
| 1.9 | Publishing Requirements |
| 1.10 | Unauthorized Representation |
| 1.11 | Contractor Identification Requirements and Performance of Work on Government Premises |
| 1.12 | Place of Performance |
| 1.13 | Personnel Qualifications |
| 1.14 | Limitations on Subcontracting |
SECTION 2 SERVICES SUMMARY (SS)
| 2.1 | Quality Control |
| 2.2 | Quality Assurance |
SECTION 3 GOVERNMENT-FURNISHED PROPERTY AND SERVICES
| 3.1 | General Information |
| 3.2 | Defense Property Accounting System |
| 3.3 | Documents |
SECTION 4 CONTRACTOR PHASE-IN AND PHASE-OUT/TRANSITION
| 4.1 | Definitions | |
| 4.2 | Phase-In – Introduction and Overview | |
| 4.3 | Phase-In – Specific Requirements | |
| 4.4 | Phase-Out – Introduction and Overview | |
| 4.5 | Phase-Out – Specific Requirements |
SECTION 5 APPENDICES
| 5.1 | CSIAC Contract Data Requirement Summary |
| 5.2 | Historical Workload Estimate |
| 5.3 | Acronyms |
| 5.4 | Glossary |
SECTION 1: DESCRIPTION OF SERVICES
1.1 INTRODUCTION AND MISSION
The Department of Defense (DoD) Information Analysis Center (IAC) Program operates in accordance with (IAW) DoD Manual 3200.14 Volume 1, “Principles and Operational Parameters of the DoD Scientific and Technical Information Program: General Processes”, Mar 14; and DoD Manual 3200.14 Volume 2, “Principles and Operational Parameters of the DoD Scientific and Technical Information Program: Information Analysis Centers (IACs)”, Jan 15
DoD IACs function as specialized subject focal points and centers of excellence, supplementing the Defense Technical Information Center (DTIC) services within DoD Directive 3200.12, “DoD Scientific and Technical Information (STI) Program (STIP)”, Aug 13.
The mission of the Cyber Security and Information Systems Information Analysis Center (CSIAC) is to perform the functions of a DoD IAC as described in DoD Manual 3200.14 in support of the vital technical areas delineated under paragraph 1.2 “Purpose and Scope” below. IACs are operated by contractors from industry and academia.
The IAC Program Management Office (PMO) aligned 21 technical focus areas critical to current defense needs into three technical domain areas. Each domain area has one BCO contract and one multiple award technical area task (MAC TAT) indefinite-delivery type contract vehicle that collectively provide IAC services for that domain. For the Cyber Security and Information Systems domain area, the predecessor CSIAC BCO contract was awarded in June, 2012 with an ordering period through 2017 as a single-award indefinite delivery/indefinite quantity (IDIQ) type contract. CSIAC's current MAC TAT counterpart, the multiple award, indefinite-delivery type contract vehicle for Cyber Security and Information Systems Technical Area Tasks (CS TATs) was awarded to sixteen contractors in December, 2015. In the future, the construct of one MAC TAT contract to one BCO contract may undergo change/consolidation into fewer than three MAC TAT contracts and the number of technical focus areas is subject to change as DoD’s Science and Technology (S&T) requirements evolve.
The interdependence between “Core” services and TATs is defined in DoD guidance -- DoD Instruction 3200.14 establishes IACs to provide Core and additional tasks. The BCO establishes a knowledge base in areas of strategic importance. The intent of TATs is to leverage the knowledge base to increase efficiency and effectiveness. BCOs serve as the foundation for TATs. The requirement described herein is for BCO services.
1.2 PURPOSE AND SCOPE
The purpose of this performance work statement is to define the mission, background, and period of performance with outcome based objectives and to define constraints applicable to the current and future environment. The scope of this contract encompasses BCO functions necessary to fulfill the mission and objectives applicable to the DoD RDT&E and Acquisition communities' needs in the technical focus areas listed below and fulfill the objectives of this contract. The contractor shall operate the BCO IAC for CSIAC. The list below is not all inclusive and may be expanded to include disciplines and subjects in related areas as new technologies emerge in the area of CSIAC’s scope.
STI is communicable knowledge or information resulting from or pertaining to the conduct and management of research and engineering efforts. STI is used by administrators, managers, scientists, engineers engaged in scientific and technological efforts, and is the basic intellectual resource for and result of such effort. Representative examples of the STI technical focus areas covered under this PWS are described below:
Software Data & Analysis is defined as the process of inspecting, cleaning, transforming, and modeling data with the goal of highlighting useful information, suggesting conclusions, and supporting decision making. The scope, as it relates to the DoD RDT&E communities‘ needs, includes the entire field of software technologies and engineering specifically as related to information, documentation, databases, model and architecture repositories, analysis, training, testing, data synthesis, hardware, software, standards, economic consideration of selection of techniques and processes, and interoperability. The contractor shall have technical familiarity to work with the following STI subject areas:
Installation, demonstration, test, validation and evaluation of new and existing software, tools, methods and software measurement technologies; evaluations of the quality of existing software systems and recommending improvements; needs and risk analyses of software packages (developmental, non-developmental and commercial off the shelf (COTS) relative to mission requirements; development, updating, and evaluation of software engineering standards, specifications, handbooks, or manuals; supporting the revision and development of military standards and specifications; verification and validation of solution sets and protocols; assisting user organizations with all aspects of software acquisition; development of life cycle cost models; and customization of software analytical tools, models, decision aids, screening methods and techniques used to evaluate and support the authenticity and continuity of DoD, national, commercial, and international information systems.
Cyber Security (CS) is defined as the technologies, processes, and practices designed for prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communication services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and non-repudiation. The term “Cyber Security” was previously known as Information Assurance, which is an element of Cyber Security and falls within this scope area. While focused dominantly on information in digital form, the full range of CS also encompasses analog and physical form. The scope is not limited to information security; it includes the entire field of CS (availability, identification and authentication, confidentiality, integrity, and non-repudiation) and includes the economic considerations with respect to selection of CS techniques, CS processes, and industry trends. It also includes Information Operations (IO), e.g. operational security of IT, the use of the electromagnetic spectrum for IT purposes and computer network operations. In a contested cyber environment, CS supports Mission Assurance (MA) measures required to accomplish mission essential objectives. CS support to MA entails prioritizing mission essential functions, mapping mission dependence on cyberspace, identifying cyber-related vulnerabilities, and mitigating risk of these vulnerabilities. The contractor shall have technical familiarity to work with the following STI subject areas:
Full spectrum cyber operations including 1) developing CS planning frameworks and development of requirements and mission needs documents and conducting trade-off analyses; 2) cyber threat avoidance; 3) defensive cyber operations (DCO) including red teaming and performing threat assessments; and 4) cyber offensive and exploitative operations. All of the above may include: cyber technology research, analysis and prototyping, cyber situational and mission awareness, cyber modeling, simulation and war gaming, integrating innovative cyber technologies to enable cyber superiority and the facilitation of technology transition.
Modeling and Simulation (M&S) is defined as the use of models, including emulators, prototypes, simulators, and stimulators, either statically or over time, to develop data as a basis for making managerial or technical decisions. The scope includes all classes of models and simulations, and may involve the interface of real-world systems (e.g., command and control systems, intelligence systems, weapon systems and components, sensors) with models or simulations, as well as working with model elements, standards and specifications, and modeling system descriptions, interfaces, and data communication methods. The contractor shall have technical familiarity to work with the following STI subject areas:
M&S subject matter expertise for supporting program reviews, strategic planning, exercise management, knowledge acquisition, and operations coordination and monitoring; providing support for DoD certification of compliance with High Level Architecture (HLA) for federates; evaluating and improving models and databases that support IA; the development and implementation of modeling and analysis tools for collaborative databases and data stores; applying M&S for evaluating the effectiveness of forces, systems, doctrines, tactics and plans in support of training, analysis and acquisition activities; evaluating M&S interoperability, reuse, capabilities and cost-effectiveness, particularly as fostered by the common technical framework; and supporting cross-domain coordination, configuration management, and military exercises and demonstrations.
Knowledge Management and Information Sharing. Knowledge management (KM) is defined as the analysis and technical support of practices used in an organization to identify, create, represent, distribute, conduct and enable the adoption and leveraging of good practices embedded in collaborative settings and, in particular, in organizational processes. Information Sharing (IS) is defined as data exchange, communication protocols and technological infrastructures. It includes standardization of information, as well as the human functions involved in the semantic, pragmatic and social levels of organizational semiotics. The two areas of KM and IS are intertwined as information sharing is the foundation for knowledge management. The contractor shall have technical familiarity to work with the following STI subject areas:
Expertise in working with comprehensive collections of empirical data on the development, operation, and maintenance of software systems; analysis of this data (data may be from new or existing sources) – this includes data analytics (data to decisions); supporting the development, delivery and/or evaluation of training (including classroom, computer-based-instruction, videotape, distance learning, and other forms of instruction); expertise in advanced collaborative analysis tools that allow for the integration of existing and in-process social networking and intelligence data exploitation tools; and supporting the evaluation, development and implementation of a wide variety of intelligence and collaboration systems including Global Net Centric Systems. This subject area could involve system engineering and integration, software engineering and software technology, R&D transition, and network and communication engineering, development and deployment.
DoD IAC PROGRAM LINKS
| DoD IACs: | IAC : Information Analysis Centers | ||
| CSIAC: | https://www.csiac.org/ | ||
| CS TATs: | http://iac.dtic.mil/cstat.html | ||
| DoD Directive 3200.12: | http://www.dtic.mil/whs/directives/corres/pdf/320012p.pdf |
DoD Instruction 3200.14 Volume 1: http://www.dtic.mil/whs/directives/corres/pdf/320014vol1_2014.pdf DoD Instruction 3200.14
| Volume 2: | http://www.dtic.mil/whs/directives/corres/pdf/320014vol2.pdf | |
| ASD (R&E): | http://www.acq.osd.mil/chieftechnologist/ | |
| DTIC: | http://www.dtic.mil/dtic/ |
1.3 CONTRACT OBJECTIVES/CONTRACTOR RESPONSIBILITIES -- GENERAL
1.3.1 Objectives
The purpose of this contract is to leverage the best expertise from industry, other Government agencies, and academia to solve the government’s toughest scientific and technical problems and enhance the knowledge bases of those communities across the entire spectrum of the Defense Systems domain. IACs serve as a ready tool for strategic, operational and tactical organizations within DoD and the broader community to understand and apply new technologies and emerging threat trends. CSIAC shall take the lead in disseminating Cyber Security and Information Systems (CS)-related STI to stakeholders throughout DoD, reducing duplication of effort, both in terms of avoiding the creation of duplicate holdings of STI as well as duplicate analytical capabilities among various R&D support components. CSIAC shall build a community of subject matter experts (SMEs) and provide long-term STI corporate memory for the DoD and enable DoD to avoid the creation of duplicate holdings of STI, as well as duplicate analytical capabilities in various R&D support components. Principal objectives of this contract include:
| – | Investing up-front resources for discovering and covering areas of strategic and tactical importance | |
| − | Keeping abreast of current and emerging areas of DoD STI by collaborating with scientists and other SMEs around the globe including the Unified Combatant Commands, Defense research laboratories, other DoD entities, U.S. Intelligence organizations, as well as engineers, technologists, and other experts from various non DoD government organizations (Department of State, OMB, DHS, FBI, etc.), and private industry | |
| − | Maintaining awareness, relevance, and value to emerging issues | |
| − | Combating and enabling military strategic surprise by conducting trend analyses and capacity building | |
| − | Enabling rapid response to existing and emerging threats through proactive knowledge development | |
| – | Maintaining and expanding DoD’s Scientific and Technical Information (STI) repository | |
| – | Developing IAC products / responses to technical inquiries | |
| – | Developing and maintaining a subject matter expert (SME) network and building a community of experts and stakeholders across government, industry, and academia in all scope areas and yet-to-be identified subjects falling within the contract focus areas | |
| − | Integrating knowledge bases and customer-funded work to provide increased value in a time of shrinking budgets and growing requirements | |
| − | Providing tactical relevance by responding to an immediate need | |
| − | Developing strategic capabilities by analyzing trends and recommending improvements to the | |
| acquisition community | ||
| − | Increasing the productivity of the DoD Research, Development, Test, and Evaluation (RDT&E) community, as well as other scientific and engineering groups | |
| − | Facilitating the use of CSIAC STI | |
| − | Transferring CSIAC technology information within the U.S. Government and from the U.S. Government to authorized customers; and | |
| − | Promoting standardization within the field of CS and information systems, for example, by providing in-depth analysis, creating products, responding to technical inquiries, performing technology assessments, and supporting exchanges of information among Scientists, Engineers, and practitioners of various disciplines |
1.3.2 Contractor Responsibilities – General.
The contractor shall operate the IAC in accordance with all directives, instructions, regulations, and military standards listed in the contract, Section J, Attachment 1. The services to be provided apply performance- based principles (FAR 37.6) to deliver research and development (R&D) and/or R&D related advisory and assistance services and all task orders will result in the creation of specific identified deliverables. The contractor is not authorized to perform personal services as defined at FAR 37.101, or inherently governmental functions as defined at FAR 7.5 at any time under this contract. This contract is an indefinite delivery/indefinite quantity type contract. All services, whether performed under the BCO/BCO option contract line items (CLINs), Phase-In/Phase-Out/Transition CLINs, the Data CLIN, the Core Analysis Task (CAT)/Extended Technical Inquiry Services Task Order CLIN, or Extension of Services CLINs, will be procured and funded through the issuance of task orders (TOs). The only exception is purchases of services described in this PWS made directly by customers, through separate credit card transactions or purchase orders. These purchases are “Other than DTIC Funded Products and Services” (see para. 1.5.1.2.2) and are not orders against this contract. It is anticipated that all the BCO (aka “core”) services will be procured one-two years at a time under one dedicated annual TO, with multiple periods of performance, however it is possible that the BCO core services will be procured for incremental periods of less than one year in a series of BCO TOs (for example four quarterly TOs or two semi-annual TOs). CATs will be up to a one year period of performance (see section 1.6).
The IAC contractor shall undertake a variety of activities focusing on the collection (including identification and access), analysis, synthesizing/processing, and dissemination of STI. These four terms are further explained and elaborated upon below under paragraph 1.4, “Task Requirements”. The contractor’s activities shall cover all aspects of identified or potential military and national security-related applications of CSIAC technology. The contractor shall provide timely and authoritative information relative to key R&D concepts and acquisition functions, results and trends, applications and processes, assessments of CSIAC technology on military operations, and assessment of international R&D technology. Delivery of such information shall be undertaken in both a proactive as well as responsive manner. PWS Appendix 5.2 provides estimates of historical workload for several primary types of services provided by the incumbent BCO (CSIAC) contractor.
Information collection, analysis, synthesis/processing, and dissemination efforts should facilitate use of existing STI, while reducing unnecessary duplication of research, information collection and analysis, and information dissemination efforts. The IAC contractor shall integrate output from CATs that it performs under this contract, as well as output from TATs performed under the TAT contracts, to re-use STI. The contractor shall collaborate extensively with the IAC multiple award contract/technical area task (aka MAC TAT) contractors who are conducting TAT analyses in the same or relevant IAC subject areas.
CSIAC shall accomplish the contract objectives through the development and maintenance of anticipatory marketing of IAC products and services to STI users in Government, industry, and academia, as well as decision and policy makers in the acquisition community. CSIAC shall identify and seek out opportunities to provide CSIAC STI to DoD components, other U.S. Government agencies and departments, their contractors, and other authorized recipients of CSIAC STI. The contractor shall capture the most significant Success Stories that it achieves in performing this PWS in the IAC Quarterly Success Stories Deliverable (CDRL A016).
The contractor’s expertise shall cover:
1. Basic and applied RDT&E activities carried out by DoD components, other U.S. Government agencies and departments and their contractors, state and local governments, as well as international organizations in which the U.S. Government is a member or participant;
1. Military and other related or similar operations conducted by DoD components and other U.S. Government agencies and departments or international organizations to which the United States belongs or foreign governments with which the United States has international agreements for military or related operations;
1. Development of doctrine, tactics or plans by DoD components, other Government Agencies and Departments, their contractors, and foreign military organizations that the Department of Defense provides military assistance and sales;
1. Basic and applied research carried out by industry, academia, and other institutions where the results of such research are expected to provide benefits to the U.S. Government in the future.
To avoid the potential for an organizational conflict of interest, the CSIAC BCO prime contractor will be restricted from being a prime or a subcontractor on the Cyber Security and Information Systems Technical Area Tasks (CS TAT) and, if awarded a contract as prime or subcontractor on the Information Analysis Center Multiple Award Contract (IAC MAC) Technical Area Task Indefinite Delivery Indefinite Quantity contract, will be precluded from proposing/performing on individual technical area tasks that are determined to fall under the scope of CSIAC.
1.4 TASK REQUIREMENTS
1.4.1 Collection and Storage
1.4.1.1 General. The contractor shall monitor and extract CSIAC technology- related STI from worldwide engineering, technical, and scientific information, including documents, databases, and electronic, paper, and other media. The contractor shall ensure maximum use of the resources of other DoD IACs. Key processes in this area include employing technology and innovative techniques, utilizing personnel experienced in research analysis and synthesis, maintaining awareness through participation in conferences, symposia, workshops and engineering and scientific community coordination. The contractor shall review and evaluate STI for relevance and accuracy. Outputs consist of information awareness products, databases, the IAC website and evaluated STI.
The contractor is required to interface with the TAT contractors in their related IAC area when relevant to efforts performed under this contract, and fully utilize relevant TAT STI contributions. TAT contributions consist of gathering, evaluating and producing STI during performance of a TAT.
1.4.1.2 Sources: In order to perform work specified herein, the contractor shall utilize information resources of the current incumbent CSIAC contractor; technology information collected by the contractor’s staff; information furnished to the CSIAC by the U.S. Government and/or its contractors; and any additionally available (foreign or domestic) CSIAC information. The contractor shall obtain information from DoD staff elements, laboratories and agencies with competence in the fields of science and technology which this center addresses. The contractor shall search and extract information from resources and collections rather than trying to duplicate them.
Collection and use of unclassified, unclassified but limited distribution, and classified (foreign and domestic) information in the performance of this PWS is authorized as long as all security regulations and restrictions are adhered to.
1.4.1.3 Collection Activities: The contractor shall employ techniques and technology to monitor and extract STI and engineering data from current and historical sources across government, industry, and academia, utilizing a core staff of technical experts (i.e., scientists, engineers, information specialists, etc.), related to CSIAC technical focus areas. Additionally, in acquiring the source information, the contractor shall utilize personnel experienced in research, analysis and synthesis of technical literature and advanced STI management procedures for evaluation that will ensure the highest possible access and identification of emerging technology STI for the CSIAC user community's benefit.
1.4.1.4 Storage: The contractor shall store paper, microfiche, microfilm, and electronic media under conditions necessary and sufficient to ensure that information contained in the media shall remain accessible to the Government during the period of performance of this contract. All CSIAC holdings within the repository are unclassified and are in English or have been translated into English. The figures below provide a summary of the current holdings of the CSIAC repositories and the estimated quantities of items in each category as of solicitation issuance.
The contractor shall maintain an electronic archive of all information displayed on its CSIAC website. This archived information shall be returned to the Government at the completion of the contract or otherwise disposed/transferred as directed by the Contracting Officer.
| BCO Core Holdings |
| Current Holdings (as of Sept. 2016) |
Estimated Numbers
| Books |
| 492 |
| VHS Video Tapes |
| 321 |
| Compact Disks |
| 126 |
| Hardcopy Technical Reports |
| 3,952 |
| Hardcopy Technical Journals |
| 1,825 |
1.4.1.5 DTIC Online (STI Repository): This is DTIC's master repository of digital STI. The DTIC Online STI database provides for total electronic collection and dissemination capabilities of STI within the IAC Program. The DTIC Online database contains both metadata and full text searchable documents. There is one metadata record per document. In coordination with IAC Program Management Office (PMO), the contractor shall provide input into the DTIC Online database, consisting of STI documents and citation/metadata. The contractor will be provided with access to the web based IAC STI document processing interface for the DTIC database for uploading STI. Before uploading any STI, regardless of source, the BCO contractor shall perform a quality check to ensure it meets DTIC-provided quality standards for DTIC Online.
1.4.1.6 Scanning and Uploading: The current CSIAC contractor has been scanning and uploading STI into DTIC Online throughout the term of their contract. Materials, both digital and hardcopy, that have been uploaded into DTIC Online will not transfer from the incumbent CSIAC contractor. The contractor shall continuously identify STI eligible for uploading into DTIC Online and shall also process STI received from the IAC MAC TAT contractors when that STI has a primary subject matter that falls within the scope of CSIAC. For STI identified for uploading by CSIAC, CSIAC shall, if needed, scan the document (most documents processed will already be in electronic format), convert into PDF format, OCR, index, and upload it. Once documents are digitized and entered into DTIC Online, the contractor is authorized to destroy any hardcopy or duplicate electronic documents. Targeted documents for uploading into DTIC Online are high demand documents, leveraged for technical inquires that are tied to DoD technology needs for today and the foreseeable future years. For STI that has been produced by a MAC TAT contractor, CSIAC is responsible for performing a quality check and submitting it into DTIC Online via the IAC STI document processing system.
The contractor shall utilize this system to provide rapid collection and dissemination capabilities. Note for classified records, regardless of whether the source is CSIAC or a MAC TAT contractor, the transmission procedure requires the CSIAC contractor to burn the data to media which is then mailed to DTIC by registered mail.
CSIAC shall perform a quality check of all STI documents approved by DTIC for submittal to DTIC Online regardless of whether the STI source is the BCO or a MAC TAT contractor. The quality check shall be completed upon approval from the ACOR for submitting the STI. As part of the quality check, the contractor shall correct all minor discrepancies/irregularities in the STI that it can resolve independently (for example, marking ambiguities, page numbering or citation issues, etc.) and also shall ensure it is bona fide STI. For STI received from a MAC TAT contractor, if there are problems that the CSIAC contractor cannot resolve, it shall promptly refer the STI in question, along with an identification of the problem, to the MAC TAT contractor for correction. STI submittal problems that cannot be promptly resolved by the BCO or MAC TAT contractor shall be referred by the BCO contractor to the DTIC-I point of contact for DTIC Online, or the CSIAC COR. In no case shall the BCO contractor hold STI approved for submittal to DTIC Online, for more than two weeks, without taking progressive steps as needed to resolve any problems with the document.
1.4.1.7 CSIAC Libraries. The contractor shall maintain and expand the library collections (both hardcopy/physical and digital) of STI materials such as reports, videos, audio-recordings, studies and analyses, not suitable for upload to DTIC Online, consisting of information in various classifications (unclassified, FOUO, Secret and Top Secret). The CSIAC libraries shall provide a CSIAC technology community-wide system for facilitating the reuse of CSIAC technology STI resources. Any substantive change in the types of libraries maintained shall be made by the contractor only when properly authorized. Libraries maintained by CSIAC include:
| a) Hardcopy Subscriptions | e) Briefing charts | ||
| b) Subject Matter Books | f) Access to On-line Services | ||
| c) Vendor Product Material (Hardcopies) | g) Policy Directives | ||
| d) Citation References | h) DoD Publications |
A database within the library shall contain the following items and other data as the contractor deems appropriate:
| a) CSIAC Tool Library | d) CSIAC Centralized Document Repository | ||
| b) INFOSEC Library | e) Product Vulnerability Information | ||
| c) Vendor Product Information Library |
1.4.1.8 Additional Libraries and Databases: The Government does not have any requirements for the contractor to develop or maintain any specific additional databases and libraries other than those listed herein. The contractor shall create and maintain whatever additional databases and libraries it deems necessary to optimally perform this contract and in accordance with the technical approach set forth in its accepted proposal. This information is provided for background purposes only; it is not intended to establish a mandatory or optimal requirement. The details as to whether any or all of these records may be transferred to the new CSIAC contractor will be determined by the incumbent CSIAC and the successor CSIAC contractor during the transition-in period.(A012).
Information contained in each library or database may contain information at different levels of classification up to TOP SECRET, therefore it is expected that they may reside in separate libraries.
The table below provides information on the current size of the CSIAC facility devoted to the libraries and server room.
| Square Footage |
| Current |
| Library |
| 1600 |
Server Room Current Computer Storage Footprint
1.4.2 Dissemination, Training, and Awareness
1.4.2.1 General: The contractor shall be responsible for dissemination of CSIAC STI in the form of products and services. Dissemination takes the form of STI production and distribution such as the Journal, models and simulations, and other products; briefings, conference presentations; training/webinars; research and analysis responses to user inquiries, and IAC service promotion. The contractor shall draw on library holdings and other databases and all available STI and relevant subject matter expertise when developing and disseminating information to the CSIAC S&T community.
1.4.2.2 Products: One of the means of satisfying user needs for authoritative information directly applicable to their ongoing work is through the design, preparation and maintenance of STI products. The contractor shall provide information products to other U.S. Government organizations, their contractors, and other approved, DTIC authorized users within available physical, information, and financial resources in accordance with all applicable DoD Regulations, Directives, Instructions, and Policies with respect to the dissemination of STI. The contractor is not authorized to promote or sell the products of third-party sources. The contractor’s information outputs may take the form of standards, reports, guidebooks, technology benchmarks, handbooks, manuals and data sets; lists of technical experts; critical reviews, alternative technology analyses; technology assessments; state-of-the-art (SOAR) reports; models, analytical tools and techniques; and other specialized STI products (CDRLs A003, A005, A010).
Handbook, databases, data books, and web-based technical reports shall be presented to the COR who must pre-approve them before publication/dissemination.
The contractor shall potentially develop the following new products for CSIAC:
| Product Types |
| CSIAC Products |
| Reports and Guidebooks |
| 1) Securing Systems through Software Reliability Engineering |
2) Security Testing and Evaluation Guidebook
3) Supply Chain Risk Management
4) Penetration Testing
5) Return on Investment of M&S
6) Securing Real Time Systems
7) Ontological Analysis of M&S Component Disciplines
8) Cost Estimation of Cyber Assurance and Information Systems
| Web/Free Resources |
| 9) Series in Cyber Security tools: Examples include Intrusion Detection Tools, Software Assurance Tools, Security Risk Analysis Tools |
10) DIACAP for M&S Guide
| Collaborative/Community Based Products |
| 11) M&S Body of Knowledge |
12) Cost Estimation Benchmarks
13) Others, as suggested by the Community
In developing these products, the Community of Practice (CoP) will be used to gauge product interest, identify other supporting STI, and dissemination of product announcements.
One of the objectives of CSIAC operations is to encourage use of existing CSIAC information throughout the DoD and DoD-related CSIAC community to minimize unnecessary duplication of effort. The contractor shall propose additional current awareness products in addition to those specified above, and/or dissemination techniques to expand use of existing CSIAC information resources. Each product must be reviewed and pre-approved by the COR and the IAC PMO (and DTIC public affairs) before publication/dissemination. The contractor shall propose methods to produce current awareness products in task orders during the contract period (CDRL A003).
1.4.2.3 Training, Presentations and Conferences: The contractor shall aggressively develop a classroom and web-based training program targeted towards the needs of CSIAC users. This may include informal briefings and presentations. The contractor is responsible for sponsoring, planning agendas for, and speaking and/or providing training at major technical conferences, meetings, symposia, or workshops. The contractor shall make optimum use of computer technology to store, sort, select, package, and disseminate data and information.
Course topics and handouts shall be approved by the COR. Training authorized on this contract shall serve to disseminate information to the CSIAC scientific and technical community that is relevant to the CSIAC research and development subject areas described herein. This does not include "how/to" classes/tutorials for users or administrators on existing systems, applications, products or techniques, whether the systems/products/techniques are commercial off-the-shelf or non-developmental; such training is not authorized under the scope of the CSIAC contract. (CDRL A010).
All web based courses will be integrated into the CSIAC CoP. A sample of potential course offerings are listed below.
| CSIAC Technical Area |
| Training Courses |
| Cyber Security |
| (1) Hacking and Penetration Testing; (2) In-depth Malicious Code Analysis and Classification; (3) Law and Policy of Cyber Conflict; (4) Information Security Management/Officer-CISSP® Master Class; (5) Wireless Network Security; (6) Securing the Cloud |
| Modeling & Simulation |
| (1) Program Manager’s Course on M&S; (2)Principals of Simulation Interoperability; (3) M&S and DIACAP: Getting to an ATO; (4) Simulation Architectures; (5) Enterprise investment approach to M&S |
| Software Intensive Systems Engineering, Software Assurance & Technology |
| (1) Software Assurance Awareness; (2) Building Security into the Software Development Life Cycle; (3) Software Quality and Security |
| Knowledge Management |
| (1) Introduction to Data Mining; (2) Introduction to Knowledge Management & Discovery |
| All Areas |
| (1) Introduction to Risk Management ; (2) Video Podcasts - Web based SME dissemination of issues (15 minutes, twice per month) via podcasts |
The contractor shall host and present at least one free webinar per month on topics of high interest to the CSIAC community.
1.4.2.4 Awareness. The contractor shall maintain affiliations, associations, and specific involvement in and with the Defense research, development, testing and engineering community, to include other DoD Communities of Interest (COI), Federal Agencies, contractors, educational organizations, technical societies, State and local governments and foreign governments, sufficient to hold a well- established presence in that community. The contractor shall leverage these interactions to (1) support and promote exchanges of information among scientists, engineers, and practitioners, including awareness of historical and on-going research, (2) identify current and future technical information needs, including gaps in the knowledge base, and (3) provide a ready pool of reach-back subject matter experts to provide further technical information and analysis, related to the CSIAC subject areas. The contractor shall participate in professional/technical activities every year, sponsored by national and international CSIAC-related organization and related societies and associations. The purpose of such participation shall be to identify both defense related as well as national CSIAC technology needs and priorities, to collect related information, to develop consensus on information assessment and evaluation techniques and to disseminate CSIAC information.
The contractor shall emphasize user service by anticipating and responding to customers’ needs. Anticipation of CSIAC user information needs shall result from continuing awareness and analysis of the social, political, and technical contexts influencing the course and direction of scientific, technical and operational disciplines or domains which define or influence the needs of the user community.
1.4.2.5 Conferences, Symposia, Workshops, and other Meetings
In order to respond to Government requirements, IACs engage in the collection, analysis, synthesis and dissemination of information. The contractor shall provide technical input to support scientific, technical, and DoD-related CSIAC conferences, symposia, workshops, and other meetings. These functions shall include providing technical coordination and information services required to support and host the meetings of the CSIAC Executive Steering Committee (when held) and Program Review (once a year). Activities planned and accomplished under this task shall be captured under Contract Data Requirements List (CDRL) deliverables A007, A008, A009 and A010.
In preparation for the conferences, symposia, workshops, and other meetings, the contractor shall also prepare and disseminate acceptance/rejection letters to respective authors; and collect, edit, publish and distribute manuscripts, papers and proceedings. Use of conferences, symposia, and workshops and other information collection, analysis, and dissemination as part of basic CSIAC operations are authorized when approved in advance by the Contracting Officer’s Representative (COR).
1.4.2.6 Internet/Website
CSIAC is a user of and contributor to the Internet/World Wide Web (WWW). CSIAC shall become familiar with and knowledgeable about multiple networks at various classification levels for use in collecting and disseminating information to the CSIAC user community. The contractor shall publish and disseminate information with multiple Internet tools and resources including Hypertext Markup Language (HTML), various search engines and tools, File Transfer Protocol (FTP), Extensive Markup Language (XML), and World Wide Web (WWW). The contractor shall develop/maintain an internet home page website for CSIAC within 60 days from award of contract with related collaboration areas for CSIAC groups, which shall at a minimum contain information about CSIAC, as well as content of interest to the CSIAC user community, to include: journals and publications, calendar of events, databases, other IAC products such as State of the Art Reports (SOARs),web-based technical reports, handbooks, databases and Critical Reviews and Technology Assessments. All information from non-federal entities posted on the website will be clearly identified as information intended to advance the IAC objective of helping the community of technologists from the Government, academia, and private industry maintain awareness of opportunities to interact and collaborate. The website shall make clear that the presence of this information does not constitute endorsement by the United States Department of Defense of any non-federal entity or event sponsored by a non-federal entity. The contractor shall maintain, update and provide continuing support for the Internet resources and tools in order to ensure reliable information for its user community. The CSIAC website shall be designed and maintained to maximize its useful and relevance to the CSIAC community. The contractor shall build an interactive CSIAC Community of Practice. (CDRL A001).
1.4.2.7. CSIAC Journal (Newsletter): The term “newsletter” and “journal” as used in this contract refer to the same deliverable. The contractor shall draft and distribute a journal to approximately 12,548 hardcopy and 12,170 electronic recipients. This information is provided for historical background purposes only.
The contractor shall publish a quarterly Journal/Newsletter. Each of the PWS technical focus areas of CSIAC will be highlighted in at least one issue per year.
Journal articles shall be written for a DoD technical subject matter expert audience in mind and shall emphasize technical aspects rather than operational, strategic, or personal ones. The journal(s) shall contain the following, among other things: synopses and critiques of significant, newly acquired reports and/or journal articles; summaries of the initiation of new R&D programs; summaries of significant technological breakthroughs and significant new technological applications and highlights of any other outstanding developments. News from various DoD CSIAC programs that would be of interest to other DoD organizations should be included. The contractor shall develop, update, and maintain a journal mailing list on a continual basis. The journal shall be available electronically and/or printed or otherwise made available), to addressees on the list. Precautions shall be taken to ensure that no classified or restricted distribution material is included in these journals. The contractor shall take all measures in accordance with DoD Issuances Affecting Operation of the CSIAC (Section J, Attachment 2) to ensure that no unauthorized disclosure of controlled information occurs. Each journal shall be submitted, in draft form, for COR (and security) review and approval, at least one month prior to anticipated distribution. The contractor may accept paid advertising after prepublication review and with COR authorization. Payments from advertisements will be treated as a form of revenue from the sale of products and services and will be net billed to the Government. An explicit disclaimer statement shall be included in the journal stating that the appearance of an advertisement in the journal does not constitute endorsement by the DoD or the IAC (See DoDI 5120.4). (CDRL A004).
1.4.2.8. Distribution: The contractor shall disseminate CSIAC STI to users and potential users in paper, electronic, and other media. In receipt, holding and disseminating STI, the contractor shall adhere to the current version requirements of DoD Instruction 8520.03 "Identity Authentication for Information Systems" and 5200.01 "DoD Information Security Program". TAT contractor STI contributions include preparing Weekly Activity Reports for the IAC PMO, highlighting key achievements of TATS, other STI deliverables produced in the performance of TATs, and may include contribution of articles and other summaries of successes to highlight TAT work in IAC publications. The CSIAC STI distribution listserve is currently at 45,808 electronic addressees, as of April, 2016 (excludes Newsletter/Journal distribution).
1.4.3 Analysis, Synthesis, and Research
1.4.3.1 General: The contractor shall be responsible for analyzing, synthesizing and researching CSIAC STI and other relevant current scientific and technical information through the use of worldwide-available technology information resources, data and records maintained by the contractor through its databases and digital libraries, and DTIC STI.
The contractor shall leverage an understanding of data in the context of operations, conduct trend analyses, and build on data to produce knowledge that improves operations. The contractor shall ensure free use and access of data between all IAC BCO and multiple award TAT contractors in support of the IAC program.
1.4.3.2 Interface with TAT contractors: In anticipation of and in response to technical inquiries, BCO services, and core analysis tasks, the contractor shall analyze STI to create and distribute STI products and offer STI technical advisory services. In providing analytical and technical support, the contractor will attempt to fill the gaps identified in the knowledge base by (1) creating the missing information through analysis of available STI, or (2) researching available STI to support applied and basic research programs. The contractor shall serve as a gateway to information resources and collections in the CSIAC field and shall search and extract information from all available resources and collections. The contractor is required to interface with the TAT contractors for their related IAC area and fully utilize TAT STI contributions. TAT contractors contribute by conducting detailed analyses of STI and may identify new areas requiring a detailed knowledge base. Analysis outputs consist of reports, databases, handbooks, models, simulations, inquiry responses and new/improved tools and techniques.
1.4.3.3. CAT/TAT STI Relevance Assessment (Literature Searches) and Gap Analysis: Additionally, the contractor shall conduct STI literature searches/analyses for new TATs and CATs. For TATs, CSIAC shall interface with the TATs contractors in the CS and information systems domain. Literature searches will be accomplished at the request of the CS TAT’s (or successor contract’s) COR to assist the COR in reviewing new incoming TATs requirements. These searches shall be conducted during the TAT pre-award /requirements planning stage using DTIC STI databases and other resources deemed relevant by the CSIAC contractor, and will be focused on identifying existing STI that will shape the requirements and technical approach of the TAT. For CATs, the contractor shall prepare an annual summary of STI used in performance of the CAT. Costs incurred with producing this deliverable shall be charged to the BCO task order for TATs and to the sponsoring requiring activity for CATs. See Section J, Exhibit J-9_Literature Search and Gap Analysis and CDRL A019, for instructions applicable to the literature search. For purposes of providing historical information, the charts below depict the number of active TATs in place as of 23 May 2016 for CS TATs and the predecessor contract to CS TATs, the Software, Network, Information, Modeling and Simulation (SNIM) contract vehicle. TATs typically have a three to five year period of performance. Historically, approximately 10 new TATs have been awarded each year under SNIM (the CS TATs vehicle is too new to forecast whether that pattern will continue). The number of active TATs is a snapshot estimate of the typical number that are active at any one time, and could be higher or lower in the future. The typical number, period of performance and dollar value of TATs to be issued under the CS TATs contract vehicle is unknown. (CDRL A019)
ACTIVE…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .