Attachment No. 2 Draft Statement of Scope.doc

DOC document 82 KB Posted

Attached to
INTEGRATED TARGETING AUTOMATION CAPABILITY Federal contract opportunity
Solicitation number
FA8750-10-R-0001
Issued by
Department of the Air Force Materiel Command Research Laboratory

About this file

Attachment 2 - Draft Statement of Scope

View the file

Other files for this federal contract opportunity

Other files attached to INTEGRATED TARGETING AUTOMATION CAPABILITY, newest first.
File Type Posted
Attachment No. 10 Past Performance Survey.doc DOC document
Attachment No. 8 List of Registered Parties.doc DOC document
Attachment No. 6 Labor Category Qualifications.doc DOC document
Attachment No. 9 Cross Reference Matrix.doc DOC document
Attachment No. 3 Anticipated CDRL.doc DOC document
Attachment No. 1 Draft DD254.pdf PDF
Attachment No. 12 ID and Assertion.doc DOC document
Draft RFP FA8750-10-R-0001.pdf PDF
Attachment No. 11 List of GFP.pdf PDF
Attachment No. 7 Technical Read Library.doc DOC document
Attachment No. 5 Draft Order 0002.pdf PDF
Draft RFP Cover Letter.pdf PDF
Attachment No. 4 Draft Order 0001.pdf PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

E-0-1259

AIR FORCE RESEARCH LABORATORY

ROME RESEARCH SITE

ROME NEW YORK

STATEMENT OF SCOPE

FOR

INTEGRATED TARGETING AUTOMATION CAPABILITY (ITAC)

PCSN. E-0-1259

2 FEBRUARY 2010

(Contract Number FA8750-10-R-0001)

TABLE OF CONTENTS

Paragraph
Subject
Page
1.0
Objective
3
2.0
Scope
3
3.0
Background
4
4.0
Technical Requirements
6

1.0

OBJECTIVE

1.1 The objective of this effort is to deliver joint targeting software with enhanced functionality that fully automates all needed targeting capabilities including support to all elements of the joint targeting cycle and to time-critical and time-sensitive targeting operations. The effort will supply enhanced versions of the joint targeting software, which will include: improvements to the current targeting functionality and performance, making it more responsive to operational needs; and an upgraded suite of applications that will be periodically updated with new versions of Commercial-Off-The-Shelf (COTS) and newly developed (Government-Off-The-Shelf (GOTS)) software. Delivery of the enhanced software will require the Contractor to support integration testing with various operating environments (Department of Defense Intelligence Information System (DoDIIS), Theater Battle Management Core Systems (TBMCS), Joint Digital Intelligence Support System (JDISS), Global Command and Control System-Joint (GCCS-J), GCCS-Maritime (M), GCCS Integrated Intelligence and Imagery (I3), GCCS-Air Force (GCCS-AF), Modernized Integrated Database (MIDB), etc.), and respond to user mission needs concerning the initialization, operation, and management of the supported suite of applications.

2.0

SCOPE

2.1 The scope of this effort includes the requirements analysis, research, design, enhancement, development, testing, integration, modification, maintenance and delivery of joint targeting software (approximately one release every year with several patches between each release) for integration into the GCCS family of systems, to include computer software, technical documentation, and, as required, installation and maintenance of the current systems located at existing intelligence sites worldwide.

2.2 This effort will result in software applications capable of being integrated into any intelligence or command center and providing immediate operational utility. This capability will interface to existing intelligence, operations, weather, logistics, execution, planning and communication systems/databases.

2.3 This program will extend the targeting capability to support the full range of military service and Joint targeting functions including detailed target analysis, target data base maintenance, comprehensive weaponeering, intelligence collection request support, and Combat Assessment. An enhanced Human-Machine Interface (HMI) will provide user friendly, efficient Command and Control (C2) of, and communication with, the new upgraded application functions.

2.4 This program will also provide for the research, development, enhancement, integration, and maintenance of other intelligence and targeting systems as may be required to support the nation’s strategic and tactical capabilities.

3.0

BACKGROUND

3.1 The increasing tempo of modern warfare dictates that all-source information be more efficiently and effectively exploited to achieve more timely operational planning, coordination, and control. The Air Force Research Laboratory, in conjunction with the AF A2 (Air Staff), Intelligence Surveillance and Reconnaissance (ISR) Agency Detachment 2, and the Joint Targeting Automation Steering Group (JTASG), has been investigating techniques over the last two decades to improve the effective utilization of the large body of data and information available to operational commanders. In particular, the use of advanced decision aiding technologies such as artificial intelligence, decision analysis, situation templating, and operations research is required to provide more robust and comprehensive force employment recommendations. These have been identified as high priority requirements for incorporation into the joint commander's emerging Command, Control, Communications, Computers and Intelligence (C4I) support systems. Timely and accurate Order of Battle (OB) production and maintenance, target material exploitation, mission planning material distribution and target development have been identified as the critical links between intelligence analysis and operational employment of weapon systems.

3.2 Targeting is the process through which commander's objectives and guidance are analyzed, identified targets are selected for attack, desired effects are determined based upon the specific situation and campaign goals, and appropriate individual targets and target aim points are selected. Targeting can consider fixed strategic facilities such as national leadership, manufacturing, transportation systems, and electrical power generation; Offensive Counter Air (OCA) targets including airfields; interdiction targets such as bridges, rail yards, and line of communication choke points, early warning radar and Surface-to-Air Missiles (SAMs); and mobile targets including columns of armored vehicles, field artillery, troops in the field, and surface-to-surface missiles. The targeting process involves not only a stated mission, force posture, and capabilities, but final plans, Concepts of Operation (CONOPS), Rules Of Engagement (ROE), enemy threat, and target intelligence. Effective targeting takes the intelligence-derived knowledge of enemy capability, intent, and current disposition, predicts his future actions and locations, identifies key facilities, sites, entities and/or units to attack, and provides operational planners with the what, where, when, and why to attack. All that remains is the how. With the proper intelligence, the operational staff can then effectively plan the employment of air assets against specific critical physical facilities of target system infrastructures to meet stated campaign objectives. OB production and maintenance is the process through which the community analyzes information about enemy forces and infrastructure to provide the basis to support national and theater commander’s analysis of objectives within guidance to support Courses of Action (COA) development in support of decision makers and to reflect the results of actions taken by friendly and enemy forces upon that basis of intelligence data.

3.3 Under a series of Air Force Research Laboratory contracts, the current operational suites of automated software were developed to serve as the National OB production system and the Joint standard targeting system. The baselines have been designed to access selected intelligence and operational data bases to provide rationally chosen, situationally-prioritized, support to the Regional Support Centers (RSCs), COCOMs, and Joint Forces Commanders for both OB production and Target Nomination Lists (TNLs).

3.4 The current fielded software, however, has not yet provided complete support to all levels of the National Intelligence, Joint command structure, operational commanders and subordinate units, but rather has built an architectural foundation which has solved the most significant problem facing OB analysts, targeteers and campaign planners - interoperability. AFRL has built a standard foundation, combining the net capabilities of legacy systems and applications, new developments and emerging technologies. It is upon this foundation that the future effort of this program will build more robust, efficient and complete analytical tools satisfying needs identified across the broad spectrum of the OB production and targeting disciplines in all the Agencies, Services, Commands and Joint organizations.

4.0 TECHNICAL REQUIREMENTS. The contractor shall accomplish the following in accordance with the individual Order Requirements:

4.1 Requirements and Baseline Review and Analysis:

4.1.1

Review all documented targeting requirements and deficiencies in support of operational use in preparation for future design of software and database solutions and the development and implementation of these solutions.

4.1.2

Evaluate database and application performance to determine whether requirements demands are consistent with objectives. Evaluate existing databases and software to determine consistency with requirements. Parameters to be examined, shall, as a minimum, fall into the following categories: data interoperability, data sharing/dissemination, execution time, interface requirements, adherence to standards, development constraints, lifecycle, cost, maintainability, transportability, functional completeness and flexibility.

4.1.3

Perform System Requirements Analysis of operational, technical, functional, data and interface requirements.

4.1.4

Produce augmented System Designs consisting of separate functional and interface software and database designs. Evolve the System Designs from the results of the System Requirements Analysis and allocate the software and data requirements to Computer Software Components (CSCs), Computer Software Configuration Items (CSCIs) and Computer Software Units (CSUs).

4.2 Enhance the functionality of the operational baseline by expanding the baseline's scope of applicability to more robust worldwide operation. Incorporate validated new and modified requirements into the currently fielded baselines.

4.2.1

Areas for enhancement include all functional subcategories, but not limited to; target and target systems analysis, target development, combat assessment, situational analysis, intelligence preparation of the battlespace, exploitation of the Common Operational Picture (COP) and Course Of Action (COA) prediction, interfaces to geopositioning/mensuration and weaponeering, OB production, replication, security, data filters, associations, geospatial display, history and archive processing, data administration and Continuity Of Operations (COOP).

4.2.2

Design and develop new capabilities based upon the functional, operational, interface, data and technical requirements.

4.2.3

Provide enhancements/development for all requirements as approved by the Government Program Office in Rome, NY:

4.2.3.1

Targeting Applications - As received from AF/A2CP in coordination with the Joint Target Automation Steering Group (JTASG).

4.2.4

Center the application of decision aid technology on employment of proven decision analysis, artificial intelligence, operations research, automated communications, interface, modeling techniques and perspective viewing technologies which can be applied to the varied environment and mission scenarios.

4.2.5

Assess, determine and document the impacts that emerging technologies may have on the targeting and intelligence Communities. Develop, document, and coordinate solutions and other recommendations for resolution or minimization of the impacts identified.

4.2.6

Explore and analyze emerging technologies for application with Intelligence and targeting systems.

4.2.7

Develop rapid prototypes to provide new and innovative intelligence and targeting tools and in response to user needs and warfighter trends.

4.3 Testing 4.3.1

Software testing. Plan, develop, conduct and document acceptance, unit, and regression testing on all software releases to ensure that the software meets requirements, Key Performance Parameters (KPPs), and battle rhythm and does not impact existing baselines and interfaces. Conduct testing in accordance with approved Software Test Plans and Software Test Procedures. Perform all final tests and demonstrations in the presence of a Government representative.

4.3.2

Independent testing. Support independent conducted testing (security accreditation, date processing, architectural standards compliance, interoperability and functional).

4.4 Operational User Support 4.4.1

Problem Reports (PRs)/Change Requests (CRs):

4.4.1.1

Implement and maintain a process for handling all PRs and CRs assigned for correction and development against the targeting products under configuration control and in the software development activities in accordance with the Configuration Management Plan (CMP). Implement a reporting procedure to describe each PR and CR assigned in software or documentation that have been placed under configuration control.

4.4.1.2

Maintain a central repository for the processing of all PRs and CRs. Log, track, validate and monitor PRs and CRs on a continuous basis. Utilize system and software engineering metrics, procedures and practices to measure, track and review progress on PR and CR evaluation, technical resolution, coding, testing and completion.

4.4.1.3

Evaluate and process all assigned PRs and CRs in accordance with the CMP and provide the Government with a detailed report of all PRs and CRs.

4.4.1.4

Develop work plans for PRs and CRs for Government review, include as a minimum: the definition of the problem or change, recommendations to correct the problem or implement the change, the total estimated manhours, cost and schedule for completion of the problem or change, action taken to prevent reoccurrence, and the documentation and software modules affected by the problem or change.

4.4.1.5

Develop, test and implement software modifications resulting from PRs or CRs applicable to targeting automation software.

4.4.1.6

At the direction of the Government, dedicate the support required to resolve all Priority 1 PRs/CRs within forty-eight (48) hours.

4.4.2

Provide support for all software modules. Software modifications and enhancements may include the following activities:

4.4.2.1

Resolve software problems through corrective action under CM procedures. As software fixes are accumulated, prepare updated releases encompassing all previous changes.

4.4.2.2

Implement software changes necessary to incorporate COTS/GOTS upgrades.

4.4.3

Provide on-site user support to include: installation assistance for new versions, integration, testing, instruction in the utilization of the application, and technical support for military exercises and user sites specified by the Government.

4.4.3.1

Conduct and document site surveys.

4.4.3.2

Develop materials for and conduct user orientation, training and familiarization.

4.4.3.3

Install the enhanced baseline in suitable operational and exercise environments, including Outside the Continental United States (OCONUS), to provide for operational use and evaluation.

4.4.3.4

Provide quick response support for PRs. Provide problem definition and analysis, and immediate resolution or generation of work plans.

4.4.4

Support user group and configuration control board meetings, technical exchange meetings and working group meetings. Address issues such as user requirements, PRs and CRs, information on new software releases, and software enhancements. Demonstrate the functional capabilities to obtain user feedback and evaluation.

4.5 Configuration Management

4.5.1

Establish, maintain and implement a configuration management process in accordance with an approved CMP for software development and operational baseline support. Operational baseline support will employ the existing Configuration Management Data Base (CMDB) located at AFRL/RI.

4.5.1.1

Establish and document procedures for maintaining configuration control in the CMP. Minimize approaches based on paper products and make maximum use of automated tools.

4.5.1.2

The CMP shall specify, for the appropriate configuration items, all configuration management and configuration control procedures to be followed while maintaining and upgrading the baselines.

4.5.2

Implement Government approved Configuration Management (CM) procedures for targeting software developed, assembled, modified, and acquired. Identify all major software and hardware components and activities necessary to monitor the effort and successfully implement CM. Control the changes to the approved baselines, using the configuration control procedures documented in the CMP. Implement CM to include the following:

4.5.2.1

Delineate policies, standards, and procedures for the orderly control and dissemination of all software. Provide an effective mechanism for incorporating software changes, both during development and operational use. The CMP shall identify the specific products and information managed under the task and incorporate mechanisms for the modification and distribution of targeting software products and documentation both to and from the software users, developers, and maintainers.

4.5.2.2

Include an administrative framework for performing requirements analysis, software design and engineering and documentation for all targeting software and documentation enhancements or modifications. The CMP shall include mechanisms, procedures, and policies for PRs/CRs; software modifications; software testing and qualification; and documentation modifications. The CMP shall also provide mechanisms, procedures, and policies for verifying that changes from previous versions are still maintained in current versions unless changes are necessary and approved by the Government.

4.5.2.3

Implement a software failure analysis and reporting system to incorporate all failures and deficiencies, including non-relevant or out of scope deficiencies. Update and maintain a list of reported problems and deficiencies.

4.5.2.4

Develop and maintain procedures for tracking software and documentation releases pertaining to the developmental baselines.

4.5.3

Utilize system and software engineering metrics, procedures and practices to measure, track and review the technical development progress on a continual basis to ensure a coherent, consistent and integrated effort. Ensure that total system integrity, performance, and complete functionality are achieved, along with compatibility of the overall system with its environment and between subsystems. Perform system integration of the various software components in preparation for system demonstration and insertion into the operational baseline.

4.5.3.1

Employ and adhere to established standards for the various targeting automation environments and architectures, as approved by the Government, for software development, test, configuration management and quality assurance of the software developed and maintained under this effort.

4.5.3.2

Assist in target database reconciliation between interfacing systems. Participate in targeting community efforts to perform necessary database expansions, conversions and synchronization to improve the efficiency of operational databases, the information contained therein and interfaces. Maintain compliance to standard database formats and access methods.

4.6 Quality Assurance and Evaluation Program (QAEP) 4.6.1

Provide and document the resources and organizational support to implement a QAEP. This program will apply to all software developed, assembled, modified or acquired for the effort. Ensure the QAEP adheres to the Quality Assurance and Evaluation Plan, established programming conventions and specified software quality measures. The QAEP shall include review of all software products and activities against applicable standards, procedures, and requirements. QAEP Management shall support the following:

4.6.1.1

Software Documentation Review Process. Develop, document, and implement procedures for reviewing software documentation to evaluate the design, logical fulfillment of requirements, completeness, and compliance with specified standards, procedures, and requirements.

4.6.1.2

Program Development Auditing. Develop, document, and implement procedures for auditing and tracing program development between phases of the life cycle. Procedures and their implementations will be subject to independent review.

4.6.1.3

Quality Evaluation Testing. Develop, document, and implement procedures for testing the software to evaluate the design, logical fulfillment of requirements, completeness, and compliance with specified standards, procedures, and requirements. The tests include those specified in the approved software test plans/procedures. The tests will be subject to independent monitoring and the test results to independent review.

4.7 Management.

4.7.1

Continually track the status of the Orders and report progress toward accomplishment of requirements through the use of software development metrics and cost/schedule metrics.

4.7.2

Continually determine the status of funding required for Order performance.

4.7.3

Conduct Program Status Reviews (PSRs) to present the status of the technical progress made to date in the performance of all active Orders. Conduct/participate in technical reviews (i.e., System/Subsystem Requirement Review, System Specification Review, System/Subsystem Design Review, Software Requirement Review, Software Design Review, Preliminary and Critical Design Reviews (PDR/CDR), Test Readiness Reviews).

4.7.4

Document all technical work accomplished and information gained during performance of each Order. Include all pertinent observations, nature of problems, positive and negative results, and design criteria established where applicable. Document procedures followed, processes developed, “Lessons Learned”, etc. Document the details of all technical work to permit full understanding of the techniques and procedures used in the evolving technology or processes developed. Cross-reference separate design, engineering, or process specifications delivered to permit a full understanding of the total acquisition.

4.7.5

Update existing Government documentation in the form of revisions. Format and content of changes shall not deviate from that of the existing documentation without prior Government approval.

4.8

Develop, update and maintain the following documentation as specified in each order.

4.8.1

Develop a Program Management Plan (PMP) which describes the organization and execution of performance to meet all technical requirements. The PMP shall include, but not be limited to: schedule, technical performance, cost, deliverables, and work breakdown structure information. Update the PMP in the form of page changes as new Orders are initiated or existing Orders are modified or concluded.

4.8.2

Develop a Software Development Plan (SDP) for the duration of the contract. All software developed shall be in accordance with the SDP. Describe plans for conducting a software development effort. The term “software development” is meant to include new development, modification, reuse, reengineering, maintenance, and all other activities resulting in software products.

4.8.2.1

The SDP shall provide insight into, and a tool for monitoring, the processes to be followed for software development, the methods to be used, the approach to be followed for each activity, and project schedules, organization, and resources.

4.8.3

Develop a Integrated Master Schedule (IMS) as a detailed, time-dependent, networked, task oriented, schedule (including specific calendar dates) of the effort required to accomplish the complete program. An integrated program network schedule includes all of the tasks, activities, and resources (skills and time duration of application) required to complete each milestone. The IMS will be directly traceable to requirements of each Order. Update the IMS in the form of page changes as new Orders are initiated or existing Orders are modified or concluded.

4.8.4

Develop a Configuration Management Plan (CMP). Describe the configuration management program, how it is organized, how it will be conducted, and the methods procedures and controls effective configuration identification, change control, status accounting, and audits of the total configuration, including hardware, software and firmware. The principle use is to provide the Government a basis for review, evaluation and monitoring of the CM program and its proposed components.

4.9 Software. All software developed, modified, enhanced, assembled or acquired shall be delivered to the Government in accordance with each Order and the following:

4.9.1

All software developed shall be delivered to the Government in the form of source and object code.

4.9.2

Design and develop all computer software using an approved Higher Order Language (HOL). Base the selection of the HOL on system interface, interoperability, communications functions, human interface, and requirements for security, safety, and reliability. Design the software to make use of existing software and for subsequent reuse to the maximum feasible extent.

4.9.3

Document all software in the form of hard copies and electronic media in accordance with the Contract Data Requirements List (CDRL).

4.9.4

Developed software under this effort is to be completely maintainable and modifiable with no reliance on any non-delivered computer programs or documentation.

4.9.5

Evaluate the planning performed for the use of non-developmental software (e.g., Commercial Off-The-Shelf (COTS), reusable, or Government furnished (GOTS)) to fulfill contract requirements. Determine whether the software performs as documented before incorporating acquired software. Determine whether documentation is adequate for the intended purpose.

4.9.6

For all software purchased or licensed, arrangements shall be made for licensing and maintenance agreements to be transferred to the Government upon the completion of each order. All applicable manuals and supplemental data shall be delivered to the Government for all COTS software purchased.

4.9.7

All information technology items must be Year 2000 compliant, or non-compliant items must be upgraded to be Year 2000 compliant. Year 2000 compliant means information technology that accurately processes date/time data (including, but not limited to, calculating, comparing, and sequencing) from, into, and between the twentieth and twenty-first centuries, and the years 1999 and 2000, and leap year calculations, to the extent that other information technology, used in combination with the information technology being acquired, properly exchanges date and time data.

4.9.8

Define or select a software lifecycle model appropriate to the scope, magnitude, and complexity of the project. The activities and tasks of the development process will be selected and mapped onto the chosen lifecycle model.

4.9.9

Perform system requirements analysis to the extent that the specific intended use of the system will be analyzed to specify system level requirements. Document the system level requirements describing the functions and capabilities of the system, the business, organizational, user, safety, security, human-factors engineering, interface, operations, maintenance requirements, as well as design constraints and qualification requirements. Present the results of this activity at system/subsystem requirements reviews, as required.

4.9.10

Perform system architectural design to the extent that a top-level architecture of the system will be established. The architecture will identify all software items. Ensure all the system level requirements are allocated among the items. Software configuration items will be subsequently identified from these items. Document the system architecture and the system level requirements allocated to the items. Present the results of this activity at system/subsystem design reviews, as required.

4.9.11

Perform software requirements analysis to the extent that the specific intended use of the software will be analyzed to specify software level requirements. Document the software level requirements describing the functional and capability specifications, including performance, physical characteristics, environmental conditions under which the software is to perform; interfaces external to the software item, qualifications requirements, safety specifications, including those related to methods of operation and maintenance, environmental influences and personal injury; security specifications, including those related to compromise of sensitive information, human factors engineering, data definition and database requirements, installation and acceptance requirements of the delivered software product, and user maintenance requirements to the extent required. Present the results of this activity at software requirements reviews, as required.

4.9.12

Perform software architectural design to the extent that requirements for the software items are transformed into an architecture that describes its top-level structure and identifies the software components. Ensure that all the requirements for the software items are allocated to its software components and further refined to facilitate detailed design. Document the architecture of the software item. Present the results of this activity at software design reviews, as required.

4.9.13

Perform a detailed design for each software component of the software item. Refine the software components into lower levels containing software units that can be coded, compiled, and tested. Ensure that all the software requirements are allocated from the software components to the software units. Document the detailed design. Present the results of this activity at software design reviews, as required.

4.9.14

Provide prototype visualizations of changes to Human Machine Interface (HMI) as a result of system enhancements on an as-required basis. Enhance and change the prototype throughout the development process to represent the most current version of the design, and demonstrate the prototype at each formal review or HMI Working Group. Provide a copy of the prototype executable software after each demonstration. Support users working with the prototypes to guarantee completeness and consistency.

4.9.15

Perform software coding and testing for each software component/item in accordance with the approved Software Development Plan (SDP). Build and document each software unit and database. Develop test procedures and test data for each software unit and database. Test each software unit and database ensuring that each satisfies its requirements. Document the results of each test.

4.9.16

Perform software integration and testing for each software item. Develop and document an integration plan that includes test requirements, procedures, data, responsibilities, and schedule. Integrate the software units and software components and test as the aggregates are developed in accordance with the integration plan. Ensure that each aggregate satisfies the requirements of the software item and that the software item is integrated at the conclusion of the integration activity. Document the integration and test results.

4.9.17

Perform software qualification testing for each software item. Develop and document, for each qualification requirement of the software item, a set of tests, test cases (inputs, outputs, test criteria), and test procedures for conducting Software Qualification Testing. Ensure that the integrated software item is ready for Software Qualification Testing. Identify the software or system requirements addressed by each test case and ensure that all software requirements are included as part of software qualification testing. Conduct qualification testing in accordance with the qualification requirements from the software item. Ensure that the implementation of each software requirement is tested for compliance. Document the qualification testing results.

4.9.18

Perform system integration. Ensure the software configuration items are integrated with other systems as necessary, into the system. Test the aggregates as they are developed, against their requirements. Document the integration and the test results.

4.9.18.1

Perform Early Interface Testing (EIT) as required.

4.9.19

Conduct test readiness reviews to ensure the readiness of the system item to be tested. All requirements verification documentation, test case results, and status of all software and documentation discrepancy reports shall be presented and reviewed for determination of software item readiness for test. Document the results of the reviews.

4.9.20

Perform system qualification testing. Develop and document, for each qualification requirement of the system, a set of tests, test cases (inputs, outputs, test criteria), and test procedures for conducting System Qualification Testing. Ensure that the integrated system is ready for System Qualification Testing. Conduct qualification testing in accordance with the qualification requirements for the system. Ensure that the implementation of each system requirement is tested for compliance and that the system is ready for delivery. Document the qualification testing results.

4.10

The Air Force Computer Emergency Response Team (AFCERT) issues advisories to identify known vulnerabilities in computers and computer networks. These advisories include but are not limited to Information Assurance Vulnerability Alerts, Virus notification, Advisory Compliance Messages (ACMs), and Follow-Up Messages. Report suspected vulnerabilities and security incidents in accordance with AFSSI 5021. Respond to AFCERT advisories in accordance with AFSSI 5021 as follows.

4.10.1

Acknowledge receipt of AFCERT advisories in three (3) days of issue.

4.10.2

Implement the countermeasures identified by the advisory within the timeframe specified by the advisory or as specified by the Contracting Officer Technical Representative (COTR). If the countermeasures can not be implemented, document the inability and receive approval from the Designated Approving Authority (DAA) (see AFI 33-202) and the COTR for either an alternative corrective action or to continue operations without the countermeasures. If alternative corrective action is approved, implement this action within the timeframe specified.

4.10

The Air Force Network Operations Service Center (AFNOSC) issues Time Compliance Network Orders (TCNOs) to identify potential vulnerabilities and patches for systems and networks. The JTT Program Office is required to respond to TCNOs within 72 hours; therefore, the contractor shall respond to TCNOs within 48 hrs of the release date. Responses shall be provided according to format required by AFNOSC.

ATTACHMENT NO. 2

DRAFT

File details come from the government source that posted it. Updated .