Attch 10 Sample Order 0001 Work Description.docx
DOCX document 25 KB Posted
- Attached to
- AGILE CYBER TECHNOLOGY (ACT) Federal contract opportunity
- Solicitation number
- FA8750-12-R-0002
About this file
Atch 10 - Sample Order 0001 Work Description
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SAMPLE ORDER
AIR FORCE RESEARCH LABORATORY
ROME RESEARCH SITE
ROME, NEW YORK
SAMPLE ORDER
WORK DESCRIPTION
FOR
NEXT GENERATION SECURE RESEARCH AND DEVELOPMENT NETWORK (Next-Gen SRDN)
22 JUN 2011
ALL INFORMATION CONTAINED IN THIS SAMPLE ORDER IS NOTIONAL
THIS SAMPLE ORDER IS PROVIDED FOR USE BY POTENTIAL AGILE CYBER TECHNOLOGY OFFERORS FOR PROPOSAL PURPOSES.
(Contract Number FA8750-12-R-0002/SAMPLE Order 0001)
| 4.0 | TECHNICAL REQUIREMENTS. The contractor shall accomplish the following: |
| 4.1 | Design, develop, and implement a prototype Next-Gen SRDN for a military research and development facility. The network must adhere to the following specifications: |
| -Must be compatible with Internet Protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6). |
-Must consist of 100 end nodes conforming to 2010 (or newer) USAF Quarterly Enterprise Buy (QEB) minimum specifications for an Expandable Mini-Tower. Other network infrastructure components may be added as needed.
- End nodes must be capable of running varying operating systems.
-May not “block” access to any external web sites.
4.1.1 Provide an environment that incorporates threat avoidance and next generation cyber defense.
4.1.1.1 Provide the technology to avoid threats through formal mission specification and trusted hardware/software implementation, mitigate vulnerabilities through protocol flattening and novel architectures, and assure mission survival in dynamic threat and mission environments.
4.1.1.2 Develop techniques to evade and escape threats and attacks.
4.1.1.3 Develop the technology to automatically survive attacks without interruption or degradation of mission functions.
4.1.1.4 Analyze, understand, defeat, and recover from attacks.
4.1.1.5 Provide a dynamic cyber defense technology to recover the sensors, processors, servers, networks, systems, and applications to an operable state following a successful adversary attack. Incorporate survivability, graceful degradation, and reconstitution as part of the recovery process.
4.1.1.6 Develop and demonstrate technologies for timely response to adversary attacks, minimization of damage, trusted recovery, and integration of fault tolerance and attack tolerance.
4.1.1.7 Investigate and implement real-time quarantine of malicious code, enterprise-wide survivability, and defense against “Zero Day Attacks.”
4.1.2 Develop and demonstrate situational awareness capabilities within the Next-Gen SRDN.
4.1.2.1 Develop a comprehensive situational awareness model for the next generation cyber defense environment that includes health, status, and contingency planning in the event of unforeseen situations (such as cyber attacks or network outages).
4.1.2.2 Integrate knowledge base technology, data fusion to include text analytics, and forensics to achieve enhanced cyberspace situation and mission awareness.
4.1.2.3 Detect novel cyber vulnerabilities and anomalies that attract attacks including means and capabilities of the cyber attacker, attribution of cyber activity (digital/physical identity), anti-spoofing, and collection and transport of remote cyber evidence.
4.1.2.4 Provide visualizations of network security data at both a high level (for display to mission commander) and low investigative level (for use by network analyst).
4.1.3 Develop and demonstrate methods for mission assurance capabilities within the Next-Gen SRDN.
4.1.3.1 Develop a methodology that deals with identifying and prioritizing the critical mission functions, the scoping of the mission mapping activity, and the boundary establishment.
4.1.3.2 Develop methods to conduct a systematic assessment of mission essential functions (MEFs) susceptibility to process failures and the vulnerability of atomic cyber processes and inter-process communication to accidents and attacks. Include the following steps as part of the vulnerability assessment process:
4.1.3.2.1 For each processing unit, estimate the risk based on the software it executes and the documented vulnerabilities and threats.
4.1.3.2.2 For each data communication channel, estimate the threats to protocol and implementation vulnerabilities.
4.1.3.2.3 For each vulnerability, define its temporal and spatial properties and estimate their effects.
4.1.3.3 Develop mitigation strategies that focus on atomic cyber processes, sensors, storage units, and inter-process communication. Include measures to reduce the export to, and impact of a cyber compromise, including: shifting the defensive posture from intrusion detection to threat denial, physical and logical system isolation, virtualization, static threat avoidance via moving vulnerabilities out of band through system redesign, domain modification through protocol flattening, polymorphism through protocol and implementation modification, application of authentication measures, and selective insertion of GOTS technology into COTS system to harden against common threat.
4.1.4 Deliver and install the Next-Gen SRDN at Air Force Research Laboratory, Information Directorate, Rome New York. Installation shall include all hardware and software in order to fully demonstrate the Next-Gen SRDN. Prior to the delivery and installation, identify any special requirements needed for the Next-Gen SRDN that would not be available in a typical computer facility. (See CDRL, A004)
4.1.5 Upon completion of the installation, conduct a three (3) day familiarization, six (6) hours each day, of the Next-Gen SRDN to approximately five (5) Government personnel. This familiarization shall include set-up, operating and demonstration capabilities of the system. (See CDRLs, A003, A007 and A008)
4.1.6 Conduct a large scale demonstration at such a time and place as specified in the contract schedule. This demonstration shall include all capabilities and functionality developed in paragraphs 4.1.1 through 4.1.3 of this Order. Conduct the demonstration in accordance with the Government reviewed Demonstration Plan. (See CDRL, A005)
| 4.2 | Software and Hardware. | |
| 4.2.1 | Deliver all software and hardware developed, assembled, or acquired to the Government in accordance with the Order schedule and the following: | |
| 4.2.1.1 | Deliver all software developed under this effort as source and object (executable) code. Include commented source listings and source coded for the target computer system. (See CDRL, A006) | |
| 4.2.1.2 | Provide complete software documentation to include Installation, User, and Maintenance Instructions. (See CDRL, A007) | |
| 4.2.1.3 | Design and develop all computer software using a Higher Order Language (HOL) discussed with the Government. Base the selection criteria upon system interface, interoperability, communications functions, human interface, and requirements for security, safety, and reliability. Design the software to make use of existing software and for subsequent reuse to the maximum feasible extent. | |
| 4.2.1.4 | Software developed under this effort is to be completely maintainable and modifiable with no reliance on any non-delivered computer programs or documentation. | |
| 4.2.1.5 | For all software and hardware purchased or licensed for use as a component to be delivered, arrangements shall be made for licensing and maintenance agreements to be transferred to the Government upon the completion of this effort. (See CDRL, A008) |
| 4.3 | Reporting. | |
| 4.3.1 | Continually determine the status of the effort and report progress toward accomplishment of Order requirements. (See CDRL, A001) | |
| 4.3.2 | Continually determine the status of funding required for Order performance. (See CDRL, A002) | |
| 4.3.3 | Conduct oral presentations at such times and places designated in the Order schedule. Provide status of technical progress made to date in performance of the Order during presentations. (See CDRL, A003) | |
| 4.3.4 | Document the details of all technical work accomplished and information gained during performance of this acquisition to permit full understanding of the techniques and procedures used in evolving technology or processes developed. Include all pertinent observations, nature of problems, positive and negative outcome, and design criteria established where applicable. Document procedures followed, processes developed, “lessons learned,” and other useful information. Cross-reference each design, engineering, and process specification delivered to facilitate a full understanding of the total acquisition. (See CDRL, A009) |
Attachment No. 10
File details come from the government source that posted it. Updated .