ACT_2_SOW_Umbrella_v5_(2016_12_1).pdf
PDF 116 KB Posted
- Attached to
- Agile Cyber Technology 2 (ACT2) Federal contract opportunity
- Solicitation number
- FA8750-17-R-0001
About this file
Revised Draft Statement of Work
View the file
Other files for this federal contract opportunity
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AIR FORCE RESEARCH LABORATORY
ROME RESEARCH SITE
ROME, NEW YORK
STATEMENT OF WORK
FOR
AGILE CYBER TECHNOLOGY 2 (ACT 2)
PCSN G-X-XXXX
11 OCT 2016
TABLE OF CONTENTS
Section Title Page
1.0 OBJECTIVE 3
2.0 SCOPE 3
3.0 BACKGROUND 3
4.0 TECHNICAL REQUIREMENTS 9
1.0 OBJECTIVE:
1.1 The objective of this effort is to provide a focused yet flexible, rapid contracting vehicle between
Air Force Research Laboratory (AFRL), its Products Centers, and the Operational Community to support rapid research, development, prototyping, demonstration, evaluation, and transition of cyber capabilities. Emphasis will be placed on: a) development of technology capability solutions that address specific user requirements; b) delivery of prototype technologies for evaluation and feedback in the context of the user’s operational environment; and c) provision of a mechanism for user acquisition of limited product quantities required for operational introduction of technologies.
2.0 SCOPE:
2.1 The scope of this effort is to perform multiple activities necessary to achieve AFRL’s Science and
Technology (S&T) vision of cyber superiority. This includes activities for rapid development, design, prototyping, demonstration, scenario development, experimentation & evaluation, integration, testing, technical installation, transition, and support through initial operations of cyber technologies, which enable Global Vigilance, Global Reach, and Global Power in air, space, and cyberspace for:
1. Cyber Threat Avoidance & Cyber Defense
2. Full Spectrum Cyber Operations
3. Cyber Network Exploitation
4. Cyber Situational and Mission Awareness
5. Cyber Command & Control
6. Cyber Modeling, Simulation, & War Gaming
7. Cyber Infrastructure
8. Cyber Mission Assurance
2.1.1 The AFRL Core Technical Competencies (CTCs) relevant to the effort are: 1) Autonomy, Command and Control, and Decision Support, 2) Processing and Exploitation, 3) Connectivity and
Dissemination, and 4) Cyber Science and Technology.
3.0 BACKGROUND:
3.1 Joint Publication 1-02 defines cyberspace as a global domain within the information environment consisting of the interdependent network of information technology infrastructures, including the
Internet, telecommunications networks, computer systems, and embedded processors and controllers.
3.1.1 Cyberspace operations are defined as the employment of cyber capabilities where the primary purpose is to achieve military objectives or effects in or through cyberspace [1]. Such operations include computer network operations and activities to operate and defend the Global Information Grid.
From an S&T perspective, operations in cyberspace occur whenever signals affect intelligent systems.
This S&T view breaks cyber operations into three components: a) the effectors include a broad range of signal-borne threats, analog or digital, electronic or electromagnetic; b) the medium encompasses all means of signal delivery, wired or wireless, software or hardware; and c) the targets include all weapons and systems that use computers or networks.
[1]. Cyberspace is as relevant a domain for DoD activities as the traditional domains of land, sea, air, and space. The growing dependence of Air Force operations on cyber capabilities makes cyberspace a new “center of gravity” and ideal target for any adversary.
3.1.2 The information technology infrastructure on which Air Force missions depend is controlled by both military and commercial entities and is vulnerable to attacks and manipulation. As operations in cyberspace have the ability to impact operations in all other warfighting domains, it is essential the Air
Force preserve the ability to operate when the generation, processing, storage, transmission, and consumption of vital information is challenged.
3.2 The USAF vision of Global Vigilance, Global Reach and Global Power across the full spectrum of conflict from peacetime to major combat operations drives the S&T requirements for cyber operations.
Figure 1 illustrates the changing requirements for vigilance, reach and power as tensions escalate towards combat. Within this context, cyber operations provide a necessary enabler for Air and Space power, while providing an additional domain where the USAF can deliver effects.
The S&T requirements for cyber operations do not focus solely on conducting operations in cyberspace, but rather look holistically at the cyber S&T necessary to accomplish the USAF vision of
Global Vigilance, Global Reach and Global Power in all three domains of Air, Space and Cyberspace.
Cyberspace is first and foremost a foundational domain that enables US military superiority, and secondarily another domain where the US can deliver effects. Through cross domain dominance, operations in cyberspace can guarantee freedom of maneuver and assure mission essential functions
(MEF) in all war fighting domains.
3.2.1 Global Vigilance. Global Vigilance refers to the persistent world-wide capability to keep an unblinking eye on any entity, to provide warning on capabilities and intentions, and to identify requirements and opportunities. The primary challenges of Global Vigilance include maintaining persistent, global, situational awareness using assured, trusted systems that can avoid a broad spectrum of threats. In turn, Global Vigilance depends to some extent on elements of Global Reach to support sensor positioning and forward basing of assets for situational awareness. Situational awareness, information and mission assurance, and threat avoidance are three main capabilities necessary to achieve Global Vigilance in and through cyberspace.
3.2.2 Global Reach. Global Reach describes the ability to move, supply and position assets with unrivaled velocity and precision anywhere on the planet. The concepts that support global reach in cyberspace include access technologies to position and deploy cyber assets, survival in a contested cyber environment, and cross-domain superiority for command and control of integrated mission execution. Global Reach is enabled through predominantly defensive measures when tension pushes a situation away from peace towards conflict. In turn, these predominantly defensive measures enable the capabilities that support Global Power in the event of conflict escalation into major combat operations.
3.2.3 Global Power. Global Power enables the US to affect any asset, anywhere in the world, at a time of our choosing, and to project swift, decisive and precise effects. Delivery of Global Power in any war fighting domain requires command and control of cyberspace, on which modern US military capability depends. The global projection of cyber power creates unique S&T challenges of developing precise cyber capabilities, estimating first, second, and higher order effects, and responding actively to external events.
3.2.4 Integrating Global Vigilance, Global Reach and Global Power to Achieve Cyber Superiority. The
US Air Force vitally depends on cyberspace to achieve its vision of Global Vigilance, Global Reach and Global Power. Further, the USAF projects differently Global Vigilance, Global Reach and Global
Power at various stages of tension across the spectrum of conflict. Global Vigilance at peacetime requires persistent situational awareness in all domains, mission and information assurance, and threat avoidance through deterrence and technology. Global Reach requires access to the battle space, survival and fighting through cyberspace attacks, and integrated planning of mission essential functions and their dependence on cyberspace. Global Power calls for predominantly combat operations enabled through the delivery of precision effects in cyberspace, reliable effects assessment and automated response action. Global Vigilance, Global Reach, and Global Power capabilities must all work together to realize the cyber superiority vision.
3.3 S&T for Cyber Superiority
3.3.1 Threat Avoidance & Cyber Defense. Defensive cyber technologies are those that guarantee the successful execution of MEF in a contested environment. Cyber defense seeks to avoid as many threats and attacks as possible by mitigating vulnerabilities, disrupting threats, and assuring missions.
A goal is to deliberately design the cyber domain in order to favor defense and eliminate opportunities for attacks. Attacks will be avoided by way of agile systems that can evade and escape attacks.
Advanced cyber defensive technologies will purposely misdirect the adversary, manipulating their perception of friendly systems and disrupting attack planning.
3.3.1.1 When attacks cannot be avoided, critical systems must be built with the ability to “fight through” successful attacks. The requirement will be at a speed that supports the minimum allowable continuity of MEFs, thus enabling successful completion of the mission despite attackers’ varying degrees of success. It should be noted that a successful “fight through” capability may go beyond the use of traditional network defense mechanisms such as intrusion detection systems (IDS), event correlation, visualization, attribution, etc., because none of these directly support the successful completion of a time-critical MEF.
3.3.1.2 Preserving continuity of operations requires that cyber defense systems include a longer-term ability to sense, fuse, attribute, understand and project the cyber situation and its impact on future missions. This awareness must then be used to actuate systems, configurations, architectures, and dependencies in order to maximize the ability to guarantee future missions.
3.3.2 Full Spectrum Cyber Operations enable the impact of any asset, anywhere in the world, at any time to project swift, decisive, and precise effects.
3.3.3 In Network Exploitation, current automated sensors are capable of collecting a vast amount of data, far more than can be processed by analysts. Efficient automatic/semi-automatic tools and methods to rapidly ascertain the highest interest information are paramount to the success for intelligence production.
3.3.4 Situation and Mission Awareness. The strategic objective of cyber situation and mission awareness (SA/MA) is to provide automated situation and mission assessment and analysis that meet the operational requirements of all areas within the cyber domain – friendly systems and missions, traversal neutral systems or global commons and adversary systems – across the entire spectrum of conflict – from peacetime to major combat operations. Mission awareness lies at the heart of SA.
Understanding the dependence of missions on specific assets, the interdependence of assets and the interdependence of missions drives the requirements for SA.
3.3.5 Command and Control (C2). Cyber operations can be conducted at any level of war and across the entire spectrum of conflict in support of global and theater objectives. Global C2 provides a persistent, 24/7, collaborative environment comprised of people, processes, systems and tools to enable timely response to today’s asymmetric challenges. Global C2 ties real-time intelligence, collaborative planning and decision making to support a broad mix of military options – offensive, defensive, kinetic and non-kinetic. C2 capabilities for monitoring, assessing, planning, and executing cyber operations need to be designed, developed, and implemented to integrate with existing air and space capabilities using information sharing across multiple security classification domains.
3.3.5.1 Many parallels exist between operations in the more traditional domains of air and space and in the emerging domain of cyberspace. As capabilities are integrated, planning requirements for cyber assets mirror those for traditional Intelligence, Surveillance, and Reconnaissance (ISR) and combat assets. The practice of procedural versus positive control over air assets and the time scales of the Air
Operations Center (AOC) do not translate well to cyberspace where decision cycles hover around a fraction of a second. Conversely, placing cyber assets under procedural control requires the incorporation of a set of previously agreed upon rules for a broad range of future scenarios. Integrated planning must take into consideration the challenges of cyberspace de-confliction, Identification of
Friend or Foe (IFF) procedures and the potential of cyber fratricide and cross-domain fratricide. The ability to tag and identify cyber assets, and to continuously ascertain their status and integrity creates technical challenges unique to cyberspace.
3.3.5.2 Simply porting technologies developed for C2 in the air and space domain may not be directly applicable or useful in the cyber domain. Furthermore, the integration of non-kinetic assets with kinetic assets and the effects they produce are at a formative stage. With these two concepts in mind, novel and unique approaches to enable C2 in an environment that is not constrained by time, distance, and geographical boundaries are required.
3.3.6 Cyber Infrastructure. Cyber infrastructure consists of the underlying technologies that are crucial for cyber superiority. The concepts of correctness and acceptability are at the core of cyber infrastructure. Correctness is a theoretical concept motivated by the "computational" side of cyber.
Cyber does not exist without computation. Acceptability is the practical side of cyber. It is motivated by the rest of the infrastructure. If infrastructure is defined as being composed of computing, communications, physical, and human components, then correctness is concerned with computing and communications. Acceptability is concerned with the physical and human components.
3.3.6.1 Due to the efforts of many mathematicians and computer scientists, computing can either be an art or a science. When relegated to the art form, individuals or organizations simply specify, design, implement, and deliver hardware and software that operates, but much remains unknown about the system. As such, bugs and vulnerabilities are often reported and have the potential to be exploited by the adversary.
3.3.6.2 On the other hand, correctness is science. It is a careful application of formal methods.
Correctness is a proof of a certain conclusion based on assumptions and premises. It also coincides with the different stages of the system life cycle. Correctness during the Design phase guarantees the design meets the specifications. If mission assurance properties appear in the original specification, the design must correctly meet those specifications. Correctness during the Implementation phase ensures the same mission assurance properties are met.
3.3.6.3 Correctness by itself is inadequate. For example, it is extremely difficult, if not impossible, to prove that a system in the Operations and Maintenance (O&M) phase of the lifecycle is equivalent to the implementation itself. What might be proven is that the system maintains its correctness if the underlying assumptions of the proof during the Research and Development phase were never violated.
This is where acceptability comes in. Acceptability is concerned with practice, whereas correctness is a strict embodiment of theory. Acceptability is the notion of whether the physical and human infrastructures continue to enforce proven assumptions. This is a drastic departure from traditional cyber initiatives that work system development from the top-down.
3.3.6.4 In the top-down model, assumptions made during the Specification, Design or Implementation phases are incorporated into a usage policy. This policy is then forced on the users during O&M without knowledge of whether the policy will or can be enforced. In the bottom-up model, knowledge about the eventual users (human psychology in general) and operating environments where the systems will be used guide the assumptions that can be made. Much of this already takes place during the
Requirements Gathering phase. If the same process is extended to the other stages of the system life cycle, especially the O&M phase, then the system further achieves acceptability. The most difficult aspect of acceptability is the ability to ascertain the expected human behavior, express it in the form of a formal language used in the correctness proofs, and then re-verify the same system under the new assumptions.
3.4 REFERENCE DOCUMENTS:
1. Joint Publication 1-02, Department of Defense Dictionary of Military and Associated Terms, 12 April 2001 (as amended through 15 February 2016)
2. Jabbour, Dr Kamal, “The Science & Technology of Cyber Operations,” High Frontier Journal for Space & Missile Professionals, May 2009, Volume 5, Number 3.
3. Defense Science Board Summer Study on the Challenges to Military Operations in Support of National Interests, 2007.
4. White House Cyberspace Policy Review, May 2009.
4.0 TECHNICAL REQUIREMENTS.
4.1. The Contractor shall accomplish the following on an order by order basis. The requirements for each order may encompass rapid Research & Development (R&D), design, prototyping, demonstration, scenario development, experimentation and evaluation, integration, testing, technical installation, transition, and support through initial operations of cyber technologies, which are relevant to the following CTCs: 1) Autonomy, Command and Control, and Decision Support, 2) Processing and
Exploitation, 3) Connectivity and Dissemination, and 4) Cyber Science and Technology.
4.1.1 Cyber Threat Avoidance & Cyber Defense
4.1.1.1 Research, develop, enhance, and integrate capabilities to secure and defend critical assets from cyber threats and cyber-attacks.
4.1.1.2 Perform leading edge research, development, enhancement, and integration to advance, demonstrate, and implement technologies and concepts to support mission-based cyber defense including techniques to avoid cyber attacks by mitigating vulnerabilities and disrupting threats, ability to fight through unavoidable attacks in “mission time”, and assure mission essential functions are able to be conducted during an attack.
4.1.1.3 Provide a dynamic cyber defense to recover the sensors, processors, servers, networks, systems, and applications to an operable state following a successful adversary attack. Incorporate survivability, graceful degradation, and reconstitution as part of the recovery process.
4.1.1.4 Design, develop, and demonstrate wireless network defense capabilities, including wireless intrusion detection systems, detection of passive sniffers, defense against jammers, active response techniques, application of software defined radio technology to information assurance, and distributed and collaborative boundary control. Address wireless and Internet Protocol Version 6 (IPv6) standards.
4.1.2 Full Spectrum Cyber Operations
4.1.2.1 Research, develop, enhance, and integrate cyber capabilities to affect adversary perceptions, reactions, and ability to conduct operations.
4.1.2.2 Research, develop, enhance, and integrate capabilities to facilitate freedom of operation in cyberspace while denying adversaries the same ability.
4.1.3 Cyber Network Exploitation
4.1.3.1 Research, develop, enhance, and integrate technologies that provide Signals Intelligence, Imagery Intelligence, Computer Network Intelligence, Cyber Intelligence, Measurement/Signature
Intelligence, and other relevant intelligence to achieve information dominance through processing of data from intelligence sensors.
4.1.3.2 Reduce the workload of the Intelligence Surveillance and Reconnaissance (ISR) operator/analyst by developing automated processes to identify, extract, analyze, correlate, sort and report information for further intelligence analysis, collection mission management, and warfighter action.
4.1.4 Cyber Situational and Mission Awareness
4.1.4.1 Research, develop, enhance, and integrate techniques and tools for automated situation and mission analysis and assessment for friendly cyber systems and missions, forces, neutral systems, and adversary systems across the spectrum of conflict – from peacetime to major combat operations.
Develop cyber SA/MA capabilities such that they are able to be integrated with air and space SA capabilities.
4.1.4.1.1 Investigate, model, and develop a comprehensive SA/MA model for friendly cyber systems and missions that includes health, status, and contingency planning.
4.1.4.1.2 Develop data and models for awareness of adversary and neutral cyber systems.
4.1.4.1.3 Integrate knowledge base technology, data fusion to include text analytics, and forensics to achieve enhanced cyberspace situation and mission awareness.
4.1.4.1.7 Visualization of cyber data. Provide the capability to move seamlessly between geospatial and non-geospatial data to enable integrated decisions over the air, space, and cyber domains. Provide the capability to correlate and fuse cross-domain information on cyber, air, and space assets and graphically display the information in a Global Common Operating Picture (COP). Implement the capability to tailor and filter the information from the Global COP into a User Defined Operational
Picture (UDOP).
4.1.5 Cyber Command & Control
4.1.5.1 Research, develop, enhance, integrate, demonstrate, experiment, and evaluate cyber C2 technologies and techniques to improve cyber C2 capabilities and integration of these capabilities with existing kinetic processes for Air Force systems. These technologies and techniques may address the following:
4.1.5.1.1 Collaborative planning, execution, and assessment of global integrated mission packages across multiple areas of responsibilities (AORs)
4.1.5.1.2 Courses of action for integrated, multi-domain effects that cross multiple AORs
4.1.5.1.3 Comprehensive modeling, simulation, and war gaming capabilities that provides realistic cross-domain (air, space, and cyberspace) representations and depictions
4.1.5.1.4 Synchronized tasking of air, space, and cyberspace assets arranged in time and space
(physical and virtual)
4.1.5.1.5 Characterization of cyber assets for cyber effects and mission representations
4.1.5.1.6 Friendly Order of Battle (FROB) depictions for all air, space, and cyber assets in use during the various phases of planning and execution
4.1.5.1.7 Operational assessments of integrated air, space and cyberspace effects
4.1.6 Cyber Modeling & Simulation
4.1.6.1 Research, develop, enhance, and integrate cyber models for simulation of appropriate environments to support complex COA evaluation within the cyberspace domain and across the air, space, and cyberspace domains. Develop the cyber models and simulations such that they are interoperable with existing air and space modeling & simulation environments, and improve the realism of cyber components in air and space models.
4.1.7 Cyber Infrastructure
4.1.7.1 Research, develop, enhance, and integrate technologies to establish the correctness of cyber infrastructure, including sensors, computers, servers, networks, and systems. Include both the correctness of systems that are built from scratch and systems whose correctness needs to be established after the fact.
4.1.7.2 Research, develop, enhance, and integrate technologies to establish the correctness of the communications infrastructure, including software application programmer’s interfaces.
4.1.7.2.1 Prove the correctness of existing networking protocols. Develop tools and techniques for new protocols. Research techniques for taking protocol specifications and automatically generating the equivalent source code to prove the source meets the protocol specification.
4.1.7.3 Design and identify means and methods for assessing the impacts of technologies to physical infrastructure.
4.1.7.4 Research and develop theories and methods for composing systems comprised of a) hardware/software systems; b) hardware/software/communications systems; and c) cyber/physical systems. Research tools and methods to show the impact of a certain assumption being violated on the overall correctness of the system.
4.1.7.5 Develop and implement means for ensuring smooth technology transitions. Examples: from
Internet Protocol version 4 (IPv4) to IPv6, Windows XP to Windows Vista to Windows 7, and from standard system configurations to hardened systems.
4.1.7.7 Develop and implement means for vulnerability assessments for all infrastructures, holistically.
4.1.7.8 Develop and implement means for hardening interfaces between the physical and computing infrastructures.
4.1.7.9 Develop and implement means for hardening interfaces between different computing infrastructures.
4.1.8 Cyber Mission Assurance
4.1.8.1 Research, develop, enhance, and integrate capabilities for mission assurance in the cyber domain that addresses the following mission assurance attributes: a) prioritization, b) mapping, c) vulnerability assessment, and d) mitigation.
4.1.8.1.1 Prioritization: Research, develop, and implement a methodology that deals with identifying and prioritizing the critical mission functions, the scoping of the mission mapping activity, and the boundary establishment. Develop a methodology based on mission essential functions (MEFs) and the prioritization of the MEFs with respect to the overall mission of a command.
4.1.8.1.2 Mapping: Research, develop, and implement methods that define the functionality of each atomic cyber process and the interaction among the processes. Develop methods that decompose each critical MEF into a number of layers that represent sub-functions, relationships, responsibilities and systems, culminating into a logical representation of the atomic cyber processes that enable the MEF.
4.1.8.1.3 Vulnerability Assessment: Research, develop, and implement methods, based on autonomic discovery and table top war gaming by a combined team of cyber and mission domain experts, to conduct a systematic assessment of MEF susceptibility to process failures and the vulnerability of atomic cyber processes and inter-process communication to accidents and attacks.
4.1.8.1.3.2 Mitigation: Research, develop, and implement mitigation strategies that focus on atomic cyber processes, sensors, storage units, and inter-process communication.
4.1.9 Integrate Innovative Cyber Technologies to Enable Cyber Superiority
4.1.9.1 Provide for an integrated, operator-focused, full spectrum cyber operations and C2 environment that can process data from multiple sensors and intelligence sources.
4.1.9.2 Integrate the cyber modules and multiple sources of data into an architecture capable of meeting program requirements.
4.1.9.3 Develop or provide the ability to automatically generate datasets, to include automated text extraction techniques that can be used by the cyber systems for demonstration, test, and evaluation to include data set characteristics and evaluation metrics.
4.1.9.4 Perform test planning. Develop or acquire suitable test data, scenarios, metrics, and algorithms to support the cyber technology.
4.1.9.5 Develop the documentation required to permit the demonstration, testing, and evaluation of the cyber applications and systems.
4.1.9.6 Develop performance measures and metrics, Measures of Effectiveness (MOEs) and Measures of Performance (MOPs) for the cyber capabilities being tested and evaluated.
4.1.9.7 Evaluate performance based on predefined operational expectations.
4.1.9.8 Perform testing. Document all test results and provide recommendations on test results.
4.1.9.9 Perform demonstrations, field experiments, and field exercises to show the effectiveness of the cyber technology.
4.1.9.10 Provide on-site technical expertise at multiple locations for real-time automatic feedback, exercises, demonstrations, and fielding at/between multi-agency laboratories/organizations.
4.1.9.11 Perform site surveys, site installations and on-site technical expertise for cyber technologies.
4.1.9.12 Conduct on-site assessment and maintenance of cyber capabilities to identify problem areas, recommend solutions and implement bug fixes.
4.1.9.13 Develop work plans and schedules to manage and accomplish new installations of cyber technologies.
4.1.9.14 Integrate cyber technology with the fielded systems.
4.1.9.15 Deliver all supporting information and documentation developed or acquired to train, operate, install and maintain the cyber technology.
4.1.9.16 Prepare and develop documentation and conduct testing and evaluation required for DoD/Air
Force certification and accreditation (C&A) to support operational fielding.
4.1.9.17 Determine Life Cycle Costing requirements for any operational/fielded cyber technology.
4.1.9.18 Determine Design-To-Cost requirements for any operational/fielded cyber technology.
4.1.9.19 Provide on-site familiarization and training of cyber technologies, their applications and tools.
4.1.9.20 Use a configuration management process for managing the development and integration of any delivered software. The software development process may include, but not be limited to, the following activities: Systems Requirements Analysis/Design, Software Requirements Analysis, Preliminary/Critical Design, Detailed Design, Coding and Computer Software Configuration Item
Testing, System Integration and Testing, and Software/System Security Certification and Accreditation.
4.1.10 Facilitate Technology Transition
4.1.10.1 Enhance and operate cyber technologies developed and transitioned under this effort. Perform support through initial operations, maintenance and administration of data and information components, products or systems including engineering to address Operations & Maintenance (O&M) problems such as:
4.1.10.1.1 Problem Reports (PRs) and Change Requests (CRs), as identified in each applicable order.
4.1.10.1.2 Studies, analyses and recommendations on modifications, upgrades, and future enhancements/increments.
4.1.10.1.3 Interoperability, technology or process improvement.
4.1.10.1.4 System or architecture obsolescence.
4.1.10.1.5 Aging system or architecture issues.
4.1.10.1.6 Upgrades for Joint or Service commonality and interoperability.
4.1.10.1.7 Transition enhancements of system or architecture affordability, reliability, and supportability, while maintaining readiness.
4.1.10.2 Make module changes and enhancements to meet emerging user requirements, changing operating environments, and to resolve problems identified with the system. Provide baseline maintenance for all system and software configurations under a Government defined operational baseline. Update/revise system documentation.
4.2 Program Management
4.2.1 Continually determine the status of each order and report progress towards accomplishment of the requirements.
4.2.2 Continually determine the status of funding required for order performance.
4.2.3 Conduct oral presentations at such times and places designated in the order schedule. Provide status of technical progress made to date in performance of the order during presentations.
4.2.4 Update Government Furnished Documentation in the form of revisions. Format of the changes shall not deviate from that of the existing documentation without prior Government approval.
4.2.5 Document all technical work accomplished and information gained during performance of each
Order. Include all pertinent observations, nature of problems, positive and negative results, and design criteria established where applicable. Document procedures followed, processes developed, “Lessons
Learned”, etc. Document the details of all technical work to permit full understanding of the techniques and procedures used in the evolving technology or processes developed. Cross-reference separate design, engineering, or process specifications delivered to permit a full understanding of the total acquisition.
4.3 Software/Hardware
4.3.1 Deliver all software/hardware developed, modified, enhanced, assembled, or acquired to the
Government in accordance with each order and the following:
4.3.1.1 All software developed shall be delivered to the Government in the form of source and object code.
4.3.1.2 Developed software is to be completely maintainable and modifiable with no reliance on any non-delivered computer programs or documentation.
4.3.1.3 For all software/hardware purchased or licensed, arrangements shall be made for licensing and maintenance agreements to be transferred to the Government upon the completion of each order.
4.3.1.4 Document the cyber developments in accordance with the Contract Data Requirements List
(CDRL).
4.3.1.5 Design and develop all computer software using an approved Higher Order Language (HOL).
Base the justification for the HOL selected on system interface, interoperability, communications functions, human interface, and requirements for security, safety, and reliability. Design the software to make use of existing software and for subsequent reuse to the maximum feasible extent.
4.3.1.6 The Air Force Computer Emergency Response Team (AFCERT) issues advisories to identify known vulnerabilities in computers and computer networks. These advisories include but are not limited to Information Assurance Vulnerability Alerts, Virus notification, Advisory Compliance
Messages (ACMs), and Follow-up Messages. The Contractor shall report suspected vulnerabilities and security incidents in accordance with AFSSI 5021. The Contractor shall respond to AFCERT advisories in accordance with AFSSI 5021 as follows.
4.3.1.6.1 Acknowledge receipt of AFCERT advisories within three (3) days of issue.
4.3.1.6.2 Implement the countermeasures identified by the advisory within the timeframe specified by the advisory or as specified by the Government. If the countermeasures cannot be implemented, the
Contractor shall document the inability and must receive approval from the Designated Approving
Authority (see AFI 33-202) and the Government for either an alternative corrective action to continue operations without the countermeasures. If alternative corrective action is approved, the Contractor shall implement this action within the timeframe specified by the Government.
4.4 Safety.
4.4.1 Comply with all safety and health requirements necessary for the protection of personnel, facilities and equipment including, but not limited to, the Occupational Safety and Health
Administration (OSHA) standards, while performing this contract at the Air Force Research Laboratory
(AFRL), Rome Research Site (RRS), Rome NY. It is the Contractor’s sole responsibility to make certain that all safety requirements are met.
4.4.1.1 Maintain a written safety program for compliance with the applicable OSHA standards, and make said plan available for review by the Government upon request by the contracting officer.
4.4.1.2 In the event of a mishap, or a “near miss”, during the performance of this contract at AFRL
RRS, notify the Procuring Contracting Officer and the AFRL RRS Safety Office in an expeditious manner. Provide written notification to the contracting officer within 72 hours that includes the following information (RRS Form 2 Supervisors Mishap Data Worksheet may be used):
a. Contract, Contract number, Name and Title of Person(s) Reporting b.Date, Time and exact location of accident/incident
c. Brief Narrative of accident/incident (events leading to accident/incident) d.Cause of accident/incident (if known)
e. Type of injuries resulting from the accident/incident and estimated cost of accident/incident
(material and labor to replace/repair)
f. Nomenclature of equipment involved in accident/incident g.Personnel involved in accident/incident h.Corrective Actions (taken or proposed)
i. Other pertinent information
4.4.2 AFRL RRS is in the process of pursuing OSHA Voluntary Protection Program (VPP) recognition. All Contractors are required to familiarize themselves with the requirements of VPP and ensure employees and managers have a comprehensive understanding of VPP. Detailed information on
VPP is available at the OSHA website at http://www.osha.gov/dcsp/vpp/index.html. On-site
Contractors are required to attend a Local Conditions Course as part of in-processing at AFRL RRS.
4.4.2.1 If Contractor or subcontractor(s) employees work more than 1,000 hours per quarter on-site at the AFRL, Rome Research Site (RRS), the following applies:
4.4.2.1.1 Submit Total Case Incidence Rate (TCIR) and Days Away, Restricted and/or Transfer Case
Incident (DART) Rate and an OSHA Form 300A, Annual Summary of Work-Related Injuries and
Illnesses, to the contracting officer and the AFRL RRS Safety Office by 15 January each year. AFRL
RRS will consolidate and submit this information as part of the installation’s annual VPP Safety and
Health Management Report. The TCIR is the total number of recordable injuries and illness cases per
100 full-time employees that a site has experienced in a given time frame. The DART rate is the number of recordable injuries and illness cases per 100 full-time employees resulting in days away from work, restricted work activity, and/or job transfer that a site has experienced in a given time frame.
4.4.2.1.2 Submit a Safety and Health Plan and corresponding site safety checklist to the contracting officer within 10 days after contract award. The plan shall include appropriate measures to ensure the
Contractor reacts promptly to investigate, correct and track alleged safety & health violations and/or uncontrolled hazards in Contractor work areas.
4.4.2.1.3 Include the name and phone number of the person who will be the primary point of contact for safety and health issues for the on-site operation. Keep the contract safety manager information current by notifying the contracting officer of any change in personnel or contact information.
4.4.2.1.4 Demonstrate a management commitment to employee safety and health;
4.4.2.1.5 Identify the application of the safety and health plan to subcontractors;
4.4.2.1.6 Identify the roles and responsibilities of:
a. Management
b. Supervisors
c. Employees
d. Safety Coordinator
4.4.2.1.7 Identify applicable safety rules and regulations;
http://www.osha.gov/dcsp/vpp/index.html
4.4.2.1.8 Include a worksite hazard analysis to include base-line hazard identification and required control measures;
4.4.2.1.9 Include a job site analysis to include hazards of tasks required to control measures;
4.4.2.1.10 Identify employee safety and health training requirements and the documentation process;
4.4.2.1.11 Include a workplace inspection frequency, to include identifying the individual conducting the inspections;
4.4.2.1.12 Include employee hazard reporting procedures;
4.4.2.1.13 Identify individual(s) responsible for corrective action of hazards;
4.4.2.1.14 Identify first aid/injury procedures;
4.4.2.1.15 Identify procedures for accident investigation and reporting;
4.4.2.1.16 Identify emergency response procedures; and
4.4.2.1.17 Identify the process for tracking controlled hazards in Contractor work areas.
4.4.2.1.18 Identify disciplinary methods that will be used to discourage willful or repeated non-compliance by employees.
File details come from the government source that posted it. Updated .