AF_DCO_MS_PWS_28_Aug_14.pdf

PDF 474 KB Posted

Attached to
33rd NWS AF DCO Mission Services Federal contract opportunity
Solicitation number
FA8773-14-R-8001
Issued by
Department of the Air Force Space Command

About this file

Performance Work Statement (PWS)_dated 28 Aug 2014

View the file

Other files for this federal contract opportunity

Other files attached to 33rd NWS AF DCO Mission Services, newest first.
File Type Posted
AF_DCO_MS_PWS_21_Oct_14.pdf PDF
SF30_Amend_0001.doc DOC document
FA8773-14-R-8001_QA_V1_21Oct.pdf PDF
Section_L_Atch_2_PP_Questionaire_Tracking_Record_Mission.doc DOC document
DD_Form_254_(Mission_Services)Pre-award.pdf PDF
Section_L_Atch_3_PP_Sample_Questionnaire_Cover_Letter_Mission.doc DOC document
CDRLS_A001-A008.pdf PDF
Section_L_Atch_1_PP_Questionnaire_Mission.docx DOCX document
254_Attachments_MissionServices.pdf PDF
Pricing_Table__DCO_MS_11Sep14.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE-BASED WORK STATEMENT (PWS)

FOR

AIR FORCE

DEFENSIVE CYBER OPERATIONS (DCO) MISSION SERVICES

rd

Network Warfare Squadron (33 NWS)

Lackland Air Force Base

San Antonio, Texas 78236

28 Aug 2014

Table of Contents

1 INTRODUCTION

2 BASIC REQUIREMENTS

3 PERFORMANCE REQUIREMENTS

4 SERVICE SUMMARY & DELIVERABLES

5 GOVERNMENT FURNISHED PROPERTY

6 SPECIAL REQUIREMENTS

7 APPENDICES

1 INTRODUCTION

1.1 Objective

This contract will provide essential capabilities to provide support to the 33 NWS in conducting its mission of Air Force (AF) Defensive Cyberspace Operations (DCO) for the AF and supported unified commands and their combatant commanders. The AF Gateways serve as the AF Network (AFNet) boundary and external connectivity through the Defense Information Systems Network (DISN) to the Internet. The 33 NWS implements the AF DCO deployed capabilities consisting of activities and operations to counter network exploits and attacks, to dynamically defend and protect the AFNet and provide mission assurance for the AF and supported combatant commands. The 33 NWS AF DCO mission consists of multi-faceted roles and responsibilities spanning cyber defense, network operations, and information protection. This contract will support the 33 NWS’s 24 hours a day/seven days a week/365 days a year (24/7/365) mission of AF DCO.

Additionally, the 33 NWS expects the contractor to leverage every opportunity to identify/suggest improvements to existing AF DCO processes, operating procedures, training, systems and applications over the current operations across all functional areas.

1.2 Background

1.2.1 The 33 NWS is the AF’s primary operational unit providing DCO (i.e., cyber defense) for the

AF’s cyber domain. The 33 NWS DCO mission activities span to functional areas of cyber defense, operations and security, protection, and mission assurance support for AF operations and missions conducted on AF computers, networks, and network enclaves, to include those of supported unified commands. DCO, cyber defense, and computer network defense (CND) can be used interchangeably, although the current preferred usage is DCO.

1.2.2 The 33 NWS conducts its cyber defense mission in support of the 24th AF Network Operations

Commander [AFNetOps/Commander (CC), 67th Cyberspace Wing (67 CW), under the AF Space

Command (AFSPC)]. The 33 NWS also conducts responsibilities for cyber defense reporting to the

624th Operations Center (OC), which supports centralized strategic AF enterprise situation awareness and command and control (C2).

1.2.3 The 33 NWS DCO mission is categorized in functional areas that require monitoring host computer and network activity to detect, identify, contain and respond to anomalous, suspicious and/or malicious events on the AF’s and supported unified commands’ systems and networks [classified and unclassified internet protocol (IP)].

1.2.4 The 33 NWS is responsible for the execution of several DCO tasks to include network forensics based on identified cyber incidents/investigations, countermeasures engineering and development, computer system and blue force network vulnerability assessments, e.g. AF’s Assured Compliance

Assessment Solution (ACAS), Gateway and Information Operations Platform (IOP) Intrusion Detection

System/Intrusion Prevention System (IDS/IPS) sensor operations maintenance, mission enclave systems operations and maintenance, database management, applications, network, and system administration.

These tasks and other supporting functions provide the capabilities necessary for detection, identification, isolation, containment, resolution and prevention of unlawful acts which may deny unauthorized users access to or corrupt information resident on Automated Information Systems (AIS) or network traffic traversing AF networks. Therefore, successful implementation of DCO tasks, and successful contract support provided under this PWS, will reduce risks to the Department of Defense

(DoD) warfighter and preserve the military capabilities of the AF during peacetime, crisis, and war.

1.3 Scope

The contractor shall be required to plan, implement, and execute the 33 NWS-managed AF DCO mission. In addition, contractor support is required for conducting analysis of all network defense events, alerts, and traffic on all network IDS and IPS, Non-secure Internet Protocol Router Network (NIPRNet) and Secure

Internet Protocol Router Network (SIPRNet). Also, contract support is required for 24/7/365 operations to isolate, contain, and prevent intrusive activities on AF AIS and networks on both NIPRNet and SIPRNet.

The requirements for this document include all aspects of DCO analysis to include Real-Time Detection on both NIPRNet and SIPRNet, Incident Response, Forensic, Vulnerability Assessment, Signature Writing, Content Development, and Tactics Development support.

2 BASIC REQUIREMENTS

2.1 Business Relations

The contractor shall work with the Government Contracting Officer Representative (COR) or Government shift lead to accomplish Government requirements, goals, and mission objectives as efficiently and effectively as possible. This shall include sharing or coordinating information resulting from the work required within the PWS or previous Government efforts and working as a team to perform tasks in concert.

The contractor shall ensure minimum duplication of effort in execution of all work specified within this PWS and build upon work previously accomplished by the Government, the contractor, or other contractors to the fullest extent practical.

2.2 Non-Personal Services

The Government shall neither supervise contractor nor control the method by which the contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of nature of personal services, or give the perception of personal services. If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor’s responsibility to notify the Contracting Officer (CO) immediately.

2.3 Contract Administration and Management

2.3.1 Work Personnel Staff. The contractor shall ensure the numbers of personnel, job category and expertise of the personnel assigned are sufficient to cover the work specified within this PWS. The contractor shall notify the COR of any personnel re-assignments. The contractor shall maintain proficiency in each functional area listed within the PWS at its own expense (e.g., for DoD Directive

(DoDD) 8570.01-M certification and Information Assurance (IA) training found in Appendix D).

2.3.1.1 The contractor shall fully cooperate with the Government and other contractors assigned to the same functional areas, raising the level of proficiency and effectiveness as it engages the adversarial threat from around the world.

2.3.1.2 The contractor shall assign one of the full-time, DoDD 8570.01-M certified employees as task lead and at least one additional full-time, DoDD 8570.01-M certified employee as alternate task lead. This individual shall have full contractor authority to act in all contract matters and be responsible and accountable to the CO in representing the contractor for meeting the performance requirements of this PWS. The task lead shall be available during normal duty hours, Monday through Friday, except Federal Holidays, to meet with the COR or Government shift lead to discuss program and/or technical issues. The task lead shall attend scheduled staff meetings, as requested by the COR.

2.3.1.3 In accordance with (IAW) DoDD 8570.01-M, Information Assurance Workforce

Improvement Program, all contractors assigned to perform IA, Computing Environment

(CE)/Infrastructure Support (IS), and Computer Network Defense Service Provider (CNDSP) functions shall have a current Information Assurance Technical (IAT) or IA Managing Level certification, and the applicable CNDSP and CE/IS specialty certification. The certificates must be provided to COR during squadron in-processing. Throughout the course of this contract, internal movement of personnel will require updated certifications prior to move. The minimum certification/training requirements shall be maintained as an electronic record through a maintained shared network drive location. Contractor personnel must provide proof of release of certification to the DoD via Defense Workforce Certification Application (DWCA). The associated CNDSP specialty requirements are:

2.3.1.3.1 The contractor shall complete all 67 CW and 33NWS required training. This shall include Operations Security (OPSEC), Force Protection, Human Relations, Security and Information Protection training. The contractor will also abide by AFSPC General

Memorandum (GM) 10-01 (to be replaced by Air Force Instruction (AFI) 10-1703

Volume 1, Cybercrew Training) when performing a Mission Ready (MR) function.

2.3.1.3.2 The contractor shall utilize approved 33 NWS mission support systems such as the 33 NWS web sites, the AF Portal, SharePoint, Remedy, the Computer Security

Assistance Program (CSAP) Database System (CDS), ArcSight, Joint Computer

Response Team (CERT) Database, Griffin Operations Portal (GOP), NIPRNET, SIPRNET, and Joint Worldwide Intelligence Communications System (JWICS) Intelink to distribute NetD information to AF units.

2.3.1.3.3 The contractor shall work in a closed system environment where all code, documentation, and project management information will be kept.

2.3.1.3.4 The contractor shall support the enhancement of AF DCO-related tactics, techniques, and procedures (TTPs), processes, systems and applications by utilizing existing processes, and where-by suggesting possible improvements. This shall include

AF Form 1067 submittals online, engineer software change requests, other automated processes, and by attending operations and mission support meetings to discuss, help document, and prioritize mission requirements.

2.3.1.4 AFI 11-202V3 stipulates that all personnel working on a "weapon system" will have at least 12 hours of crew rest between shifts. Contractor shall ensure they provide sufficient contractor personnel to allow for 12 hour crew rest.

2.3.2 Contract Management.

2.3.2.1 The contractor shall conduct at least one formal Technical Interchange Meeting (TIM) per quarter. The contractor or Government may schedule additional informal meetings to review deliverables, address any issues, and review contract status. Contractor shall provide meeting minutes for the TIM. (Contract Data Requirements List (CDRL) A001)

2.3.2.2 The contractor shall prepare and disseminate operational reports. The contractor shall provide all operational reports to the requesting 33 NWS Point of Contact (POC) and COR.

Additionally, the contract lead for each position will provide the Government Section Lead a

Weekly Activity Report (WAR) every week highlighting the work accomplished. (CDRL A002)

2.3.2.3 Contractor shall provide an Employee Work Schedule consisting of all personnel at least

14 calendar days, in advance, and notify the COR to support deconfliction of operational schedules. This document shall list employees’ names and functions they support, be updated on a continual basis as changes occur and located on a shared network drive. Any unforeseen calendar changes shall be coordinated with the COR within hours of notification of change. This information is vital and ensures the 24/7/365 mission is covered during times of emergency and provides the 33 NWS Crew Commander a list of contract personnel who are available to contact in emergency situations and to keep accountability in emergency situations. Contractor shall identify all acronyms, codes, abbreviations, signs and symbols used in each record. Contractor format is acceptable, but contractor shall use the same format for initial and all subsequent submissions of the same record unless otherwise approved by the COR.

2.3.2.3 The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the DCO effort via a secure data collection site. The contactor is required to completely fill in all required data fields using the following web address http://www.ecmra.mil. Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs

October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. Contractors may direct questions to the Enterprise-wide Contractor Manpower Reporting Application (ECMRA) help desk.

2.4 Contractor Employees

2.4.1 The contractor shall not employ any person for work on this contract if such employment is identified to the contractor by the CO as a potential threat to the health, safety, security, general wellbeing, or operational mission of the installation and its population.

2.4.2 All contractor employees shall be able to read, write, speak and understand the English language to the extent necessary in the performance of this work.

2.4.3 The contractor shall not employ any person who is an employee of the United States (US)

Government if employing that person would create a conflict of interest. Additionally, the contractor shall not employ any person who is an employee of the Department of the AF, unless such has been approved IAW DOD 5500.7-R, Joint Ethics Regulation.

http://www.ecmra.mil/

2.4.4 Contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification with Government personnel. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversations and in formal written correspondence.

2.4.5 The office environment at the 33 NWS is predominately business casual. Daily attire is considered to be business casual or the contractor company logo apparel and slacks, depending on position and duties.

2.5 Contractor Common Access Cards (CAC)

The contractor shall be identified with a CAC marked by a vertical green stripe. The CAC shall be worn by employees in such a standardized manner as to be clearly visible except when in use (i.e. inserted in a computer CAC reader). Contractor personnel shall be identified by their 24 AF and Air Force

Intelligence Surveillance Reconnaissance Agency (AFISRA) Form 325 (Green Badge) with name, “CONTRACTOR”, and contract expiration date clearly visible and worn above the belt and below the shoulders when present within the TOP SECRET Sensitive Compartmented Information Facility (SCIF) as proof of proper clearance to remain unescorted within the SCIF. When exiting, the contractor personnel shall conceal their credentials from plain view. To access any Government base and certain facilities, the contractor personnel shall present and wear (if required) their contractor CAC identified by a vertical green stripe, in a similar matter as the Form 325 where clearly visible.

2.6 Work Locations

The contractor shall support the 33 NWS’ 24/7/365 mission at the following locations. The task lead will be notified of change in work location one hour in advance. All contractor personnel are expected to relocate within the one hour timeframe. One hour timeframe includes time taken by the task lead to reach affected personnel.

2.6.1 33 NWS Operations. 33 NWS operations are located in Building 16000 at the Lackland AFB, San Antonio, Texas site.

2.6.2 Alternate Operations Location. 33 NWS’ Alternate Operating Location (AOL) and Building

178/179, at Kelly USA, also known as Port San Antonio or other designated AOL locations within the

San Antonio metropolitan area when directed by the COR or Government shift lead.

2.6.3 Remote COOP. 33 NWS’ Continuity of Operations (COOP) site shall be utilized in the event an interruption of services occurs. The task lead will identify contractor personnel deploying to the COOP location and provide names to the 33 NWS COR and Government shift lead.

2.7 Travel Requirements

Travel shall be required under this contract to support 33 NWS mission activities. The contractor shall be required to travel within Continental US (CONUS) and Other than Continental US (OCONUS) to a base location(s) or AF site(s) affected by a computer incident, installation and maintenance of Griffin Cyber

Defense Systems (GCyDS)-related equipment, planning conferences, and exercises. All travel requirements

(including plans, agenda, itinerary, dates) shall be pre-approved by the CO, and are on a cost reimbursable basis. Costs for travel shall be billed IAW the Joint Travel Regulation and Federal Acquisition Regulation

(FAR) 31.205-46, Travel Costs. Government contractors presenting themselves for travel shall have letters of identification and shall require passports for OCONUS travel. Government Contract City Pair fares are not available to contractors. The contractor shall submit a trip report to the COR within five business days detailing the work completed, lessons learned, and applicable recommendations. The trip report shall include a copy of the traveler’s submitted travel voucher. (CDRL A003).

3 PERFORMANCE REQUIREMENTS

The contractor shall provide sufficient personnel to meet mission requirements on a 24/7/365 basis. The contractor shall ensure there is no instance when any function in this section is not being performed.

3.1 NIPR Real-Time Detection

3.1.1 The contractor shall conduct near real-time network security monitoring and intrusion detection analysis for the NIPRNet using the AF's selected IDS/IPS tools and activities related to 33 NWS mission execution. All Near Real-Time IDS/IPS alerts shall be reviewed per 33 NWS Operating Instruction (OI) and checklists. 33 NWS specific operational training (i.e., process/procedures and checklist familiarization) will be conducted by the Government to maintain operational proficiency.

3.1.2 The contractor shall also conduct near real-time network security monitoring and intrusion detection analysis for the NIPRNet using the AF's selected IDS/IPS tools and activities related to 33

NWS mission execution at the COOP location on a 24/7/365 basis and incorporate into daily operations.

The contractor shall be responsible for all network security monitoring and intrusion detection during emergency situations or system/network outages at the 33 NWS operations floor at Lackland AFB.

3.1.3 The contractor shall analyze NIPR DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities. The contractor shall enter event data into mission support systems IAW 33 NWS operational procedures and reports through the 33 NWS chain. The contractor shall record suspicious events, meeting established 33 NWS thresholds, into the operational database for suspicious traffic. These records shall contain sufficient information to stimulate future analysis of suspicious traffic. The record shall answer the: who, what, where, why and when for this suspicious activity. The contractor shall compile suspicious events records and other artifacts as part of its Monthly Operational Report. (CDRL A006)

3.1.4 The contractor shall provide pass-on information to bring incoming crews up to speed on latest suspicious traffic seen from a given port, Internet Protocol (IP), etc.

3.1.5 The contractor shall provide computer security-related support to AF field units (example: the

Integrated Network Operations and Security Center (INOSC), Base Information Assurance shop) in countering vulnerabilities, minimizing risk, and improving the security posture of AF computer networks and systems within the scope of 33 NWS operational requirements and mission execution.

3.1.6 The contractor shall provide focused DCO, tailored analysis and monitoring operations of specified sensor locations during contingency operations and in support of named DCO operations and exercises.

3.2 SIPR Real-Time Detection

3.2.1 The contractor shall conduct network security monitoring and intrusion detection analysis for the

SIPRNet using the AF's selected IDS/IPS tools, consolidators, and activities related to 33 NWS mission execution. The contractor shall not perform consolidator integration involving content development or signature management. However, contractor shall provide written and verbal input for content development and signature management. The 33 NWS specific operational training (i.e., process/procedures and checklist familiarization) will be conducted by the Government to maintain operational proficiency.

3.2.2 The contractor shall analyze SIPR DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities. The contractor shall not perform historical site batch analysis; however, contractor shall correlate real time suspicious events with data stored within 33 NWS databases and other resources. The contractor shall enter event data into mission support systems IAW 33 NWS operational procedures and reports through the 33 NWS chain. The contractor shall record suspicious events, meeting established 33 NWS thresholds, into the operational database for suspicious traffic. These records shall contain sufficient information to stimulate future analysis of suspicious traffic. The record shall answer the: who, what, where, why and when for this suspicious activity. The contractor shall compile suspicious events records and other artifacts as part of its Monthly Operational Report. (CDRL A006)

3.2.3 The contractor shall provide pass-on information to bring incoming crews up to speed on latest suspicious traffic seen from a given port, IP, etc..

3.2.4 The contractor shall provide computer security-related support to AF field units (example: the

Integrated Network Operations and Security Center (INOSC), Base Information Assurance (IA) shop) in countering vulnerabilities, minimizing risk, and improving the security posture of AF SIPRNet within the scope of 33 NWS operational requirements and mission execution.

3.2.5 The contractor shall provide focused DCO, tailored analysis and monitoring operations of specified sensor locations during contingency operations and in support of named DCO operations and exercises.

3.3 Content Development

3.3.1 The contractor shall manage the Active Lists for the current DCO real-time alert correlation tool

(currently ArcSight managers) on NIPRNet and SIPRNet. The contractor shall also obtain the ArcSight

Certified Advanced Energy and Sustainability Management Content for Security Use Cases from

Hewlett Packard. The contractor shall analyze NIPR DCO events as described in 3.1.3.

3.3.2 The contractor shall coordinate via the COR or Government shift lead with the Signature

Management Team (SMT) when deploying new signatures to implement alert lists within ArcSight to provide the most up-to-date content.

3.3.3 The contractor shall create and maintain ArcSight resources such as rules, filters, lists, trends, and reports to satisfy reporting functions at the 33 NWS.

3.4 Incident Response

3.4.1 The contractor shall perform network traffic analysis and log analysis to evaluate intruder activities using host and network-based monitoring systems and logs. The contractor shall correlate information gathered to provide AF networks effective methods to protect their domains. The contractor shall determine the probability of exploitation of discovered network vulnerabilities. The contractor shall ensure appropriate notification action is taken to reduce the risk to all AF networks.

3.4.2 Upon identification of suspicious activity on AF networks, the contractor shall open and conduct network intrusion investigations to validate the unauthorized activity and determine the type and extent of activity.

3.4.3 The contractor shall manage all investigation/incident cases on suspected and confirmed compromised AF systems to determine the method of intrusion and corrective actions to be taken to prevent or detect similar future activities. The contractor will author an opening and closing Incident

Report for every confirmed incident on the AFNet. (CDRL A005)

3.4.4 The contractor shall provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter-intelligence activities. The contractor shall continue to conduct base network defense while OSI collects network evidence. The contractor shall provide support to AF network administrators on the installation and analysis of packet sniffers on their network topology in support of OSI directed activity.

3.4.5 The contractor shall support incident response deployment with same day notice. This travel will allow responders to support the retrieval of hard drives or miscellaneous storage media, isolate system(s) for additional investigation, and perform other on-site Incident Response actions identified above in paragraphs 3.4.1 - 3.4.4. Reference paragraph 2.7, Travel Requirements.

3.4.6 The contractor shall develop cyber countermeasures based on findings during investigations and/or incident handling procedures.

3.5 Forensics

3.5.1 The contractor shall conduct network and computer forensics on suspected and confirmed compromised AF systems to determine the method of intrusion and corrective actions to be taken to prevent or detect similar future activities. The contractor shall document all findings in the investigation/incident log. The contractor shall confirm malicious activity when new information is identified through the course of forensic analysis.

3.5.2 The contractor shall perform software reverse engineering of suspected malicious files to verify if system compromise occurred. The contractor shall document all findings in the investigation/incident log for each file.

3.5.3 The contractor shall perform Hard Drive Analysis of suspected/confirmed infected system. The contractor shall document all findings in the investigation/incident log for each hard drive.

3.5.4 The contractor shall develop methods to identify, contain, log, and analyze malware-based activities on AF AIS and networks.

3.5.5 The contractor shall provide AF OSI DCO technical support to law enforcement and counter-intelligence activities. The contractor shall continue to conduct base network defense while AF OSI collects network evidence. The contractor shall provide support to AF network administrators on the installation and analysis of packet sniffers on their network topology. The contractor shall turn any investigation over to AF OSI if it is determined during the course of an investigation a law was broken.

3.5.6 The contractor shall support incident response deployment with same day notice. This travel will allow responders to support the retrieval of hard drives or miscellaneous storage media, isolate system(s) for additional investigation, and performing other on-site Incident Response actions.

Reference paragraph 2.7, Travel Requirements. In addition, the contractor shall be required to set up a monitor or “cage” at the on-site location.

3.6 Signature Writing

3.6.1 The contractor shall develop methods to identify, contain, log, and analyze intrusive activities and security vulnerabilities on AF AIS and networks. The contractor shall develop methods to detect and prevent intrusive activities utilizing these new vulnerabilities and exploits The contractor shall conduct operations and develop countermeasures (to include IDS/IPS signature development, policies, and correlation rule sets) to isolate, contain, alert, and prevent intrusive activities and security vulnerabilities on AF AIS and networks. The contractor shall implement signatures on IDS/IPS/Host based Intrusion

Protection System (HIPS) devices.

3.6.2 The contractor shall develop methods to identify, contain, log, and analyze malware-based activities on AF AIS and networks. The contractor shall provide specialized anti-virus support to AF field units.

3.6.3 The contractor shall develop cyber countermeasures based on findings during investigations and/or incident handling procedures.

3.7 Vulnerability Assessment

3.7.1 The contractor shall perform analysis on current and new vulnerabilities which may affect the AF and draft Time Compliance Network Orders (TCNOs), Notice to Airmen (NOTAMS), and Mission

Tasking Orders (MTOs). The contractor shall collaborate with AF, DoD, Government, and commercial groups to stay apprised of emerging network threats and associated mitigation strategies.

3.7.2 The contractor shall provide technical standardization of time critical reports, manage historical documentation, and maintain on-line vulnerability tracking and incident response databases. The contractor shall update the AF’s black hole list and blocked domain list.

3.7.3 The contractor shall analyze suspected malicious logic events and provide guidance to the field concerning potential virus infections and courses of action.

3.7.4 The contractor shall process and coordinate with the COR or Government shift lead all Malicious

Logic Reports (MLRs) as submitted from the field.

3.7.5 The contractor shall perform Blue Assessment scans of AF forward facing public websites. The assessments will be uploaded into the Defense Information Systems Agency (DISA)’s vulnerability management website for fix actions performed by the base.

3.8 Tech Writing

3.8.1 The contractor shall write, edit, and coordinate with the COR all AF Cyber Incident Reports

(AFCIRs) on root level, user level, denial of service, and severe malicious log incidents. The reports shall include any intelligence documentation discovered. (CDRL A005)

3.8.2 The contractor shall assess all technical documentation for appropriate classification.

3.8.3 The contractor shall finalize and distribute TCNOs, NOTAMs, and MTOs for release to the community.

3.9 Tactic Developing

3.9.1 The contractor shall ensure all Tactics Developing personnel are qualified instructors certified for performing the MR functions. In order to maintain this certification and proficiency, the contractor shall work crew positions as defined in Squadron’s current Director of Operations-Training OI 36-2201.

Training is considered on-the-job training for the squadron.

3.9.2 The contractor shall develop and document new Tactic Improvement Proposals (TIPs), and

Tactics, Techniques, and Procedures (TTPs) for DCO operations. The contractor shall support the integration of new equipment into daily operations and exercises by creating new TTPs for DCO functions. New TIPs/TTPs shall be documented on the appropriate weapons and tactics forms.

3.9.3 The contractor shall develop, lead, narrate and provide presentations, briefs, and debriefs. The contractor should support the identification of deficiencies in training, equipment, support or tactics which preclude optimum mission accomplishment. Identified deficiencies shall be documented via approve reporting procedures and tracked by the COR in the 33 NWS database. (CDRL A007)

3.9.4 The contractor shall maintain the unit’s tactics library. The contractor shall ensure appropriate tactics related study materials are available for unit personnel.

3.9.5 The contractor shall participate in Operations Review Panels/Boards (ORP/ORB) to aid in root cause analysis. The contractor shall provide meeting minutes within 2 working days of the ORP/ORB conclusion.

3.10 AF DCO Operations Contingency Support

3.10.1 The contractor personnel shall relocate to the 33 NWS AOL IAW established COOP procedures and operational checklists if required due to critical infrastructure failure or infrastructure upgrades.

3.10.2 The contractor shall attend planning meetings to discuss activities such as power outages, communications outages, air conditioning outages, facility related issues, and other events that may require activation of contingency operations.

3.10.3 The contractor shall maintain a 24/7/365 schedule. In support of the 33 NWS operational mission, contractor personnel shifts may have to be extended for manning shortfalls and exercise support.

4 SERVICES SUMMARY AND DELIVERABLES

4.1 SERVICES SUMMARY

Performance

Element

Performance Objective PWS Para

Ref

Performance Threshold

1 Operational Reports 2.3.2.2

Draft documents shall be limited

(on average) to five (5) or less errors per page at time of review.

Final documents shall be limited

(on average) to one (1) error per page.

Near Real-Time Detection review 3.1.3

Missed alerts shall be limited (on average) to no more than 20% of all network events a month.

3 COOP support

2.7.3 and

3.1.2

No instance of where the contractor failed to support real time operations at the COOP during an emergency situation at

Lackland.

4 Incident Reports

3.4.3 and

3.8.1

Finalized reports shall be limited

(on average) to no more than five

(5) errors.

AF Cyber Incident Reports

(AFCIRs) 3.8.1

Finalized reports shall be limited

(on average) to no more than five

(5) errors.

Provide sufficient personnel to meet mission requirements on a 24/7/365 basis

3.0 No instance where a function is

not being performed

4.2 Deliverables. The contractor shall use a combination of virtual and physical machines in preparing deliverables.

CDRL Work Product

CDRL A001 Technical Interchange Meeting (TIM)

CDRL A002 Operational Reports/WAR Report

CDRL A003 Trip Reports

CDRL A004 List of Employees (Personnel Changes)

CDRL A005 AF Cyber Incident Reports (AFCIRs)

CDRL A006 Monthly Operations Report (MOR)

CDRL A007 Weapons and Tactics Deliverables

CDRL A008 Quality Control Plan

5 GOVERNMENT FURNISHED PROPERTY AND SERVICES

NONE

6 SPECIAL REQUIREMENTS

6.1 Security Requirements

6.1.1 Industrial Security.

6.1.1.1 Contractor shall follow the security requirements outlined in the contract’s DD Form 254, Department of Defense Security Classification Specification. IAW DD Form 254, the contractor shall obtain a U.S. security clearance at the minimum level of Top Secret (TS)/Specially Compartmented

Information (SCI) for all contractor personnel required to have access to classified information or require IT-II level access. Onsite contractor personnel shall have an active clearance prior to reporting for duty in support of this contract. Interim clearances for newly hired personnel shall be processed as expeditiously as possible since some contractor personnel will be required to utilize the SIPRNET and

/or JWICS to process classified materials; however, this will be on a case-by-case basis. Such clearance must be obtained through the Defense Investigative Services.

6.1.1.2 On contract start date, a minimum of 90% of contractor personnel working within Buildings

178/179, 2000, 2012, 2169, and 16000 shall have a Top Secret (TS)/Sensitive Compartmented

Information (SCI) clearance by Intelligence Community Directives (ICD) 704 eligible with a current

Single Scope Background Investigation (SSBI). The remaining 10% contractor personnel must hold a minimum of a Secret clearance pending the completion of the SSBI, and shall obtain their TS/SCI clearance within 90 days of contract award, or be removed from the contract (except for Gunter Annex).

Contractor personnel working at Gunter Annex, Alabama are only required to possess a Secret

Clearance. After the 90-day contract start period, and throughout the remainder of this contract, no more than 20% of all contractor personnel shall be permitted to work in the 33NWS while awaiting final

TS/SCI clearance.

6.1.2 Visitor Group Security Agreement (VGSA). The contractor shall enter into a long-term VGSA.

This agreement shall outline how the contractor integrates security to ensure effective and economical operation on the installation. Security support includes packaging classified information, mailing and receiving classified materials, implementing emergency procedures for protection of classified information, security checks and internal security controls for protection of classified material and high-value pilferable property. On base, the long-term VGSA may take the place of a Standard Practice

Procedure (SPP).

6.1.3 Operations Security. The contractor shall comply with OPSEC requirements contained in AFI

10-701 and Air Force Information Operations Center (AFIOC) Sup 1 to AFI 10-701, to include all current Critical Information (CI) listings. The contractor shall participate in the 67 CW sustained

OPSEC awareness training or include OPSEC training as part of their on-going security program. The

67 CW OPSEC coordinator will evaluate OPSEC posture of AF contract activities and operations.

6.1.4 Security Clearances. The COR will work closely with the contractor’s Security Officer to ensure compliance with the above requirements. The contractor shall maintain a current listing of employees.

The list shall include employee’s name and level of security clearance. The off-base cleared facility will submit visit requests annually for on-base activity personnel to the COR IAW DoDM 5200.01, Volume

3, Enclosure 2, Paragraph 7, and AFI 31-401, paragraph 5.5. The visitor group’s Facility Security

Officer (FSO) will submit visit authorization requests via Joint Personnel Adjudication System (JPAS) to the 67 CW activity’s Security Management Office (SMO) code. The 67 CW COR serves as sponsor for the visit. A copy of the JPAS visit request will be retained at the contractor’s on-base operating activity location by the 67 CW activity Unit Security Manager (USM). If JPAS is not available, the

FSO may submit a Visitor Authorization Listing (VAL). This employee list should be marked “Subject to the Privacy Act of 1974” for privacy purposes. The list shall be validated and signed by the company

FSO and provided to the CO and COR prior to contract start date, and updated every 90 days thereafter.

The contractor shall provide updated listings whenever an employee’s status or information changes

(CDRL A004).

6.1.5 Facility Security Clearance (FCL). Contractor will require an active Top Secret FCL before being granted access to classified information. Per DoD 5220.22-M, National Industrial Security

Program Operating Manual (NISPOM), an FCL is an administrative determination that a company is eligible for access to classified information or award of a classified contract. In those cases, the contractor will be processed for an FCL at the appropriate level and must meet eligibility requirements for access to classified information. However, the contractor will not be afforded access to classified information until the FCL has been granted. An FCL is valid for access to classified information at the same or lower classification level as the FCL granted.

6.1.6 Information Security and Force Protection. The contractor shall comply with the Information

Security and Force Protection requirements as defined by AFI 31-401(Information Security Program

Management) and AFI 10-245 (Air Force Antiterrorism Standards). The contractor shall participate in the 67 CW sustained Information Security and Force Protection/Anti-terrorism training program. The

67 CW Unit Training Manager will evaluate the training posture of AF contract activities and operations. This requirement is set forth in AFI 31-40, AFI 10-245 and applicable AFSPC and local supplements.

6.1.7 Access Credentials Contractor personnel will be issued facility access credentials upon in-processing and final indoctrination to SCI materials. Contractor personnel are required to display the access credentials when inside of the facility and immediately remove the credential upon departure from the facility. The contractor personnel will be provided a unique PIN which is not to be shared with any other individual. Contractor personnel are required to notify the USM immediately in the event the access credential is lost or stolen.

6.1.8 Physical Security The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured. When authorized in writing by the unit of assignment unit commander, contractors may be authorized to Open/Close the facility. Specific facility

Opening/Closing training will be provided by the unit of assignment USM.

6.2 Continuation of Essential DoD Contractor Services During Crisis

IAW Defense FARS (DFARS) 237.76, PWS paragraphs 3.1- Near Real-Time Detection, 3.2-Incident

Response, 3.3- Forensics , 3.4- Signature Writing and 3.5- Vulnerability Assessment requirements are considered to be mission essential. The contractor shall be required to continue to perform the functions under these requirements at the same level during national crisis. The contractor shall identify to the

Government any employees working under this contract having military mobilization recall commitments.

The contractor shall notify the CO upon activation or recall of any such personnel.

6.3 Quality Assurance (QA)

6.3.1 The COR is the authorized Government representative(s) who will perform assessments of the contractor’s performance.

6.3.2 The COR(s) or alternative(s) will inform the task lead in person when discrepancies occur and will request to make corrective action. The COR(s) or alternate(s) will make a notation of the discrepancy on their assessment checklist with the date and time the discrepancy was noted and will request the task lead (or authorized representative) to initial the entry on the checklist.

6.3.3 Any matter concerning a change to the scope, prices, terms or conditions of this contract shall be referred to the CO.

6.3.4 The services performed by the contractor during the period of this contract shall, at all times and places, be subject to review by the CO or authorized representative(s).

6.4 Quality Control

The contractor shall establish and maintain a Quality Control Plan (QCP) acceptable to the Government to ensure the requirements of this contract are provided as specified. The QCP shall remain in effect during the term of the contract (including any option periods if exercised). The contractor shall retain a copy on site and ensure availability at all times to all members of their on-site staff, as well as the COR and CO. (CDRL

A008).

6.5 Key Control

6.5.1 The contractor shall establish and implement methods of ensuring that all keys and key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons.

6.5.2 The contractor shall immediately report the occurrences of a lost or duplicate key to the COR.

6.5.3 In the event keys, other than master keys, are lost or duplicated, the contractor shall, upon written direction of the CO, rekey or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform rekeying. When the replacement of locks or rekeying is performed by the Government, the total cost of rekeying or the replacement of the lock or locks shall be deducted from the monthly payment due the contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the contractor.

6.5.4 The contractor shall prohibit the use of keys issued by the Government by any persons other than the contractor’s employees. The contractor shall prohibit the opening of locked areas by contractor employees to permit entrance of persons other than contractor’s employees engaged in the performance of assigned work in those areas.

6.6 Lock Combinations

The contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations.

6.7 Hours of Operation (See Appendix C)

6.7.1 Mission Hours of Operation. The contractor shall perform the services required under this contract during the following hours: 24/7/365 days a year, unless otherwise stated in the PWS. The contractor may work past their shift, with prior approval of the CO, extended hours to ensure timely completion of work at no additional cost to the Government.

6.7.2 Core Hours of Operation. The contractor’s key personnel are required to be on-site during core hours. The core hours of operation are Monday through Friday from 0730 to 1630.

6.7.3 Base Closures Due to Emergencies. From time to time, the Center or Base CC may decide to close all or part of a Base in response to an unforeseen emergency or similar occurrence. Such emergencies include adverse weather such as snow or ice, “an act of God”, such as tornado or earthquake, or a Base disaster such as a gas leak or fire. Base closure announcements will normally be disseminated by local television and radio stations.

6.8 Conservation of Utilities

The contractor shall instruct its employees in utilities conservation practices. The contractor shall be responsible for operating under conditions which prevents the waste of utilities as follows:

6.8.1 Lights shall be used only in areas where and when work is actually being performed.

6.8.2 Mechanical equipment controls for heating, ventilation, and air conditioning systems shall not be adjusted by the contractor or by contractor employees unless authorized.

6.8.3 Water faucets or valves shall be turned off after the required use has been accomplished.

6.8.4 Government telephones shall be used only for official Government business.

6.9 Contractor Records

The contractor shall be responsible for creating, maintaining, and disposing of only those Government required records that are specifically cited in this PWS. If requested by the Government, the contractor shall provide the original record or a reproducible copy of any such record within five working days of receipt of the request.

6.10 Government Observations

Government personnel, other than COs and CORs, may from time-to-time, with CO coordination, observe contractor operations. However, these personnel may not interfere with contractor performance or make any changes to the contract.

6.11 General Safety Requirements

6.11.1 The contractor shall conform to the safety requirements contained in the contract for all activities related to the accomplishment of the work.

6.11.2 The contractor shall take such additional immediate precautions as the CO may reasonably require for safety and mishap prevention purposes.

6.11.3 Government offices possess an Emergency Response Plan which details how to maintain a safe work environment in case of an emergency. This plan will be posted on the operations floor and at all building exits to ensure all contractor employees, government facilities and property are secure.

6.11.4 Mishap Notification. The contractor shall notify the COR or 33 NWS Safety Office within one

(1) hour of all mishaps or incidents. A written report of the mishap/incident shall be sent within three calendar days to the COR, who will forward it to the 33rd NWS Safety Office. For information not available at the time of initial written report, the contractor shall provide the remaining information no later than 20 calendar days after the mishap, unless extended by the 33 NWS Safety Office. Mishap notifications shall contain, as a minimum, the following information:

6.11.4.1 Contract, Contract Number, Name and Title of Person(s) Reporting

6.11.4.2 Date, Time and exact location of accident/incident

6.11.4.3 Brief Narrative of accident/incident (Events leading to accident/incident)

6.11.4.4 Cause of accident/incident, if known

6.11.4.5 Estimated cost of accident/incident (material and labor to repair/replace)

6.11.4.6 Nomenclature of equipment and personnel involved in accident/incident

6.11.4.7 Corrective actions (taken or proposed)

6.11.4.8 Other pertinent information

6.11.5 If requested by the COR or 33rd NWS Safety Office, the contractor shall immediately secure the mishap scene/damaged property and impound pertinent maintenance and training records, until released by the 33rd NWS Safety Office. If the government elects to conduct an investigation of the accident/mishap, the contractor shall cooperate fully and assist government personnel in the conduct of investigation until the investigation is completed.

6.11.6 The safety provisions of this contract shall apply to any subcontracts/subcontractors. The contractor shall include a clause in each applicable subcontract requiring the subcontractor's cooperation and assistance in accident reporting and investigation.

6.11.7 The contractor’s Safety Program shall clearly define procedures, personnel qualifications, facilities and required equipment necessary to fulfill the following elements:

Element/Requirement Referenced Benchmark

Mishap Notification/Reporting AFI 91-204 (All)

Housekeeping AFI 91-203 (Ch. 3, Ch. 5)

Material Handling Equipment

(MHE)

AFI 91-203 (Ch. 4 Para. 4.9)

Handling, Storage and use of

Flammable/ Combustible Liquid

AFI 91-203 (Ch. 5 Para. 5.9)

Vehicle Operations AFI 91-203 (Ch. 24)

Tool Control AFI 91-203 (Ch. 24, Para.

24.15.1.2)

Foreign Object Damage (FOD) AFI 21-101 (Ch. 14, Para. 14.19)

Tobacco Use in the Air Force AFI 40-102 (All)

Hazardous Energy Control AFI 91-203 (Ch. 21)

6.12 Housekeeping

The contractor shall ensure the work areas are kept clean and orderly in compliance with federal, state, local health, fire, and safety standards. This shall include trash removal, cleaning modular furniture desktops, and ensuring cleanliness of break area. Contractor is responsible for the disposal of trash generated by its personnel. If contractor personnel choose to utilize communal trash bins, contractor shall assist with trash removal on a rotating basis.

6.13 Base Support

6.13.1 The Government will provide access to the Internet, hardware, software, office space, and any applicable documentation required for performance of this contract.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .