About this file

Atch 1 Performance Work Statement (PWS)

View the file

Other files for this federal contract opportunity

Other files attached to Offensive Cyber Operations (OCO)/Defensive Cyber Operations (DCO) and Real Time Operations and Innovation (RTO&I) SHELTER, newest first.
File Type Posted
FA8773-15-R-0043_Questions_and_Answers_(1).pdf PDF
DD1423-1 _SHELTER_CDRL_A002_(Trip_Report).pdf PDF
FA8773-15-R-0043_Draft_Atch_3_-_Section_L-1.pdf PDF
FA8773-15-R-0043_Draft_Atch_13_-_Reading_Library_Instructions.pdf PDF
DD1423-1 _SHELTER_CDRL_A005_(Computer_Software_Product_End_Item).pdf PDF
FA8773-15-R-0043_Draft_Atch_9_-_Labor_Rate_Tables.xlsx XLSX spreadsheet
FA8773-15-R-0043_Draft_Atch_4_-_Section_M-1.pdf PDF
FA8773-15-R-0043_Draft_Atch_2_-_DD_250.pdf PDF
FA8773-15-R-0043_Draft_Atch_10_-_Pricing_Model.xlsx XLSX spreadsheet
FA8773-15-R-0043_Draft_Atch_5_-_Shelter_Relevancy_Assessment.pdf PDF
DD1423-1 _SHELTER_CDRL_A006_(MSR).pdf PDF
DD1423-1 _SHELTER_CDRL_A001_(Technical_Report).pdf PDF
FA8773-15-R-0043_Draft_Atch_11_-_Task_Order_Pricing_Table.xlsx XLSX spreadsheet
DD1423-1 _SHELTER_CDRL_A003_(Media_Package).pdf PDF
FA8773-15-R-0043_Draft_Atch_7_-_Labor_History.pdf PDF
FA8773-15-R-0043_Draft_Atch_8_-_Shelter_Labor_Matrix.xlsx XLSX spreadsheet
FA8773-15-R-0043_Draft_Atch_12_-_Professional_Compensation_Evaluation.xlsx XLSX spreadsheet
DD1423-1 _SHELTER_CDRL_A004_(SUM).pdf PDF
FA8773-15-R-0043_DRAFT_RFP.pdf PDF
FA8773-15-R-0043_Draft_Atch_6_-_PPQ.pdf PDF
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Draft RFP: FA8773-15-R-0043 Attachment 1

OCO/DCO RTO&I SHELTER Project 15 Nov 15

Performance Work Statement (PWS)

Offensive Cyberspace Operations Defensive

Cyberspace Operations Real-Time

Operations and Innovation Cyber

Development Custom Software Engineering

Services

11/15/2015

Version 4.0

Vision Statement

1 Introduction

1.1 Mission

1.2 Background

1.3 Scope

2 General Requirements

2.1 Non-Personal Services

2.2 Business Relations

2.2.1 Integration and Coordination

2.2.2 Contractor Verification System

2.3 Contract Administration and Management

2.3.1 Contract Management

2.3.2 Contract Administration

2.3.3 Personnel Administration

2.4 Subcontract Management

2.5 Contractor Personnel, Disciplines, and Specialties

2.5.1 Contractor Personnel Certifications and Training

2.5.1.1 DoD 8570

2.5.1.2 Electronic Certification Records

2.5.1.3 Certification and Training

2.5.2 Contractor Personnel Identification

2.5.3 Contractor Identification Card

2.5.4 Contractor Ethics

2.5.5 Contractor Personnel

2.6 Location and Hours of Work

2.7 Travel / Temporary Duty (TDY)

3 Performance Requirements

3.1 Software Development

3.2 Vulnerability Research

3.3 Reverse Engineering

3.4 Network Intrusion Detection/Prevention/Analysis

3.5 Compliance – Detection and Forensic Capability

3.6 Documentation and Studies

3.7 Assist Cyber Operational Familiarization with Tools

3.8 Network and System Administration

3.9 Quality Assurance

4 Special Requirements

4.1 Security and Safety

4.2 Transition

4.3 Government Furnished Materials (GFM)

4.3.1 Government Furnished Property (GFP)

4.3.2 Property of the Government

4.3.2.1 Availability

4.3.2.2 Government Property

4.4 Workspace

4.4.1 Housekeeping

4.4.2 Refuse Collection

4.4.3 Conservation of Utilities

4.5 Contractor Records and Reporting

4.5.1 Contractor Manpower Reporting

4.5.2 Records

4.6 Quality

4.6.1 Quality Control

4.6.2 Quality Assurance Surveillance Plan (QASP)

4.7 Training

4.8 Freedom of Information Act Program

4.9 Contracting Officer Representative

4.10 Continuation of Essential DoD Contractor Services During Crisis

4.11 Contingency Operations

5 Deliverables

6 Related Documents

Appendix A Glossary

Appendix B Definitions

Performance Work Statement (PWS)

Offensive Cyberspace Operations Defensive Cyberspace

Operations Real-Time Operations and Innovation Cyber

Development Custom Software Engineering Services - PWS

Vision Statement

Deliver Asymmetric Advantage; to achieve air, space, and cyberspace superiority in the most efficient and artful way possible.

1 Introduction

The purpose of this Performance Work Statement (PWS) is to identify requirements for supporting the Offensive Cyberspace Operations (OCO) Defensive Cyberspace Operations

(DCO) Real-Time Operations and Innovation (RTO&I) (aka SHELTER) Cyber Development

Custom Software Engineering Services 90 Information Operations Squadron (IOS) at Joint

Base San Antonio Lackland (JBSA-Lackland) AFB, TX and to enhance the capabilities of the

90 IOS cyber assets to improve the cyber warfighters ability to respond to threats to the Air

Force Global Information Grid (AFGIG) and other networks of interest with full-spectrum cyber effects.

1.1 Mission

Innovate, integrate, and deliver cyber capabilities equipping the warfighter to dominate in cyberspace.

1.2 Background

The AFCYBER mission is to extend, operate and defend the Air Force portion of the

Department of Defense network and provide full spectrum capabilities for the Joint warfighter in, through and from cyberspace. The 90th Information Operations Squadron mission involves the research, development and provisioning of a number of different capabilities which contribute to our warfighting effectiveness. The efforts of previous iterations have contributed greatly to enabling this mission and this effort will continue to identify develop, provision and deliver new and upgraded cyber capabilities to warfighters within 24 AF and AFCYBER.

1.3 Scope

The scope of this effort supports Defensive Cyberspace Operations (DCO); Offensive

Cyberspace Operations (OCO); law enforcement (LE), and counterintelligence operations and activities; detection, containment, collection, analysis, and reverse engineering of malicious logic; Command & Control/Situational Awareness services; quality assurance; and innovation integration. This effort involves the discovery, identification, detection, and analysis of previously known and unknown wired/wireless system vulnerabilities (vulnerability research); development and/or identification of capabilities to remotely control or remotely administer and to exploit and mitigate previously known and unknown hardware and operating system vulnerabilities of targeted hosts, servers, systems, routers, switches, wireless devices/protocols such as mobile, cellular, Wi-Fi supporting base stations/internet connectivity, Worldwide Interoperability for

Microwave Access (WiMAX(), Bluetooth, IEEE 802.11, High Powered Cordless Phones

(HPCP), Fixed Wireless Access (FWA), mobile/cellular devices, wireless device OS, internal components, specific models, mobile software apps, and Adaptive Security Appliances (ASA)

(vulnerability engineering); generation of payloads for developed identified capabilities (software engineering); detection, containment, collection, reverse engineering, analysis and mitigation of malicious logic (malware research); threat analysis of discovered vulnerabilities and malware

(threat analysis); support for the installation and operation of development environments

(network/system administration), counterintelligence (CI) research/analysis and support for the development of CI plans, studies, and CI-related activities (counterintelligence) and preparation of supporting documentation including meeting Technical Assurance Standards (TAS) for

Evaluated Level of Assurance (ELA) that the developed product (a software or firmware capability) will perform as expected (Technical Writing).

2 General Requirements

This section describes the general requirements for this effort. The following sub-sections provide details of various considerations on this effort.

2.1 Non-Personal Services

The Government will neither supervise contractor employees nor control the method by which the contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor's responsibility to notify the Contracting Officer (CO) immediately.

These services shall not be used to perform work of a policy/decision making or management nature, i.e., inherently Governmental functions. All decisions relative to programs supported by the contractor shall be the sole responsibility of the Government.

2.2 Business Relations

The contractor shall cooperate, support, and interface with military, government civilians, and other contractors for completion of all tasks.

2.2.1 Integration and Coordination

The contractor shall successfully integrate and coordinate all activity needed to execute the requirement. The contractor shall manage the timeliness, completeness, and quality of problem identification. The contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.

The contractor shall work with the Contracting Officer Representative (COR), the authorized

Government representative, to accomplish Government requirements, goals, and mission objectives as efficiently and effectively as possible. This shall include sharing or coordinating information resulting from the work required within this PWS or previous Government efforts and working as a team to perform tasks in concert. The contractor shall ensure minimum duplication of effort in the execution of all work specified within this PWS and build upon work previously accomplished by the Government, the contractor, or other contractors to the fullest extent practical.

2.2.2 Contractor Verification System

The contractor shall ensure all contractor employees submit verification to the Contractor

Verification System (CVS).

2.3 Contract Administration and Management

The following subsections specify requirements for contract, management, and personnel administration.

2.3.1 Contract Management

The contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned to the requirement. The contractor shall maintain continuity between the support operations at 90 IOS JBSA-Lackland AFB, TX and the contractor's corporate offices.

2.3.2 Contract Administration

The contractor shall establish processes and assign appropriate resources to effectively administer the requirement. The contractor shall respond to Government requests for contractual actions in a timely fashion. The contractor shall have a single point of contact between the Government and Contractor personnel assigned to support contracts or task orders. The contractor shall assign work effort and maintain proper and accurate time keeping records of personnel assigned to work on the requirement.

2.3.3 Personnel Administration

The contractor shall provide the following management and support as required. The contractor shall provide for their employees during designated Government non-work days or other periods where Government offices are closed due to weather or security conditions. The contractor shall maintain the currency of their employees by providing initial and refresher training as required to meet the PWS requirements. The contractor shall make necessary travel arrangements for their employees. The Contractor shall provide the necessary resources and infrastructure to manage, perform, and administer the contract. The contractor shall provide administrative support to their employees in a timely fashion (time keeping, leave processing, pay, emergency needs). The contractor shall keep the work areas clean and orderly in compliance with federal, state, local health, fire, and safety standards.

2.4 Subcontract Management

The contractor shall be responsible for any subcontract management necessary to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance on this requirement. The prime contractor shall manage work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations. Contractors may add subcontractors to their team after notification to the CO or COR.

2.5 Contractor Personnel, Disciplines, and Specialties

The contractor shall accomplish the assigned work by employing and utilizing qualified personnel with appropriate combinations of education, training, and experience. The contractor shall match personnel skills to the work or task with a minimum of under/over employment of resources. The contractor shall ensure the labor categories as defined in the Labor Categories document, labor rates, and man-hours utilized in the performance of each Task Order (PWS line item) issued hereunder will be the minimum necessary to accomplish the task. The Contractor shall employ and maintain a technically trained and experienced work force to fulfill all requirements listed in this PWS.

2.5.1 Contractor Personnel Certifications and Training

The Contractor shall ensure their employees obtain initial and refresher commercial training as required to meet the PWS requirements. The contractor shall keep current with changes on all currently supported commercial applications within the contractor's area of responsibility (AOR).

The contractor shall complete all required Government training by suspense deadlines utilizing

Government training systems (i.e. Safety, Information Assurance, Security, etc.).

2.5.1.1 DoD 8570

The Contractor shall employ and maintain a technically trained and experienced work force to fulfill all requirements listed in this PWS IAW Department of Defense Instruction (DoDI)

8570.01-M. The referenced DoDI requires that any individual (Contractor, Government Civilian or Military Member) that performs Information Assurance Technical (IAT) and/or Information

Assurance Manager (IAM) functions to possess, within six (6) months of assignment of duties, specific certifications. The Government will not pay for these certifications.

2.5.1.2 Electronic Certification Records

The minimum certification and training requirements shall be maintained as an electronic record. Contractor personnel shall provide proof of release for certification(s) to the DoD via the

Defense Workforce Certification Application (DWCA).

2.5.1.3 Certification and Training

The contractor shall update and maintain, at their expense, certifications equivalent to technology owned, operated and maintained by the United States Air Force (USAF) covered by this contract. The Government will notify the contractor in writing when a new certification is required, and the contractor shall have six months to obtain the new certifications for their employees.

2.5.2 Contractor Personnel Identification

Contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification at all times, such as a standardized lanyard that all contract employees wear. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversations and in formal written correspondence.

2.5.3 Contractor Identification Card

Contractors shall be identified with a Government issued identification card (e.g., Common

Access Card (CAC) or unit specified identification card). When required, contractor personnel shall comply with local security policies to wear their identification card in a standardized manner, clearly visible attached to the torso of the exterior garment above the belt and below the shoulders (Except when in use (i.e. inserted in a computer CAC reader) or when in controlled areas requiring other credentials as the primary method of identification). To access any Government base and certain Government facilities, the contractor shall present a required identification card upon demand. Upon exit from Government facilities the contractor shall conceal their credentials (CAC or other credentials) from plain view. The contractor and

Contractor Security Manager/Officer shall coordinate with the COR for Government credential issues.

2.5.4 Contractor Ethics

The contractor shall not employ any person who is an employee of the US Government if employing that person would create a conflict of interest. Additionally, the contractor shall not employ any person who is an employee of the Department of the Air Force (DAF), unless approved according to DoD 5500.7-R, Joint Ethics Regulation.

2.5.5 Contractor Personnel

All contractor employees shall be able to read, write, speak and understand the English language to the extent necessary to perform PWS tasks.

The contractor shall not employ any person to work on this contract if such employee is identified by the CO as a potential threat to health, safety, security, general well-being of the installation and its population.

The Contractor shall maintain a current listing of employees. The list shall include employees name, social security number, and level of security clearance. The list shall be validated and signed by the company Facility Security Officer (FSO) and provided to the CO and Government

COR prior to contract start date. The Contractor shall provide updated listings whenever an employees status or information changes.

As determined by the government or as mission dictates, contractors supporting the 90 IOS mission shall sign non-disclosure agreements. "Proprietary information or processes will be reviewed by the Government for applicability.

2.6 Location and Hours of Work

The performance location for this work is at JBSA-Lackland in government owned facilities utilizing Government Furnished Equipment (GFE) and labs. Contractor personnel shall be expected to work as part of a larger development team. When it is in the best interest of the

Government, certain exceptions may be made that specific work may be performed at a mutually agreed upon contractor facility, so designated on the DD Form 254. This will be the exception, as our development strategies include Agile Development Processes requiring daily on-site meetings. Additionally, contractors shall have access to an off-site collateral facility.

Contractor personnel shall be present (on-site) during normal duty hours, which cover the core operational hours 0730 to 1630, Monday through Friday, except recognized federal holidays as identified in 5 U.S.C. 6103 and any other day designated as a "Down Day by the Government.

At least one contractor personnel per mission area shall always be present during the core hours. Mission area(s) will be determined by the government as required. Contractors shall not arrive to work prior to 0600 hrs or work after 1800 hrs, unless prior coordination and approval by the COR or designated Government representative is received. The Contractor will be advised by the COR if services are required, in advance of such days. Prior approval shall be obtained from the COR if the Contractor desires to work holidays and/or down days. All functions shall be open during normal duty hours.

Base Closures Due to Emergencies. From time to time, the Base Commander may decide to close all or part of a base in response to an unforeseen emergency or similar occurrence. Such emergencies include adverse weather such as snow or ice, an act of God such as tornado or earthquake, or a base disaster such as a gas leak or fire. Contractor personnel are essential personnel for purposes of any instruction regarding the emergency. Base closure announcements will normally be disseminated by local television and radio station.

2.7 Travel / Temporary Duty (TDY)

Travel to other government facilities or other contractor facilities may be required and will be specified in the PWS. All travel requirements (including plans, agenda, itinerary, or dates) shall be pre-approved by the government (subject to local policy procedures), and is on a strictly cost reimbursable basis. Costs for travel shall be billed in accordance with the regulatory implementation of Public Law 99-234 and FAR 31.205-46 Travel Costs. The contractor shall make necessary travel arrangements for contractor's employees. The contractor shall submit trip reports within five (5) business days from contractors employees return date from travel.

(CDRL: A002)

3 Performance Requirements

The following section specifies the Performance Objectives and Performance Elements

(Performance Standards (STD), Acceptable Quality Levels (AQL)) for the contract.

3.1 Software Development

Deliverables

A001 Technical Report – Studies (Report)

A003 Media Package

A004 Software User Manual / Software Installation Manual

A005 Product End Item (Source code & binary)

A006 Status Report (Monthly Status Report) (MSR)

3.1.1 The contractor shall develop software based on government/stakeholder requirements.

Tasks includes identification of objectives, requirements, system design, system/software development, testing, upgrades, and training needed for deployment and installation of the software; and updates to requirements reflecting feedback from any technical interchange meetings and testing and evaluation activities. Contractors shall be required to support multiple simultaneous development efforts. Examples of developed software include: exploits, implants, payloads, countermeasures, proof-of-concept.

Performance Standards

a) STD: Deliver all software developed, assembled, or acquired to the Government in accordance with the project schedule.

AQL: No more than two instances where delivery is late.

b) STD: All software developed as source and object (executable) code shall be commented and delivered with all source listings.

c) STD: Software developed shall comply with functional testing evaluation requirements.

AQL: No more than 3 low security risk bugs

Deliverables

A001 Technical Report – Studies (Report)

A003 Media Package

A004 Software User Manual / Software Installation Manual

3.1.2 The contractor shall refine pre-existing code into production grade software based on government/stakeholder requirements.

Performance Standards

a) STD: Develop software IAW industry best practices, innovation solutions, emerging technologies and lessons learned.

b) STD: All software developed as source and object (executable) code shall be commented and delivered with all source listings.

c) STD: All software developed based on government/stakeholder requirements shall pass final

90 IOS testing.

d) STD: Software developed shall comply with functional testing evaluation requirements.

AQL: No more than 3 low security risk bugs

Deliverables

A001 Technical Report – Studies (Report)

A003 Media Package

A004 Software User Manual / Software Installation Manual

3.2 Vulnerability Research

Deliverables

A001 Technical Report – Studies (Report)

A002 Trip Reports Includes: Technical Interchange Meeting Minutes (TIM) / Conference

Minutes

3.2.1 The Contractor shall identify vulnerabilities in software and hardware.

Software and hardware, based on requirements identified by the Government such as networks, network equipment, operating systems, software applications, wireless networks, and cloud computing technologies.

Performance Standards

a) STD: Find vulnerabilities with or without source code at the kernel and/or user level IAW government established timelines.

b) STD: Capture and document lessons learned and procedures/strategies utilized.

A001 Technical Report – Studies (Report)

A002 Trip Reports Includes: Technical Interchange Meeting Minutes (TIM) / Conference

3.3 Reverse Engineering

A001 Technical Report – Studies (Report)

A002 Trip Reports Includes: Technical Interchange Meeting Minutes (TIM) / Conference

3.3.1 The contractor shall analyze and reverse engineer software and hardware systems.

Including analyzing dynamic/static software and hardware systems; using disassembling toolkits; performing behavioral and code analysis; bypassing authentication mechanisms;

examining protected or packaged executables; patching compiled executables; and analyzing malware designed to use encryption, hashing, obfuscation, stealthy functionality, specific targeting and initiate time-triggered attacks.

Performance Standards

a) STD: Analysts shall be experienced in finding vulnerabilities either with or without source code at the kernel and/or user level.

Deliverables

A001 Technical Report – Studies (Report)

A002 Trip Reports Includes: Technical Interchange Meeting Minutes (TIM) / Conference

3.4 Network Intrusion Detection/Prevention/Analysis

A001 Technical Report – Studies (Report)

A003 Media Package

A004 Software User Manual / Software Installation Manual

3.4.1 The Contractor shall develop tools to detect, analyze and neutralize malicious logic traveling through the Global Information Grid.

Related to communications using traditional internet protocol (IP) based models as well as non-

IP based models and protocols

Performance Standards

a) STD: Tools developed allows maneuverability through cyberspace for the U.S. and its allies.

AQL: 100%

b) STD: Tools developed successfully neutralizes malicious logic.

AQL: 100%

c) STD: Utilities developed shall comply with functional testing evaluation requirements.

AQL: No more than 3 low security risk bugs

d) STD: Tools meet Capability Requirements Specifications

AQL: 100%

Deliverables

A001 Technical Report – Studies (Report)

A003 Media Package

A004 Software User Manual / Software Installation Manual

3.4.2 The Contractor shall develop software utilities that assist in managing network resources.

Performance Standards

a) STD: Utilities developed shall comply with functional testing evaluation requirements.

AQL: No more than 3 low security risk bugs

3.5 Compliance – Detection and Forensic Capability

A001 Technical Report – Studies (Report)

A004 Software User Manual / Software Installation Manual

3.5.1 The contractor shall develop tools to capture, analyze and neutralize network and host-based attack methodologies and unknown vulnerabilities.

Tasks include use of Government computer forensics and network defense tools

Performance Standards

a) STD: Tools meet Capability Requirements Specifications

AQL: 100%

Deliverables

A001 Technical Report – Studies (Report)

A004 Software User Manual / Software Installation Manual

3.6 Documentation and Studies

A001 Technical Report – Studies (Report)

A002 Trip Reports Includes: Technical Interchange Meeting Minutes (TIM) / Conference

Minutes

A003 Media Package

3.6.1 The contractor shall document all phases of software development throughout the lifecycle

The 90 IOS produces documentation for developed tools/capabilities. This documentation includes Software User Guide, Capability Requirements Specifications, Software Test Plan, Software Test Reports, etc.

Documentation shall include all relevant observations, problems experienced, outcomes, and design criteria established

Performance Standards

a) STD: Documentation shall be accurate and meets government/stakeholder technical specifications

A003 Media Package

3.6.2 The contractor shall review and coordinate documentation with government/stakeholders for software developed

Performance Standards

a) STD: Completed documentation meets governments established criteria.

AQL: No more than one instance of failure to meet government established criteria.

Deliverables

A001 Technical Report – Studies (Report)

A003 Media Package

3.6.3 The contractor shall research and document technologies identified by the

Government.

Technologies such as vulnerability research, counterintelligence, proof of concept development, exploits, implants, payloads, and countermeasures.

Performance Standards

a) STD: Completed documentation meets governments established timelines

AQL: No more than one instance of failure to meet government established timelines

Deliverables

3.7 Assist Cyber Operational Familiarization with Tools

3.7.1 The contractor shall provide developed capability demonstrations.

Performance Standards

a) STD: Completed documentation meets government established timelines

AQL: No more than one instance of failure to meet government established timelines

3.8 Network and System Administration

90 IOS creates temporary and permanent networks to support testing, development, and other activities which includes hardware, software, and virtual networks. Temporary networks include infrastructure for USAF and other DoD exercise networks, testing and lab environments to support cyber tool development. Permanent networks include closed development networks of multiple domains.

Deliverables

3.8.1 The contractor shall design and build the 90 IOS developmental systems, networks, and environments

Performance Standards

a) STD: Specified developmental system, network or environment meets work order requirement

Deliverables

3.8.2 The contractor shall modify and maintain the 90 IOS developmental systems, networks, and environments

Performance Standards

a) STD: Specified developmental system, network or environment meets government established configuration requirement

AQL: 100%

b) STD: Specified developmental system, network or environment meets government established timelines

AQL: No more than one instance of failure to meet agreed upon timeline

c) STD: Maintain client connectivity.

AQL: No more than two instances of contractor caused outages exceeding eight hours.

3.8.3 The contractor shall administer the 90 IOS developmental systems, networks, and environments.

Administration of developmental systems, networks and environments will follow 90 IOS

Standard Operating Procedures.

Performance Standards

a) STD: Ensure known downtime is pre-coordinated and approved 48 hours in advance

AQL: No more than one instance of failure to pre-coordinate 48 hours in advance

b) STD: Maintain server availability at 99%

c) STD: Contractor caused outage shall not exceed eight hours

AQL: No more than one instance of contractor caused outage exceeding eight hours

Deliverables

3.8.4 The contractor shall support network certification and accreditation for all

90 IOS development networks

90 IOS supports C&A for permanent networks to support testing, development, and other activities which includes hardware, software, and virtual networks. Permanent networks include closed development networks of multiple domains. Certification and accreditation support shall include providing necessary documentation, including network and equipment data, to the government designated POC.

Performance Standards

a) STD: Submitted Certification and Accreditation documentation meets government established timelines

AQL: No more than one instance of failure to meet government established timelines

b) STD: Submitted Certification and Accreditation documentation is complete

AQL: No more than one instance of failure to meet government requirements

3.8.5 The contractor shall maintain a Government approved Software Database for each network

Software databases include a collection of software and inventory lists.

Performance Standards

a) STD: Database updates shall be maintained bi-weekly (twice a month).

AQL: No more than one instance of failure to meet government established timelines

Deliverables

3.8.6 The contractor shall maintain an inventory for equipment on specified 90

IOS development networks

Performance Standards

a) STD: Equipment inventory list shall be maintained IAW AFI 33-112 and 688CW Supplement.

Deliverables

3.8.7 The contractor shall answer and fulfill trouble tickets and work orders submitted by the developer’s operating on the 90 IOS development networks

The 90 IOS trouble ticket/work order process includes: receipt of ticket, ticket acknowledgement, submittal of proposed timeline for completion to Government appointed lead, Government approval of timeline, upon completion document resolution.

Performance Standards

a) STD: Respond to submitted tickets/orders within 24 hours.

AQL: No more than one instance of failure to respond within 24 hours.

b) STD: Complete assigned ticket/order within government designated timeline

AQL: No more than two instances of failure to meet agreed upon timeline

3.9 Quality Assurance

A001 Technical Report – Studies (Report)

A004 Software User Manual / Software Installation Manual

3.9.1 The contractor shall perform functional evaluation and quality assurance on software and software features.

Includes 90 IOS evaluations or assessments: developmental; endurance; functional; security;

operational; black box; white box; configuration management; peer code review; static code analysis; build/release management; automated testing.

Testing of a system/network or application includes all phases of the software development lifecycle

Performance Standards

a) STD: Report bugs and missing functionality within 24 hours of identification.

AQL: No more than one instance of failure to report within 24 hours.

Deliverables

3.9.2 The contractor shall create and maintain automated testing scripts.

Reference Task 3.9.1

Performance Standards

a) STD: Automated testing scripts validates the expected results for each test case.

Deliverables

A001 Technical Report – Studies (Report)

A004 Software User Manual / Software Installation Manual

4 Special Requirements

This section describes the special requirements for this effort. The following sub-sections provide details of various considerations on this effort.

The Contractor shall work in a closed system environment where all code, documentation, and project management information will be kept. The contractor shall use a combination of virtual and physical machines in preparing deliverables. The project management software, version control software, virtual and physical machines are Government furnished. The operating systems include UNIX, Linux, and Windows (3.1/95/98/NT/2K/XP/Vista/ 7/2003/2008). Other systems the contractor shall work with are: switches and routers, virtual private networks (VPN), firewalls, traffic generators, and McAfee Intrusion Detection Systems (IDS).

All quality assurance assessments of software projects shall be conducted on a separate closed system environment from that of the development environment. Internet access will be provided for development and quality assurance purposes.

As determined by the government and mission relevant, the contractor may be required to obtain and maintain access to National Security Agency (NSA) facilities and networks.

4.1 Security and Safety

DD Forms 254: Overarching security requirements and Contractor access to classified information shall be as specified in the basic DD Form 254, which will be further identified in the

DD Form 254 for each TO, as required. All contractor personnel with access to unclassified information systems, including e-mail, shall have at a minimum a favorable National Agency

Check (NAC).

Industrial Security: Contractor personnel shall have a final U.S. Government-issued TOP

SECRET security clearance and be Director of Central Intelligence Directive (DCID) 6/4 eligible with a current Special Security Background Investigation (SSBI). The contractor shall follow the security requirements outlined in the contract DD Form 254, Department of Defense Security

Classification Specification.

Polygraph: Contractor personnel shall be willing to undergo and successfully complete a counterintelligence-scope polygraph examination with No Deception Indicated (NDI) on a pre-appointment and periodic basis.

Operations Security (OPSEC): On base contractor employees will comply with AFI 10-701, Operations Security, available on the Air Force's e-publishing web site at URL: http://www.e-publishing.af.mil/. They will also participate in the assigned unit's OPSEC program, protect critical information identified in the 688 CW Critical Information List (CIL), complete the Information Protection (ZZ133078) computer based training (CBT) module located on the Advanced Distributed Learning Service (ADLS) Website upon assignment and annually thereafter.

Visitor Group Security Agreement. The contractor shall sign a Contractor Visitor Group Security

Agreement to protect classified information involved in performance under this contract or Task

Order. The Agreement will outline responsibilities in the following areas: Contractor security supervision; Standard Practice Procedures; access, accountability, storage, and transmission of classified material; packaging, mailing, and receiving classified information; marking requirements; security education; personnel security clearances; reports; security checks;

security guidance; emergency protection; protection of government resources; DD Forms 254;

periodic security reviews; and other responsibilities, as required.

Security Training: The contractor shall be required to participate in the government's in-house and Web-based security training program under the terms of the contract. The government will provide the contractor with access to the on-line system.

Information Systems Security: The contractor's unclassified Information System (IS) shall comply with AFI 33-200, INFORMATION ASSURANCE (IA) MANAGEMENT, Chapter Three, Air Force IA Policy. Classified IS shall comply with DoD 5220.22-M, National Industrial Security

Program Operating Manual (NISPOM), Chapter Eight "Information Security". Sensitive

Compartmented Information (SCI) IS shall also comply with Intelligence Community Directive

(ICD) 503, Intelligence Community Information Technology Systems Security Risk

Management, Certification and Accreditation.

Safety Program Requirements. The contractor shall conform to the safety requirements contained in the contract for all activities related to the accomplishment of the work. The contractor shall take such additional immediate precautions as the CO may reasonably require for safety and mishap prevention purposes. The contractor shall develop and provide at the start of the orientation period or the start of the first operational performance period a safety plan for the protection of Government facilities and property and to provide a safe work environment for contractor personnel. The contractor shall provide protection to Government property to prevent damage during the period of time the property is under the control or in possession of the contractor. The safety provisions of this contract, shall apply to any subcontracts/subcontractors. The contractor shall include a clause in each applicable subcontract requiring the subcontractor's cooperation and assistance in accident reporting and investigation. The program shall address, as a minimum, the Safety Program Elements listed, and shall be used during performance of the work described in the PWS.

Mishap Notification. The Contractor shall notify the COR or 90 IOS Safety Office within one hour of all mishaps or incidents. A written report of the mishap/incident shall be sent within three calendar days to the COR, who will forward it to the 90 IOS Safety Office. For information not available at the time of initial written report, the Contractor shall provide the remaining information no later than 20 calendar days after the mishap, unless extended by the 90 IOS

Safety Office.

Mishap notifications shall contain, as a minimum, the following information:

Contract, Contract Number, Name and Title of Person(s) Reporting Date, Time and exact location of accident/incident Brief Narrative of accident/incident (Events leading to accident/incident)

Cause of accident/incident, if known Estimated cost of accident/incident (material and labor to repair/replace) Nomenclature of equipment and personnel involved in accident/incident Corrective actions (taken or proposed) Other pertinent information

If requested by the COR or 90 IOS Safety Office, the Contractor shall immediately secure the mishap scene/damaged property and impound pertinent maintenance and training records, until released by the 90 IOS Safety Office.

The safety provisions of this contract shall apply to any subcontracts/subcontractors.

Safety Program Elements. The Contractors Safety Program shall clearly define procedures, personnel qualifications, facilities and required equipment necessary to fulfill the following elements:

Element/Requirement Referenced Benchmark

Mishap Notification/Reporting AFI 91-204

Housekeeping AFOSH Std 91-501

Material Handling Equipment (MHE) AFOSH Std 91-46 and

AFOSH Std 91-501

Handling, Storage and use of Flammable/Combustible Liquid AFOSH Std 91-501

Vehicle Operations AFI 91-207

Tool Control AFMCI 21-107

Foreign Object Damage (FOD) AFI 21-101, and

AFMCI 21-122

Tobacco Use in the Air Force AFI 40-102

Hazardous Energy Control AFOSH 91-50

4.2 Transition

The contractor shall follow the transition plan submitted as part of the proposal and keep the

Government fully informed of status throughout the transition period. Throughout the phase-in/phase-out periods, it is essential that attention be given to minimize interruptions or delays to work in progress that would impact the mission. The contractor must plan for the transfer of work control, delineating the method for processing and assigning tasks during the phase-in/phase-out periods.

4.3 Government Furnished Materials (GFM)

The Government will make available the materials, office space, communications capability and information upon contract start. Configuration Management is performed via online wiki systems and are Government furnished for the purpose of product and project documentation.

These are administered and accessed through the closed development network. The

Government will provide access to the Internet, hardware, software, office space, and any applicable documentation required for onsite performance of this contract.

4.3.1 Government Furnished Property (GFP)

GFP is not applicable to the performance of this contract.

4.3.2 Property of the Government

Government Property shall remain at all times Property of the Government. In accordance with

Government procedures, the Contractor is authorized to utilize Property of the Government, without cost, with Government personnel in Government facilities at JBSA-Lackland for the duration of this contract and only as needed for the performance of this contract. Additionally, the Government will check out Government Property to contractor personnel to support development efforts conducted at contractor facilities, as required by the Government.

The Government maintains accountability for this Government Property. This Property of the

Government is not considered GFP requiring property administration IAW FAR Parts 45 and

52.245 plus supplements. The Government Organization that is accountable for this Property of the Government is also responsible for its Disposition.

4.3.2.1 Availability

The Contractor shall be required to perform in accordance with the contract terms and conditions and this PWS regardless of availability of Government Property at no additional cost to the Government.

4.3.2.2 Government Property

Government property may include the following: a workstation(s)/desk, chair, monitor, keyboard, and a mouse. As mission/tasks dictate access to the following: telephone, card readers, access to required networks (NIPR, SIPR, JWICS), access to development networks.

Configuration Management is performed via online wiki systems and are Government furnished for the purpose of product and project documentation. These are administered and accessed through the closed development network.

4.4 Workspace

4.4.1 Housekeeping

The contractor shall keep the work areas clean and orderly in compliance with federal, state, local health, fire, and safety standards.

4.4.2 Refuse Collection

The Government will provide dumpsters for refuse and provide dumpster collection service. The contractor shall take personal refuse to the nearest authorized refuse dumpster. The

Government will provide containers for the collection of recycling materials. All discarded work product must be 100% shredded or bagged in approved and appropriately labeled burn bag security containers IAW DoDM 5200.01-V3, Pg. 42, 24 February 2012.

4.4.3 Conservation of Utilities

The contractor shall instruct employees in utilities conservation practices. The contractor shall be responsible for operating under conditions which prevent the waste of utilities which include the following:

Lights shall be used only in areas where and when work is actually being performed Mechanical equipment controls for heating, ventilation, and air conditioning systems shall not be adjusted by the contractor or by contractor employees unless authorized Water faucets or valves shall be turned off after the required use has been accomplished Government telephones shall be used only for official government business

4.5 Contractor Records and Reporting

4.5.1 Contractor Manpower Reporting

The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the IAFNOS via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address http://www.ecmra.mil.

4.5.2 Records

The contractor shall be responsible for creating, maintaining, and disposing of only those

Government required records that are specifically cited in this PWS. If requested by the

Government, the contractor shall provide the original record or a reproducible copy of any such record within five working days of receipt of the request. All products developed under the contract, including, but not limited to, hardware, software (including source code), electronic and hard copy documentation, intellectual property, methodology, presentations, and notes shall be considered the sole property of the Government, and shall be delivered to the COR upon completion of the contract. All previously mentioned items will be treated as AF proprietary information, and this information will not be released to other non-AF entities without written permission from the COR.

4.6 Quality

The Government will periodically evaluate the contractors' performance by appointing a representative(s), to monitor performance to ensure services are received. The Government representative will evaluate the contractors' performance through intermittent on-site inspections of the contractor's quality control program, validated user complaints and receipt of complaints from base personnel. The Government may inspect each task as completed or increase the number of quality control inspections if deemed appropriate because of repeated failures discovered during quality control inspections or because of repeated customer complaints.

Likewise, the Government may decrease the number of quality control inspections if merited by performance. The Government will also investigate complaints received from various customers located on the installation. The contractor shall be responsible for initially validating customer complaints. However, the Government representative will make final determination of the validity of customer complaint(s) in cases of disagreement with customer(s).

4.6.1 Quality Control

IAW FAR 52.246-1, Inspection of Services, the contractor shall establish a complete QCP to ensure the requirements of this contract are provided as specified. The CO will notify the contractor of acceptance or required modifications to the plan before the contract start date. The contractor shall make appropriate modifications at no additional costs to the Government and obtain acceptance of the QCP by the CO before the start of the first operational performance period.

The contractor shall develop a QCP and maintain an effective quality control program to ensure services are performed in accordance with the contract and this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor's QCP is the means by which the contractor assures that the work complies with the requirement of the contract.

The finalized QCP will be accepted by the Government at the time of the award of the contract.

The CO may notify the contractor of required modifications to the plan during the period of performance. The contractor shall coordinate suggested modifications and obtain acceptance of the plan by the CO. Any modifications to the program during the period of performance shall be provided to the Contracting Officer for review no later than 10 working days prior to effective date of the change. The QCP shall be subject to the Governments review and approval. The

Government may find the QCP "unacceptable" whenever the contractors' procedures do not accomplish quality control objective(s). The contractor shall revise the QCP within 10 working days from receipt of notice that QCP is found "unacceptable."

4.6.2 Quality Assurance Surveillance Plan (QASP)

The Government shall monitor the Contractors performance under this contract in accordance with the Government's QASP.

4.7 Training

The contractor shall provide training to mission partners (other contractors) and receive the same from mission partners to expand team capabilities.

The contractor shall provide training to Government personnel on technologies, software products, and tools. This shall include training government personnel in areas of reverse engineering, malicious software analysis, network analysis, cyber tool development, vulnerability discovery, access tool development and other CNO areas deemed necessary by the government for mission success.

4.8 Freedom of Information Act Program

The contractor shall comply with DoD Freedom of Information Act (FOIA) Program requirements and requests. This provision includes compliance in handling Controlled Unclassified

Information (CUI) and For Official Use Only (FOUO) materials and performing data restores.

4.9 Contracting Officer Representative

4.9.1 The COR is the authorized Government representative(s) who will perform assessments of the contractors' performance. Subsequent to contract award, the identity of the COR(s), with a letter defining their duties and authority, will be promptly furnished to the contractor.

4.9.2 The COR(s) or alternate(s) will inform the contract manager in person when discrepancies occur and will request corrective action. The COR(s) or alternate(s) will make a notation of the discrepancy on their assessment checklist with the date and time the discrepancy was noted and will request the contract manager (or authorized representative) to initial the entry on the checklist.

4.9.3 Any matter concerning a change to the scope, prices, terms or conditions of this contract shall be referred to the CO and not to the COR(s).

4.9.4 The services to be performed by the contractor during the period of this contract shall at all times and places are subject to review by the CO or authorized representative(s).

4.10 Continuation of Essential DoD Contractor Services During Crisis

This requirement is not considered mission essential IAW Defense FARS (DFARS) 237.76.

4.11 Contingency Operations

The contractor shall provide support during contingencies, exercises, heightened operations, and security closures in the accomplishment of section 3 performance requirements.

Additionally, the contractor shall secure work stations IAW security policies during known/unknown work stoppages (i.e. Includes but not limited to uncleared personnel, construction, inspections, unclassified visitors, fire alarms/drills, network/system administration, facilities maintenance) or at the government's request.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .