Attachment_2_CAETS-2_PWS_dated_19_Oct_16.pdf

PDF 240 KB Posted

Attached to
Cyber Assessment Engineering and Technical Support (CAETS)-2 Federal contract opportunity
Solicitation number
FA8773-17-R-8001
Issued by
Department of the Air Force Space Command

About this file

Attachment 2 - CAETS-2 PWS dated 19 Oct 16

View the file

Other files for this federal contract opportunity

Other files attached to Cyber Assessment Engineering and Technical Support (CAETS)-2, newest first.
File Type Posted
CAETS-2_RFP_FA8773-17-R-8001_Amendment_0002.pdf PDF
Attachment_2_CAETS-2_CDRLS_A001-A019.pdf PDF
Attachment_1_CAETS-2_PWS_26_Oct_16.pdf PDF
CAETS-2_RFP_FA8773-17-R-8001_Amendment_0001.pdf PDF
CAETS-2_RFP_FA8773-17-R-8001_Amendment_0002_CONFORMED.pdf PDF
Attachment_4_CAETS-2_CDRLS_A001-A019.pdf PDF
CAETS-2_RFP_FA8773-17-R-8001.pdf PDF
DRAFT_CAETS2_PWS_12_Oct_2016_92_COS_1.docx DOCX document
DRAFT_RFP_CAET-2.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

FOR

DEPARTMENT OF THE AIR FORCE

688 CYBERSPACE WING (CW)

CYBER ASSESSMENT ENGINEERING

AND TECHNICAL SUPPORT-2 (CAETS-2)

92 Cyberspace Operations Squadron

19 October 2016

1.0 INTRODUCTION

1.1 688TH Cyberspace Wing (CW) Mission

The mission of the 688 Cyberspace Wing (CW) is to deliver Asymmetric Advantage; to achieve air, space, and cyberspace superiority in the most efficient and innovative way possible.

1.2 Cyber Assessment Program Background

Unit Mission: The mission of the 688 CW is to quantify the security posture, integrity and network defense capabilities of Department of Defense (DoD) and Air Force (AF) cyber assets.

This mission is executed through a Cyber Assessment Program linked to DoD and AF requirements along with “Best Practices” as defined by industry and governmental organizations.

1.2.1 Program Components: The 688 CW Cyber Assessment Program is composed of three main assessment pillars: Vulnerability Assessment (VA), Defense Assessment (DA), and Intrusion Assessment (IA). The three (3) pillars collect the data necessary to answer the following questions:

a. Is the security posture of the network adequate to deter cyber-attacks?

b. Can the network defenders detect and defeat a cyber-attack?

c. Has the network already been compromised?

1.2.1.1 Vulnerability Assessment (VA): Identify weaknesses in network security that could be exploited to disrupt operations. This includes the following types of functions:

a. Compliance evaluation to determine how well the network security program and implementation are meeting DoD and AF mandates (Time Compliance Network Orders (TCNOs), Information Assurance Vulnerability Alerts (IAVAs) etc).

b. “Security Best Practice”: Identify weaknesses and determine the impact of potential attack vectors by evaluating the following: architecture, firewalls, intrusion detection devices, critical program information, network maps and all pertinent documentation.

c. Penetration Test—Overt exploitation of security weaknesses to quantify and demonstrate the impact of a cyber-attack upon operations and to propose mitigation actions.

A key component of this assessment is determining the security posture and configuration of individual devices embedded in AF networks. The basic requirements for the security posture of devices are derived from DoD and AF directives, instructions, and guides. Additional security requirements should be derived from a survey of “Best Practices” as proposed by industry or Government agencies.

1.2.1.2 Defense Assessment (DA): Determine a unit’s ability to deter, detect and defeat a cyber-attack. This includes quantifying the protect, detect, react and restore capabilities of the network defenders. This is accomplished by overtly applying scripted attack vectors, and simulating technological possibilities as well as intelligence validated threats, to stimulate the network defense responses and measure the responses and proposing mitigation actions.

1.2.1.3 Intrusion Assessment (IA): Determine if a network has been compromised by a cyber-attack. This includes defining the data to be collected from the networks; collection of a tremendous amount of data concerning the state of a network at a given time; analyzing the data using specialized tools; and integrating the tool output to determine the following:

a. If a network was compromised through malicious activities.

b. How the network was compromised.

c. What damage could have been inflicted as a result of the compromise.

Provide recommendations for eradication of the Advanced Persistent Threat (APT).

1.2.2 Mission Span: 688 CW personnel conduct on-site and remote assessments of the network security, integrity and defense posture for a wide variety of AF, DoD, and DoD contractor networks, to include:

a. Base Information Technology infrastructure: networks, including Secret Internet Protocol Router Network (SIPRNET) and Non-Secure Internet Protocol Router Network (NIPRNET), located on AF bases providing administrative and mission support.

b. Mission and weapon systems: networks identified as part of a mission and weapon system and maintained by a program office through a program of record

c. Exercises: networks established, configured, and operated for exercise purposes.

d. Defense Contractor Support: networks utilized for design, test, and maintenance and support functions.

1.2.3. Assessment Infrastructure: The 688 CW utilizes an Assessment Enterprise Support System (AESS) to build the assessment capabilities. The AESS encompasses all hardware, software and data necessary to sustain, execute, and evolve the 688 CW mission. This includes an Operational component, a Base component, a Platform component, a Data Storage component and a Tool component.

1.2.3.1 Operational Component: The Operational Component consists of network infrastructures composed of, but not limited to, devices such as routers, switches, servers, firewalls, clients, and intrusion detection systems. These networks are utilized by Assessment Teams to:

a. Assess target external connections for vulnerabilities from a remote location

b. Provide reach-back capability to support on-site operations

c. Conduct and execute remote assessments for AF and DoD customers.

1.2.3.2 Base Component: The Base Component consists of the network infrastructure, composed of devices such as routers, servers, firewalls, clients and intrusion detection systems present within the AF Global Information Grid, network enclaves and mission/weapon system networks. This includes 50+ servers/(Dells/SUN), 10+ routers, 10+ switches, 5+ firewalls (sidewinder/PIX), Combat Information Transport System (CITS) replication equipment, new technologies, specialized equipment to upgrade/maintain mission/training systems. This component is used for the following functions:

a. Evaluate new assessment tools and techniques to improve assessment process

b. Train 688 CW personnel on tool execution as part of the STANEVAL program

e. Test new tools in a benign environment prior to deployment on an operational network

1.2.3.3 Platform Component: The Platform Component consists of the computer systems used to launch specialized tools to execute the assessments. This includes all laptops utilized by the 688 CW and its supporting units.

1.2.3.4 Data Storage Component: The Data Storage component is a standalone network used to store critical information such as user manuals, tool software and report data.

1.2.3.5 Tool Component: The 688 CW utilizes a mix of commercially available tools, readily available tools from the Internet and government developed tools to assess and document the security, integrity and network defense posture of AF cyber assets.

1.3 Scope

The purpose of this PWS is to provide the 92 Cyberspace Operations Squadron (COS) with the management, engineering and technical support services required to support the establishment, maintenance, and evolution of the 688 CW cyber assessment program and the execution of the assessments defined by this program as follows:

a) Mission Support: Provide the technical support necessary to baseline, evolve and sustain the 688 CW infrastructure, data and processes.

b) Training and Standardization Evaluation (STANEVAL) Support: Provide the technical support necessary to train and certify personnel to execute assessments.

c) Program Management: Provide the program management necessary to plan and execute each individual assessment, infrastructure support project, and tasking.

d) Assessment Operations: Provide the technical support necessary to baseline, evolve and sustain and execute Vulnerability Assessments, Defense Assessments, and Intrusion Assessments.

2.0 General Requirements

2.1 Non-Personal Services

The Government shall not supervise the contractor nor control the method by which the contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor’s

2.2 Business Relations

The contractor shall integrate and coordinate all contractor activity needed to execute the requirement. The contractor shall manage the timeliness, completeness, and quality of problem identification. The contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors.

2.3 Contract Administration and Management

2.3.1 Contract Management

The contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned to the requirement. The contractor must maintain continuity between the support operations at 688 CW and the contractor's corporate offices.

2.3.2 Contract Administration

2.3.2.1 The contractor shall establish processes and assign appropriate resources to effectively administer the requirement.

2.3.2.2 The contractor shall have a single point of contact between the Government and contractor personnel assigned to support this contract and subsequent task orders.

2.3.2.3 The contractor shall conduct a Kick-off meeting no later than 10 calendar days after award and hold weekly status reviews and monthly Technical Interchange Meetings (TIMs), formal program reviews and other meetings as directed by the CORs. The contractor shall present the status of the program and shall support meetings when requested by the Government.

The contractor’s weekly status reviews shall describe: the progress, resource allocation, personnel assignment and event schedule of all tasks including (a) the personnel allocated to specific tasks/assessments; (b) the status of assigned tasks; (c) training and personnel certification status; (d) results of conducted training; and (e) subject matter expert (SME) status.

2.3.2.4 The contractor shall hold monthly Technical Interchange Meetings (TIM), as well as formal program reviews/other meetings on a coordinated basis with the Contracting Officer’s Representative (COR). (Contract Data Requirements List (CDRL) A001, A002, A007)

2.3.2.5 Contractors assigned to support a specific mission shall provide daily mission status during pre/execution/post mission briefs to the Government Team Chief or Mission Commander.

2.3.3 Personnel Administration

2.3.3.1 The contractor shall accomplish the assigned work by employing and utilizing sufficient, qualified personnel with appropriate combinations of education, training and experience to perform the work specified within the PWS.

2.3.3.2 The contractor shall ensure all required certifications, training and STAN/EVAL requirements are met in accordance with (IAW) Department of Defense Manual (DoDD) 8570.01M, Air Force Manual (AFMAN) 33-285, Air Force Instruction (AFI) 10-1703 Vols 1, 2 and 3 and AFI 10-1703V1 Air Force Space Command Supplement (AFSPCSUP) and AFI 10- 1703V2 AFSPCSUP. Obtaining required certifications are the responsibility of the contractor. If the Government provides specific certification training (for purposes of satisfying 8570 requirements) using in-house assets, contractor employees may attend with COR approval, provided they pay for all related course materials/tests as well as not charging the Government for the time for the training.

The contractor shall provide a qualified team with the expertise in theoretical and practical knowledge of system security engineering; security technology evaluation; compliance assessments; vulnerability assessments; network penetration testing; defense assessments;

intrusion assessments; and developmental and operational testing. The contractor shall maintain at least one SME in each of the technology areas as listed in Appendix 2 to perform all tasks at all times. The contractor’s SMEs shall be well versed in the appropriate DISA STIG Security Technical Implementation Guide (STIG) and all the documents listed in Appendix 1 – List of Applicable Publications. The SMEs shall be proficient, at a minimum, in the technology areas listed in Appendix 2.

2.3.3.2.1 The contractor shall ensure that personnel accessing information systems have the proper and current information assurance (IA) certification to perform information assurance functions IAW DoDD 8570.01-M, Information Assurance Workforce Improvement Program.

The contractor shall meet the applicable IA certification requirements, including (1) DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01-M; and (2) appropriate operating system certification for IA technical positions as required by DoDD 8570.01-M. At least 10% of the contractor assessors shall possess a Cisco Certified Network Associate (CCNA) certification. At least 10% of the contractor assessors shall possess a Database Certification. At least 25% of the contractor assessors shall possess a Penetration Testing Certification at the beginning of the contract.

Contractor personnel performing Client Support Administrator duties shall be certified at the Information Assurance Training (IAT) I level. In accordance with DoD 8570.1M, newly assigned personnel shall have completed their certification requirements prior to being assigned to the contract.

2.3.3.2.2 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.

2.3.3.2.3 Contractor personnel who do not possess proper and current certifications shall be denied access to DoD information systems for the purpose of performing IA functions.

2.3.3.4 The prime contractor shall hold and maintain Capability Maturity Model Integration (CMMI) Level 3 throughout the entire performance period of the contract, inclusive of ordering periods. IAW the CMMI maturity models, the contractor shall “focus on process improvement” and continue the optimization of the 688 CW’s defined processes.

2.3.3.5 Contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification with Government personnel. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversation and in formal written correspondence.

2.3.4 Reporting Contract Labor

The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract via a secure data collection site. The contractor is required to completely fill in all required data fields at http://www/ecmra.mil. Reporting inputs will be for the labor executed during the period of performance for each Government Fiscal Year (FY), which runs 1 October through 30

September. While inputs may be reported any time during the FY, all data shall be reported no later than 31 October of each calendar year. The contractor may direct questions to the Contractor Manpower Reporting Application (eCMRA) help desk.

2.3.5 Subcontract Management

2.3.5.1 The contractor shall be responsible for any subcontract management necessary to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance.

2.3.5.2 The prime contractor shall manage work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations. The contractor may add or remove subcontractors to its team after contracting officer (CO) and COR notification.

2.4 Location and Hours of Work

2.4.1 Place of Performance: The primary work location shall be at 92 COS 3515 S. General McMullen Dr, Bldg 4, San Antonio TX, 78226. Additional support may be required at different off-site locations as determined by the Task Order or COR.

2.4.2 Hours of Work: Normal work hours, on-site, at the 92 COS shall be from 8:00 A.M. - 5:00 P.M. Monday - Friday excluding Federal Holidays. Alternate Work schedules in the workplace are appropriate if deemed acceptable by the COR. Performance or travel on weekends authorized only when deemed appropriate by the government. During mission execution, the number of hours may exceed 8 hours per day, may include weekends and holidays, and may include various shifts. Under certain circumstances, 24 hour operations may be required.

2.5. Travel:

2.5.1 Travel to government and contractor facilities within and outside the continental United States shall be required. Alternate work locations shall be at various places, Contiguous United States (CONUS) and Outside Contiguous United States (OCONUS) and, including but not limited to contractor’s sites, government sites, development locations, or at flight-testing sites, as required.

The purpose of contractor travel shall include conducting and attending meetings, test & evaluation (T&E) activities, performing data gathering and analysis, providing System Security Engineering (SSE) consultation, and coordinating with the 688 CW, other Department of Defense personnel, and other contractor personnel.

2.5.2 The contractor shall make necessary travel arrangements for employees. All travel requirements (including plans, agenda, itinerary, or dates) shall be pre-approved by the Government (subject to local policy procedures), and is on a strictly cost reimbursable basis.

Performance or travel on weekends is authorized only when deemed appropriate by the Government. Costs for travel shall be billed IAW the Joint Travel Regulation and regulatory implementation of Public Law 99-234 and Federal Acquisition Regulation (FAR) 31.205-46 Travel Costs (subject to local policy & procedures).

3.0 Performance Requirements.

The Performance Requirements listed below determine the color of funding that can be utilized to execute the mission, 3.1 Base Contract details work applicable to both colors of money and covers Mission Support, Training & StanEal, and Program Management 3.2 Assessment Operations for Operational Systems utilizing 3400 funding and 3.3 Assessment Operations for Research and Developmental Systems utilizing 3600 funding.

3.1 Base Contract

The based contract will be the TO covering primary support functions for squadron operations.

3.1.1 Mission Support

3.1.1.1 AESS Support: The contractor shall provide the engineering, management and technical support required to develop, evolve, operate and maintain the AESS and its associated VA, DA, and IA capabilities and data as described in Section 1.2 Background. The support required shall include, all the tasks described herein 3.1.

3.1.1.2 Baseline Definition: The contractor shall support the 688 CW in identifying AESS requirements, performing trade studies and designing the architecture and system hardware, software, interface and interconnection components required to ensure the AESS meets 688 CW mission requirements. The contractor shall provide the necessary documentation, including network diagrams, requirements documents, design criteria and test documentation to support baseline management, configuration control, and engineering activities. (CDRLs A013, A014, A015, A019)

3.1.1.3 System Evolution and Integration: The contractor shall support the 688 CW in defining and executing a disciplined process for controlling and evolving the AESS baseline and enhancing the AESS components. The contractor shall support the 688 CW in utilizing this process to procure and integrate Government approved tools, hardware and software into the AESS baseline. (CDRLs A013, A014, A015, A019)

3.1.1.4 Installation, Documentation and Testing: The contractor shall support the 688 CW installation, documentation and testing of the AESS components. The contractor’s support shall include (CDRLs A013, A014, A015, A019):

• Maintaining network configuration diagrams of AESS network components

• Maintaining configuration baselines for the approved AESS installing, configuring, testing local area network (LAN) hardware and software

• components and cabling

• Installing vendor security patches and Air Force Network (AFNet) advisories

• Implementing security recommendations

• Backing up and restoring application and operating system software establishing and maintaining firewalls, Domain Name Server (DNS), Windows Internet Name Service (WINS), Exchange services, routers

• Implementing and enforcing security measures

• Integrating approved assessment tools to the assessment platform

• Modifying the assessment platform

• Documenting and tracking AESS configuration and assets

• Testing AESS platforms, tools, network subsystems and interfaces

3.1.1.5 AESS Operations and Maintenance: The contractor shall provide user and technical support necessary to operate and maintain the AESS to meet 688 CW mission requirements. The contractor shall analyze, troubleshoot, document, resolve and report AESS problems as they are encountered IAW 688 CW and industry standards and methodologies. The contractor shall support the 688 CW in maintaining an accurate baseline and inventory of AESS hardware and software components. (CDRL A018)

3.1.1.6 Information Protect Certification and Accreditation.

The contractor shall provide engineering and technical support to the 688 CW to ensure the AESS system and its components achieve initial and recurring accreditation. This shall include developing and verifying acquisition and accreditation packages (CDRL A018).

3.1.1.7 Certification and Accreditation The contractor shall provide engineering and technical support for the Certification and Accreditation (C&A) standards and processes to achieve uniform quality and a level of consistency throughout the life cycle of the AESS. The contractor shall provide the Government support with certification and accreditation surveys and document responses into the Enterprise Information Technology Data Repository (EITDR). The contractor shall ensure the EITDR questions are answered to meet or exceed the common minimum standards as required to support annual Federal Information System Management Act (FISMA) reporting requirements. (CDRLs A018, A019)

3.1.1.7.1 DIACAP/EITDR Package and FISMA Reporting: The contractor shall support the 688 CW to develop DoD Information Assurance Certification and Accreditation Process (DIACAP) certification packages for the AESS accreditation approval. The contractor’s packages shall include the following (CDRLs A015, A018, A019):

a. DIACAP Scorecard to include validated and tested IA controls based on Mission Assurance Category (MAC) and Confidentiality Level (CL)

b. DIACAP Plan of Action and Milestone (POA&M) to include a timeline and resources to mitigate outstanding risks to an acceptable level.

c. Validation evidence for all appropriate IA Controls formatted for easy upload into EITDR

d. Final System Identification Profile

e. Final DIACAP Implementation Plan

3.1.1.7.2 System Artifacts: The contractor shall develop, review and finalize documentation necessary to satisfy IA controls which may include the following documentation (CDRLs A015, A018, A019):

a. System Security Concept of Operations

b. Security Requirements from Appropriate IA Controls

c. Security Maintenance Procedures

d. System Security Architecture and Interconnects

e. Contingency Operations Plan (COOP)

f. Data Backup Plan

g. Disaster Recovery Plan

h. Maintenance Support Plan

i. Hardware Baseline Inventory

j. Software Quality Plan

k. Systems Rules Behavior

l. Physical Functions System Security Descriptions.

3.1.1.8 Document Control and Tracking: The contractor shall provide support in the development of policies and procedures for constructing and archiving technical reports. The contractor’s support shall include developing reporting standards linked to DoD and AF guidance, generating templates based on these standards, and reviewing reports for accuracy, grammar and compliance with AF and DOD guidelines for official documents. The contractor shall develop, maintain and keep current a centralized repository of security information, government reports and contractor deliverables. To the extent possible, this repository shall be an electronic repository with an index for storage and retrieval purposes and shall be kept on a 688 CW server. The centralized repository shall include the following (CDRL A018):

a. Network security related regulations, policies and guidance

b. Assessment plans, notes and reports

c. Training materials

d. Contractor deliverables

e. AESS design, development and test documentation

f. AESS configuration baseline data

g. Assessment tools

3.1.1.9 Security support: The contractor shall provide support in the development and execution of the 688 CW security program. The contractor’s support shall include developing and maintaining the 688 CW local security guidelines, supporting travel arrangements and reviewing reports for compliance with security directives (CDRL A018).

3.1.1.10 Program Construction: The contractor shall support the full spectrum of assessment missions and types conducted by the 688 CW as described in Section 1.2 Background. The contractor shall research and develop the concepts, methodology, and technology in order for the 688 CW to fulfill its mission to conduct Cyber Assessments. The contractor shall support planning, execution and reporting on any or all parts of each assessment and mission type.

3.1.1.11 Vulnerability Assessments (VA): The contractor shall support the 688 CW in developing, evolving, fielding, and executing the remote and on-site VA concepts and methodologies.

3.1.1.11.1 Program Development and Evolution: The contractor shall support the 688 CW in developing, evolving, and fielding the VA concept and methodology to ensure 688 CW capabilities and methodologies are integrated with the DoD guidance and policy. The contractor shall conduct reviews of competing assessment programs, methodologies, processes and objectives and provide recommendations on how to improve the VA concept, process and reporting. The contractor shall develop, document, and maintain methodologies that address the full spectrum of an assessment: planning, execution, and reporting. The contractor shall provide methodologies that shall include tested and proven tools (both hardware and software based), tactics, and procedures. The contractor shall update methodologies and integrate new methodologies that address the 688 CW mission. (CDRLs A003, A016)

3.1.1.12 Tool and Technology Evaluation: The contractor shall evaluate Commercial Off The Shelf (COTS), Government Off The Shelf (GOTS), and Open Source Assessment tools for automating the assessment of each device and device type and recommend tools to be used to automate the assessment. This evaluation shall include tools for collecting, analyzing and reporting the data required to determine the security posture of the devices and device types listed in Appendix 2. The contractor shall define tool requirements and define, develop and modify tools and scripts, and support the 688 CW in integrating approved tools. The contractor shall identify, document and demonstrate the proper usage of all tools developed and modified (including scripts and data base queries) under this effort and include them in the assessment package. (CDRLs A016, A018)

3.1.1.13 Defense Assessments (DA): The contractor shall support the 688 CW in developing, evolving, fielding and executing the DA concept.

3.1.1.13.1 Program Development and Evolution: The contractor shall conduct reviews of competing assessment programs, methodologies and objectives and provide recommendations on how to improve the DA concept. The contractor shall create and refine methodologies for conducting a DA to include tools, tactics, and procedures. The contractor shall integrate the concepts of the DA into the 688 CW methodology and 688 CW training via documentation, presentation, and demonstration. (CDRLs A004, A016)

3.1.1.13.2 Scenario Development: The contractor shall support the development and maintenance of scenarios used to train and prepare the warfighter to defend DoD networks. The contractor shall support the 688 CW in developing and maintaining formal cyber-attack vectors to penetrate and stimulate the network defenders. The contractor shall construct these attack vectors from validated threat information and potential technological exploits. The contractor shall correlate identified threats to identified vulnerabilities (threat-vulnerability pairs) and provide explanation of the relationships, and provide an evaluation of the likelihood and impact of a resultant risk occurrence for each Defense Scenario. The contractor shall construct the software modules needed to execute the scenarios, test the scenarios on Government test ranges, and provide instructions on how to implement the scenario and identify methods to mitigate the simulated attack. The contractor shall customize scenarios to achieve the necessary training objects of a DA. (CDRLs A004, A018, A019)

3.1.1.14 Tool and Technology Evaluation: The contractor shall evaluate COTS, GOTS, and Open Source Assessment tools and recommend tools for executing the DAs. The contractor shall define tool requirements and define, develop and modify tools and scripts, and support the 688 CW in integrating approved tools. The contractor shall identify, document and demonstrate the proper usage of all tools developed and modified (including scripts and data base queries) under this effort and include them in the Defense Scenarios. (CDRLs A016, A018)

3.1.1.15 Intrusion Assessments (IA): The contractor shall support the 688 CW in developing, evolving, fielding and executing the IA concept.

3.1.1.15.1 Program Development and Evolution: The current 688 CW IA process consists of Log Analysis (LA), Traffic Analysis (TA), Host Analysis (HA), and Binary Analysis (BA).

They are defined as follows:

Log Analysis (LA): research, analyze and correlate log data from various information technologies such as host-based, proxy, firewall, routing and switching devices, and domain name servers, to identify suspicious activities relating to a potential APT on the network.

Traffic Analysis (TA): Analyze network traffic, at the packet level; capture and evaluate traffic patterns, traffic content; identify potential exfiltration, beaconing, and anomalous communications, in order to identify present or past existence of an APT.

Host Analysis (HA): Determine if a host contains an APT or other suspicious activity; deploy a collection agent to each host and analyze the returned host data; analyze host event logs, configuration files, and policy implementation; identify anomalous communications between networked devices, suspicious files, or processes such as spyware, malware or any other unauthorized software.

Binary Analysis (BA): Reverse engineer and analyze binary, executable, and other related files of interest, to include selected application data files, to identify the potential existence of an APT, spyware, adware, malware, or unauthorized software.

The contractor shall support the 688 CW in developing, evolving, and fielding the IA concept and methodology to ensure 688 CW capabilities and methodologies are integrated with the DoD guidance and policy. The contractor shall conduct reviews of competing assessment programs, methodologies, processes and objectives and provide recommendations on how to improve the IA concept, process and reporting. The contractor shall develop, document, and maintain methodologies that address the full spectrum of an assessment: planning, execution, and reporting. The contractor shall provide methodologies and shall include tested and proven tools (both hardware and software based), tactics, and procedures. The contractor shall update methodologies and integrate new methodologies that address the 688 CW mission. (CDRLs A003, A016)

3.1.1.15.2 Tool and Technology Evaluation: The contractor shall evaluate COTS, GOTS, and Open Source Assessment tools for automating the IA process and recommend tools to be used to automate the assessment. The contractor shall define tool requirements and define, develop and modify tools and scripts, and support the 688 CW in integrating approved tools. The contractor shall identify, document and demonstrate the proper usage of all tools developed and modified (including scripts and data base queries) under this effort and include them in the assessment package. (CDRLs A016, A018)

3.1.1.16 Package Development and Support: The contractor shall support the 688 CW in developing, maintaining and evolving assessment packages for each technology area listed in Appendix 2. The contractor shall support the 688 CW in defining a process, steps, methodology and procedures for assessing the security posture of each device. The contractor shall conduct reviews of DoD and AF compliance directives and Industry and Government “Best Practice” suggestions and develop a comprehensive assessment packages for each device and device type.

The contractor shall identify variables, heuristics or characteristics within these devices that could be exploited. The contractor shall develop checklists defining such items as the parameters to check and determine the security posture of the devices. The contractor shall define the data to be collected from each device and determine the device security posture and identify proper parameter settings. (CDRLs A010, A018)

3.1.2 Training and Standard Evaluation (STANEVAL) Support:

3.1.2.1 Program Development and Evolution: The contractor shall support the 688 CW in developing and evolving a formal training and STANEVAL program to train operators to execute AESS tools and components and to assess operator skills and quantify operator ability to execute and operate the AESS. The contractor shall develop a formal training and STANEVAL program to train personnel to execute the VA, DA, and IA missions and to assess operator skills and quantify operator abilities. The contractor shall identify skill sets and expertise levels needed to qualify for device assessment training, identify the training requirements and activities for assessing the devices and identify the infrastructure requirements needed to train personnel to execute the device assessments. The contractor shall generate the training material, including presentation material, proper usage of referenced tools, test material, student guides and instructor guides necessary to teach personnel how to execute the assessment packages (CDRLs A008, A009, A010, A011).

3.1.2.2 Program Execution and Reporting: The contractor shall support the 688 CW in training personnel to operate the AESS, evaluating and reporting their performance and monitoring personnel progress and certification status. (CDRL A001)

3.1.3 Program Management

3.1.3.1 Project Planning: The contractor shall establish, maintain and utilize the program management necessary to plan and execute each individual assessment and infrastructure support project. The Technical and Work Management Plan (TWMP) shall be the contractor’s plan on how it shall execute its approach to business management of the task. (CDRL A002)

3.1.3.2 Program Reviews and Meeting Support: The contractor shall present mission status during pre/post mission briefs and shall support meetings when requested by the Government.

(CDRLs A008, A012)

3.1.3.3 Final Reporting and Trends Analysis. The contractor shall analyze the aggregate information obtained from each assessment completed during contract execution, summarize the results of each mission type and determine the trends in network security posture and estimate potential impacts to operations if these trends are not reversed. (CDRL A017)

3.2 Assessment Operations for Operational Systems

3.2.1 Operational System Assessment Support: The contractor shall support the 688 CW in conducting assessments of developmental systems during various phases of fielding. This includes supporting Operational Test & Evaluations (OT&E), Combined Test & Evaluations (CT&E), and Information Assurance assessments of the system during the various spirals and phases of development. The support required shall include all the tasks described in 3.2.

3.2.2 Assessment Mission Support: The contractor shall provide technical support to complement the existing capabilities of the 688 CW in conducting VAs, DAs and IAs of operational, support, exercise and Defense Industrial Base (DIB) networks. The individuals assigned to the tasking or mission shall meet the technical skills required IAW the 688 CW Mission Request Form. Changes to the schedule and contractor resource allocation shall not be made less than two weeks before mission execution. Any changes shall not be made without the COR coordination. The assessment methodology shall be applied to operational network enclaves, the AF Global Information Grid (GIG), base information technology infrastructure, exercise networks and networks supporting mission and weapon systems and programs of records. The contractor shall provide trained technical personnel to support the following approximate number of missions annually:

a. Vulnerability Assessments -- 30 to 42

b. Intrusion Assessments – 12 to 24

The contractor shall support development of the assessment plan, document all activities and results obtained during the assessment and support generation of the final report. The level and scope of the contractor’s participation in planning, execution and reporting shall be as directed by the COR for each assessment mission. All planning and reporting shall be IAW Government approved reporting templates. (CDRL A001)

3.2.3 Threat Assessment: The contractor shall prepare a comprehensive assessment of the cyber threat to the network and technologies being assessed. The contractor shall review open source literature about the target network to be assessed and threat information from the most recent threat documents as well as from appropriate Government agencies to estimate the mission impact of a cyber-attack. (CDRLs A008, A018)

3.2.3.1 Threat Characterization: The contractor shall support the 688 CW in analyzing and characterizing cyber-attacks. The contractor shall review open source and specialized intelligence products to identify various attack characteristics including the vulnerabilities exploited, the methods used to exploit the vulnerabilities, the attack vectors employed, and the impact of the attack upon operations. (CDRLs A008, A018)

3.2.4 Assessment Planning: The contractor shall support and document the planning necessary to execute and report on each assessment. The contractor shall identify, develop, and refine assessment concepts, objectives, measures of effectiveness, and measures of performance. The contractor shall identify resources, including tools to be used and the expected hours and cost, required to execute each assessment. (CDRL A005)

3.2.5 Assessment Execution: The contractor shall execute assessment activities IAW approved assessment plans, procedures, network configurations, and security provisions. The contractor shall conduct assessments of the network security posture based on visual observations and manual and automated analysis of system, environment, and data. The contractor shall evaluate assessment progress against exit criteria and recommend termination of activities when exit criteria has been satisfied or cannot be satisfied through further activities within schedule, budget, or resource constraints. (CDRL A006)

3.2.5.1 Assessment Activities: These assessments typically involve the following activities:

a. Baseline Estimate: Review system and network documentation such as Interface Control Documents, System Security Authorization Agreement (SSAA), or DIACAP/EITDR packages.

b. Cyber Threat Estimate: Review intelligence data and develop new tools and techniques emulating potential threats to systems and networks.

c. Network Mapping: Map the network to be assessed using multiple mapping tools to provide a logical network map.

d. Security Program Review: Analyze the network enclave policies, procedures and processes or compliance with DoD and AF directives and institution of security “Best Practice” suggestions.

e. Device Security Assessment: Review the configuration and implementation of the security mechanisms for each device on the network for compliance and “Best Practice” implementation.

f. Network Scanning: Conduct network scans, using multiple scanning tools, both externally and internally, to identify open ports, services, and vulnerabilities.

g. Component Enumeration: Enumerate the network components to determine the operating system and patch level of each network component.

h. Penetration Testing – attempt to circumvent a system’s security features by exploiting identified vulnerabilities to gain access and elevate privileges; penetration tests can be conducted both internally and externally.

i. Security Policy Review – review the completeness of the system’s security policy to judge the effectiveness of the system’s security controls; compare the system’s security design and implementation against stated security requirements, SSAA, AF, DoD, Federal IT directives and industry-standard best practices.

j. Assessment Reporting – document, in detail, the security status of the networks and systems assessed and propose potential solutions.

k. Advanced Persistent Threat Detection – identify malware stored or executing on a host.

3.2.6 Assessment Reporting: For each assessment, the contractor shall (1) provide a written plan that includes the approved customized VA methodology and DA scenarios to be executed;

(2) provide formal documentation of daily activities, during the execution, to include tactics, procedures, findings and impacts, and any major events impacting execution; (3) conduct post-assessment analysis to include analyzing data, compiling results, and reporting deficiencies as they are encountered; (4) identify changes made to the original plans; (5) outline, write, peer review, edit, coordinate, finalize, and distribute reports documenting conduct, results, and recommendations regarding system security posture; and (6) update reporting templates and documentation with vulnerability data identified during the assessment and with new policy information released from DoD or AF. All reports shall be IAW Government-approved plans.

(CDRLs A006, A007)

3.2.7 Post Assessment Execution: After the end of each assessment, the contractor shall have 4 calendar days to provide a written After Action Report which includes at a minimum, the following items: (1) lessons learned with the assessment processes and methodologies; (2) lessons learned with the AESS; (3) process improvements; (4) procedural Problems encountered;

and (5) any major events impacting execution. (CDRL A018)

3.3 Assessment Operations for Research and Developmental Systems

3.3.1 Research and Developmental System Assessment Support: The contractor shall support the 688 CW in conducting assessments of developmental systems during various phases of fielding. This includes supporting Developmental Test & Evaluations (DT&E), Combined Test & Evaluations (CT&E), and Information Assurance assessments of the system during the various spirals and phases of development. The support required shall include all the tasks described in 3.2.

3.3.2 Assessment Mission Support: The contractor shall provide technical support to complement the existing capabilities of the 688 CW in conducting VAs, DAs and IAs of operational, support, exercise and DIB networks. The individuals assigned to the tasking or mission, shall meet the technical skills required in accordance with the 688 CW Mission Request Form. Changes to the schedule and contractor resource allocation shall not be made less than two weeks before mission execution. Any changes shall not be made without the COR coordination.

The assessment methodology shall be applied to operational network enclaves, the AF GIG, base information technology infrastructure, exercise networks and networks supporting mission and weapon systems and programs of records. The contractor shall provide trained technical personnel to support the following approximate number of missions annually:

a. Vulnerability Assessments -- 30 to 42

b. Intrusion Assessments – 12 to 24

The contractor shall support development of the assessment plan, document all activities and results obtained during the assessment and support generation of the final report. The level and scope of the contractor’s participation in planning, execution and reporting shall be as directed by the COR for each assessment mission. All planning and reporting shall be IAW Government approved reporting templates. (CDRL A001)

3.3.3 Threat Assessment: The contractor shall prepare a comprehensive assessment of the cyber threat to the network and technologies being assessed. The contractor shall review open source literature about the target network to be assessed and threat information from the most recent threat documents as well as from appropriate Government agencies to estimate the mission impact of a cyber-attack. (CDRLs A008, A018)

3.3.3.1 Threat Characterization: The contractor shall support the 688 CW in analyzing and characterizing cyber-attacks. The contractor shall review open source and specialized intelligence products to identify various attack characteristics including the vulnerabilities exploited, the methods used to exploit the vulnerabilities, the attack vectors employed, and the impact of the attack upon operations. (CDRLs A008, A018)

3.3.4 Assessment Planning: The contractor shall support and document the planning necessary to execute and report on each assessment. The contractor shall identify, develop, and refine assessment concepts, objectives, measures of effectiveness, and measures of performance. The contractor shall identify resources, including tools to be used and the expected hours and cost, required to execute each assessment. (CDRL A005)

3.3.5 Assessment Execution: The contractor shall execute assessment activities IAW approved assessment plans, procedures, network configurations, and security provisions. The contractor shall conduct assessments of the network security posture based on visual observations and manual and automated analysis of system, environment, and data. The contractor shall evaluate assessment progress against exit criteria and recommend termination of activities when exit criteria has been satisfied or cannot be satisfied through further activities within schedule, budget, or resource constraints. (CDRL A006)

3.3.5.1 Assessment Activities: These assessments typically involve the following activities:

a. Baseline Estimate: Review system and network documentation such as Interface Control

Documents, SSAA, or DIACAP/EITDR packages.

b. Cyber Threat Estimate: Review intelligence data and develop new tools and techniques emulating potential threats to systems and networks.

c. Network Mapping: Map the network to be assessed using multiple mapping tools to provide a logical network map.

d. Security Program Review: Analyze the network enclave policies, procedures and processes or compliance with DoD and AF directives and institution of security “Best Practice” suggestions.

e. Device Security Assessment: Review the configuration and implementation of the security mechanisms for each device on the network for compliance and “Best Practice” implementation.

f. Network Scanning: Conduct network scans, using multiple scanning tools, both externally and internally, to identify open ports, services, and vulnerabilities.

g. Component Enumeration: Enumerate the network components to determine the operating system and patch level of each network component.

h. Penetration Testing – attempt to circumvent a system’s security features by exploiting identified vulnerabilities to gain access and elevate privileges; penetration tests can be conducted both internally and externally.

i. Security Policy Review – review the completeness of the system’s security policy to judge the effectiveness of the system’s security controls; compare the system’s security design and implementation against stated security requirements, SSAA, AF, DoD, Federal IT directives and industry-standard best practices.

j. Assessment Reporting – document, in detail, the security status of the networks and systems assessed and propose potential solutions.

k. Advanced Persistent Threat Detection – identify malware stored or executing on a host.

3.3.6 Assessment Reporting: For each assessment, the contractor shall (1) provide a written plan that includes the approved customized VA methodology and DA scenarios to be executed;

(2) provide formal documentation of daily activities, during the execution, to include tactics, procedures, findings and impacts, and any major events impacting execution; (3) conduct post-assessment analysis to include analyzing data, compiling results, and reporting deficiencies as they are encountered; (4) identify changes made to the original plans; (5) outline, write, peer review, edit, coordinate, finalize, and distribute reports documenting conduct, results, and recommendations regarding system security posture; and (6) update reporting templates and documentation with vulnerability data identified during the assessment and with new policy information released from DoD or AF. All reports shall be IAW Government-approved plans.

(CDRLs A006, A007)

3.3.7 Post Assessment Execution: After the end of each assessment, the contractor shall have 4 calendar days to provide a written After Action Report which includes at a minimum, the following items: (1) lessons learned with the assessment processes and methodologies; (2) lessons learned with the AESS; (3) process improvements; (4) procedural Problems encountered;

and (5) any major events impacting execution. (CDRL A018)

4.0 Deliverables: The contractor shall deliver all end…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .