Section_J_Attachment_1-_ICPS_PWS.pdf
PDF 295 KB Posted
- Attached to
- Integrated Cyber Protection Services Federal contract opportunity
- Solicitation number
- FA8773-18-R-8008
About this file
PEFORMANCE WORK STATEMENT
View the file
Other files for this federal contract opportunity
Show all 42
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FOR OFFICIAL USE ONLY (FOUO)
PERFORMANCE WORK STATEMENT (PWS)
FOR
Integrated Cyber Protection Systems (ICPS)
90TH CYBERSPACE OPERATIONS SQUADRON
LACKLAND, AFB TX
RFP# FA8773-18-R-8008
18 Jun 2018
Vision Statement……………………………………………………………………………...4
1 Introduction
1.1 Mission
1.2 Background
1.3 Scope
2 General Requirements
2.1 Distribution and Use Rights
2.2 Non-Personnal Services
2.3 Business Relations………………………………………………………………………..5
2.4 Contractor Records……………………………………………………………………….6
2.5 Contract Management and Administration
2.6 Location and Hours of Work
2.7 Contractor Common Access Card (CAC)
2.8 Travel / Temporary Duty (TDY)
2.9 Technical Interchange Meetings(TIMs)
3 Performance Requirements
3.1 Explore Emerging Technologies in Support of Cyber Defense Platform Capabilities
3.2 Innovate Cyber Defense Platform Capabilities
3.3 Integrate Cyber Defense Platform Capabilities
3.4 Provide Operations Support for Cyber Defense Platform Capabilities
3.5 Provide Information Assurance…………………………………………………………15
4 Product Deliverables and Performance Services Summaries
5 Government Furnished Property, Materials, and Services………………………………..21
6 Special Requirements..……………………………………………………………………22
6.1 Quality…………………………………………………………………………………..22
6.2 Security and Safety
6.3 Mission Essential Services………………..…………………………………………….26
6.4 Operational Contingency Requirements.………………………………………………..26
6.5 Key Control……………………………………………………………………..….…...26
6.6 Housekeeping…………………………………………………………………………...27
7 Applicable Directives
Appendix 1, Acronyms
Appendix 2, Definitions
Appendix 3, ICPS Qualification Technology Areas
Performance Work Statement (PWS)
Integrated Cyber Platform Systems (ICPS)
Vision Statement Innovate and implement solutions to defend the Air Force (AF) network infrastructure against evolving cyber threats; streamline cyber defense processes and capabilities and provide a platform upon which to consolidate multiple information assurance (IA) tools and systems into a single Command and Control management platform.
1 Introduction The 90th Cyberspace Operations Squadron (90 COS), located at Joint Base San Antonio- Lackland (JBSA-Lackland), Texas is the U.S. AF's cyber real-time operations and innovation provider. The squadron is responsible for equipping the warfighter with offensive and defensive cyber warfare capabilities. The 90 COS contains organic expertise on cyber warfare, computer network security, cyber technology integration, and modeling and simulation.
1.1 Mission
Empower all domain warfighters with the ability to execute "State of the Art" cyber effects for freedom of maneuver. The 90 COS of the 688th Cyberspace Wing (688 CW) innovates AF network infrastructure defense solutions under the umbrella project ICPS.
1.2 Background
1.2.1 The Information Operations Platform (IOP) is an example of one of the 90 COS innovative network defense solutions; it combines network defense tools and services to support AF IA and information operations (IO). IOP is a system of systems hardware platform whose functions include real-time network monitoring, enterprise-level intrusion detection and prevention, data management, correlation, forensic capabilities, documentation, reporting, data visualization, and policy enforcement. The IOP system enhances network security by analyzing network internet protocol (IP) traffic and identifying suspicious activity through an in-line monitoring approach.
Upon detecting network threats, the system offers automated and manual blocking of selected network traffic. Multiple network protocols, including transmission control protocol (TCP), user datagram protocol (UDP), and internet control message protocol (ICMP) traffic, are monitored by IOP. Platform detection techniques include attack signature recognition, anomaly detection, expert system correlations, and pattern recognition. System configurations include deployment of mobile suites for short duration missions and traditional, rack-mounted suites for permanent installation applications.
1.2.2 The 90 COS is responsible for the baseline configuration updates, innovation and integration of capabilities, Tier 3 technical support (see Appendix 2 for definition), and subject matter expertise for the ICPS capabilities.
1.2.3 In summary, ICPS is a multifaceted activity, with the goals of meeting urgent cyber security needs and presenting additional real-time options to the cyber operators. Creating new capabilities extends defense-in-depth throughout the entire AF network, from the Global Information Grid (GIG) to airframe to personal computer (PC), and incorporates advanced counter-cyber options for cyber supremacy.
1.3 Scope
This PWS identifies tasks pertaining to ICPS innovations to include: enhancing and developing computer network data monitoring, threat detection, reporting, management, correlation, visualization, and tracking capabilities supporting AF locations world-wide. This is achieved by addressing current and evolving intrusion detection system (IDS) and intrusion prevention system (IPS) requirements in support of the AF’s IA and IO activities within cyberspace. These activities take place within the following construct: Exploration, Innovation, Integration, Operations Support, and Information Assurance.
2 General Requirements
2.1 Distribution and Use Rights
The Government will retain unlimited use and distribution rights for all products developed under this contract, including documentation, presentations, notes and other intellectual property.
Upon completion of the contract, the contractor will deliver all developed products to the Contracting Officer Representative (COR), for the Government's unlimited distribution and use.
The Government retention of distribution rights means that the contractor can apply lessons learned in other contracts, but cannot re-create and/or sell products based on items developed under this contract without explicit permission provided by the COR or a designated representative. Submissions with proprietary markings are unacceptable.
2.2 Non-Personal Services
The Government shall neither supervise contractor employees nor control the method by which the contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor's responsibility to notify the Contracting Officer (CO) and the COR immediately.
2.3 Business Relations
The contractor shall work with the COR to accomplish Government requirements, goals, and mission objectives as efficiently and effectively as possible. This shall include sharing or coordinating information resulting from the work required within the PWS or previous Government efforts and working as a team to perform tasks in concert. The contractor shall ensure minimum duplication of effort in execution of all work specified within this PWS and build upon work previously accomplished by the Government, the contractor, or other contractors to the fullest extent practical. The contractor shall manage the timeliness, completeness, and quality of problem identification. The contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.
2.4 Contractor Records
The contractor shall be responsible for creating, maintaining, and disposing of only those Government required records that are specifically cited in this PWS as required by the Government/COR. If requested by the Government, the contractor shall provide the original record or a reproducible copy of any such record within the required time frame stated on each Contract Data Requirements List (CDRL).
2.5 Contract Management and Administration
2.5.1 Management. The contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned to the requirement. The contractor must maintain continuity between the support operations at JBSA - Lackland and the contractor's corporate offices. The contractor shall conduct at least one formal Program Management Review (PMR) per year and provide meeting minutes per CDRL A002. The contractor or Government may schedule additional informal meetings to review deliverables, address any issues, and review contract status.
2.5.2 Administration. The contractor shall ensure the numbers of personnel, job category and expertise of the personnel assigned are sufficient to accomplish the work specified within this PWS and that contractor personnel maintain technical skills proficiency sufficient to perform assigned duties (reference Appendix 3, for ICPS Qualification Technology Areas). The contractor shall notify the COR of any personnel re-assignments. Any significant changes in workload would be accomplished by contract modification.
2.5.2.1 Enterprise-wide Contractor Manpower Reporting Application (ECMRA) Reporting. The contractor shall report all contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the ICPS via a secure data collection site. The contractor is required to completely fill in all required data fields at http://www.ecmra.mil. Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September.
While inputs may be reported any time during the FY, all data shall be reported no later than 31 October of each calendar year. The contractor may direct questions to the ECMRA help desk.
2.5.2.2 The contractor shall interface with 90 COS military, Government civilians, and other contractors (other companies) assigned to the same functional areas as one team to raise the level of proficiency and effectiveness of the entire team.
2.5.2.3 The contractor shall assign one of the full-time, Department of Defense (DoD) 8570.01- M, Information Assurance Workforce Improvement Program, certified contractor employees as task lead and at least one additional full-time, DoD 8570.01-M certified contractor employee as alternate task lead. The project task lead shall have full authority to act in all matters related to this PWS. This individual shall be responsible and accountable to the COR in representing the contractor for meeting the performance requirements of this PWS. The project task lead or alternate shall be available during normal duty hours, Monday through Friday, except Federal Holidays, to meet with COR to discuss program and/or technical issues. The project task lead shall attend scheduled staff meetings, when needed and requested by the COR.
2.5.2.4 Because the contractor will be innovating and implementing capabilities for cyber operators, contractor shall provide a DoD 8570.01M, Information Assurance – Technical (IAT) Level III certified employee as lead for each of the functional areas: Quality Assurance, Technical Support, Systems Engineering, and Development. Newly assigned personnel assuming the functional lead positions shall complete their certification requirements within six months of assignment to the position.
2.5.3 Personnel Administration. The contractor shall provide the following management and support as required.
2.5.3.1 The contractor shall maintain the currency of their employees by providing initial and refresher training as required to meet the PWS requirements. (Appendix 3)
2.5.3.2 All contractor employees shall be able to read, write, speak and understand the English language to the extent necessary for the performance of this work.
2.5.3.3 The contractor shall not employ any person who is an employee of the Department of the AF, unless such has been approved according to DOD 5500.7-R, Joint Ethics Regulation.
2.5.3.4 Contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification with Government personnel. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversations and in formal written correspondence.
2.5.3.5 Subcontract Management. The contractor shall be responsible for any subcontract management necessary to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance on this requirement. Contractors may add subcontractors to their team after notification to the CO and COR.
2.6 Location and Hours of Work
Accomplishment of the results contained in this PWS requires work at 90 COS facilities located on JBSA, Lackland AFB, 3515 S. Gen McMullen, Bldg. 3, San Antonio, TX 78226, and at various contractor, subcontractor, and Government facilities (both Continental United States (CONUS) and Other than Continental United States (OCONUS) sites).
Available work hours for the Sensitive Compartmented Information Facility (SCIF) are 0600- 1800 hours with workdays Monday through Friday, except U.S. Federal holidays. Only Government personnel are authorized to unlock/lock the SCIF. There may exceptions to the primary work area, but only on a case-by-case basis, therefore, contractors may start no earlier than 0600. All employees are expected to be available during core hours. Core hours of work are from 0900 to 1500 daily.
If the contractor's "holidays" don't align with the Federal holiday schedule, the contractor must provide their personnel an alternate work location. The SCIF will be closed on Federal holidays.
2.7 Contractor Identification Credential and Common Access Cards (CAC) Contractor personnel shall be identified by their 24 AF and Air Force Intelligence Surveillance Reconnaissance Agency (AFISRA) Form 325C (Green Badge) credential, with name, "CONTRACTOR”, and contract expiration date clearly visible and worn above the belt and below the shoulders when present within the TOP SECRET Sensitive Compartmented Information (TS-SCI) Facility (SCIF) as proof of proper clearance to remain unescorted within the SCIF. When exiting, contractor personnel shall conceal their credentials from plain view. To access any Government base and certain facilities, contractor personnel shall present and wear (if required) their contractor CAC identified by a vertical green stripe, in a similar manner as the Form 325C where clearly visible. The CAC is also used to access the DoD Non-Secure Internet Protocol Router Network (NIPRNet). In addition to the CAC, if warranted for mission requirements, contractors will be provided a credential to access Secure Internet Protocol Router Network (SIPRNet) and/or the Joint Worldwide Intelligence Communications System (JWICS).
2.8 Travel / Temporary Duty (TDY)
Travel to other Government facilities or other contractor facilities may be required in coordination with the Contracting Officer and the Government COR. The contractor shall make necessary travel arrangements for employees for TDY purposes. All travel requirements (including plans, agenda, itinerary, or dates) shall be pre-approved by the COR, and is on a strictly cost reimbursable basis. Anticipate contractor personnel shall be required to travel for approximately five days for each CONUS trip and seven days for each OCONUS trip during the contract. These requirements shall include travel overseas; however, they will not include travel into combat areas. Contractor shall provide a daily update and final trip report to the COR within five duty days after trip completion. (CDRL A003)
2.9 Technical Interchange Meetings (TIMs)
The contractor shall participate as the Government’s subject matter expert (SME) in TIMs (Examples: Configuration Control Boards (CCB), collaborative prototype reviews, developmental/operational testing, etc.) with the government project lead or by direction of the COR as required by the Government. The Contractor shall be given a 24 hour notification prior to any meeting requiring them to perform as the Subject Matter Expert (SME). TIMs may be conducted at any time and address any aspect of the contract. If requested by the Government, the contractor shall document results and deliver to the Government upon request. (CDRL A002)
3 Performance Requirements The following sections specify the Performance Objectives and Performance Elements for the contract. DoDI 8500.01, Cybersecurity, provides an overarching reference for all cyber activities conducted in this contract.
3.1 The contractor shall explore emerging technologies in support of cyber defense platform capabilities for 90 COS customers.
3.1.1 The contractor shall perform requirements identification/analysis in support of business/product development planning.
Task includes:
• Perform requirements identification/analysis for creating draft requirement documents in government-provided formats (Statement of Requirement (SOR), Cyber Needs Form (CNF), and AF Form 1067) as a prelude to innovating, integrating, and supporting operations in collaboration with operational users and/or vetted through a requirements vetting process.
• Providing inputs on the technical, financial and schedule risks associated with the requirements changes, as part of the requirements vetting process.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.1.2 The contractor shall explore advanced IDS/IPS capabilities considering changes in form factor and technologies to support fixed and deployable architectures.
Open source applications, research performed by other Government organizations, Defense Technical Information Center (DTIC) reports, computer science/machine learning journals, and commercial product advertisement all constitute valuable resources for identifying advanced threat detection/prevention algorithms or applications.
Task considers:
• New detection applications/signatures/heuristic and data post-processing algorithms to fill gaps between existing capabilities and emerging threats and to assist network operators in prioritizing detected threats
• Applying existing IDS/IPS capabilities in new ways to create new capabilities, or leveraging existing capabilities to address different network threats
• Explore new hardware subsystems or virtual appliances, considering impact to system performance, form factor, power requirements, and weighed against potential improvements in capability.
• Tactical response capabilities against malicious attacks and malicious logic incorporating automated and manually-driven real-time prevention; true source identification, and bi-directional firewall and router capabilities for blocking, redirection, and connection termination.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services A006 Software User Manual
3.1.3 The contractor shall explore potential solutions and present courses of action (COAs) in response to system change requests (SCRs).
This task includes determining priorities of SCRs and timelines for developing COAs.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.2 The contractor shall innovate cyber defense platform capabilities for 90 COS customers.
3.2.1 The contractor shall create/enhance hardware and software interfaces for IOP and other native cyber defense systems as required for meeting customer and/or 90 COS mission requirements.
Current subsystems include the Modular Real-time Information Operations Platform (MRIP), Information Operations Platform Server (IOPS), the Gateway Manager (GWM), the Third Party
Server (TPS), the Central Management Server (CMS), and IOP System Update Repository
(ISUR).
Task includes:
• Simplifying/expanding/automating command and control of multiple systems to include self-contained C2 when disconnected from a centralized management network
• Displaying intrusion related information in more intuitive formats and extending network operator interfaces to enable access/display of new data types/sources
• Enabling more efficient and effective use of system resources
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.2.2 The contractor shall explore, prototype, innovate, and integrate input acceptance, data processing, and reporting capabilities for IDS/IPS at multiple security levels.
This task includes developing solutions that include automated detection/mitigation/correlation of network threat alerts with cyber intelligence reports/databases available on higher classification networks, such that operators are better able to interpret and act on network events based on contexts and report in the format provided by the intelligence community.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.3 The contractor shall integrate cyber defense platform capabilities for 90 COS customers.
3.3.1 The contractor shall prepare technical orders (T.O.s) for approved modifications to native cyber defense systems.
This task includes preparing T.O.s IAW MIL-STD-38784, Standard Practice for Technical Manuals - General Style and Format. Electronic documents may be required to be in specific document creation tool (e.g. ArborText) formats.
Deliverables A001 Progress Report (Monthly Status Report) A004 Technical Orders
3.3.2 The contractor shall establish and maintain version control for all software and configuration items (CI) being prototyped and innovated.
Currently, CIs consist of hardware inventory, software inventory, deployed system configurations, hardware and software maintenance contracts, innovation tools, and system documentation. Government personnel will have access to the applications used for this purpose.
The contractor can recommend CIs for government disposal as needed to remove outdated or non-repairable items.
Deliverables
A001 Progress Report (Monthly Status Report) A007 Configuration Item Control Application
3.3.3 The contractor shall explore, prototype, innovate, and integrate improved methods for correlating sensor feeds into the Security Information and Event Management (SIEM) displays and visualization capabilities.
Data filter criteria may include ports, protocols, address ranges, geographic location of connection termination points, signatures, strings, patterns, statistical measures of alert features, temporal relationships between alerts (timing), etc. Currently, the SIEM used is ArcSight ESM.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services A006 Software User Manual
3.3.4 The contractor shall explore, prototype, innovate, and implement corrective actions and solutions for deficiencies and discrepancies discovered during testing.
This task includes determining priorities of deficiencies and timelines for making corrections.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services A005 QA Test Plan A006 Software User Manual
3.3.5 The contractor shall develop quality assurance (QA) test procedures and perform QA testing for all system changes (enhancements, updates, developments, creations, methods, and improvements) and integration of third party applications.
Contractor shall rely on industry best practices to develop QA test procedures. The contractor shall present QA test procedures for government review and approval prior to implementation.
Deliverables
A003 Technical Report--Study/Services A005 QA Test Plan
3.4 The contractor shall provide operations support of cyber defense platform capabilities for 90 COS customers.
3.4.1 The contractor shall maintain/enhance active mode and in-line feature sets which allows for network management and control via static firewall and dynamic IDS/IPS activity rule establishment; configurable timeouts of IDS/IPS actions; and controls for operator initiated and autonomous rule/policy enforcement.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.4.2 The contractor shall attend and provide SME support for developmental tests, operational tests, field service evaluations, test readiness reviews, and test-related TIMs.
During testing and evaluations, the contractor may be required to play the role of operator.
Deliverables A001 Progress Report (Monthly Status Report) A002 Meeting Minutes
3.4.3 The contractor shall innovate, integrate, and QA test signatures, countermeasure rule logic, and concepts for systems in sustainment.
This task includes interfacing and augmenting the SIEM (currently ArcSight).
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services A005 QA Test Plan
3.4.4 The contractor shall provide cyber analysis SME support acting as liaison between cyber developers and cyber operators to assist in developing tactics, techniques and procedures (TTPs) and developing operator training venues as required.
Deliverables
A003 Technical Report--Study/Services
3.4.5 The contractor shall provide Tier 3 technical support and resolution for cyber defense system hardware and software malfunctions, emerging requirements that require a change to the system, or configuration problems concerning the fielded systems.
Task includes:
• Providing advanced technical expertise applied to issues not resolved by Tier 1 or 2 support. This may include calling in vendor support
• Coordinating through the AFNet Response Center, which is responsible to provide Tier 1 and 2 technical support
• Reconfiguring and redeploying upgrades and modernizations for fielded cyber defense systems
• Potential for traveling to locations in CONUS and OCONUS to upgrade and repair systems on-site
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services A006 Software User Manual A007 Configuration Item Control Application
3.4.6 The contractor shall develop and conduct familiarization training and/or technical instruction for ICPS platform systems/capabilities and provide course development support to the 39 IOS.
Task includes:
• Planning and conducting training/instructing 4 x 1 week sessions per year Planning and training/instructing 10 individuals per session +/-50%
• Providing 4 wks/yr on-site support with 39 IOS, Hurlbert Field, FL, developing/updating course material for training ICPS platform(s) operations and maintenance
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.4.7 The contractor shall manage and maintain 90 COS/DOP information technology (development and innovation) equipment (ITE) and automated data processing (ADP) equipment IAW AFMAN 33-153, Information Technology (IT) Asset Management (ITAM) and Air Force Instruction (AFI)pps 23-111, Management of Government Property in Possession of the Air Force.
This task includes periodic physical inventories and Defense Logistics Agency Disposition Services (formerly Defense Reutilization and Marketing Office (DRMO)) equipment transfer efforts.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.4.8 The contractor shall design, build, modify, maintain, and administer 90 COS/DOP developmental systems, networks, and environments.
Temporary and permanent networks are required to support testing, development, and other activities which includes hardware, software, and virtual networks. Temporary networks include infrastructure for USAF and other DoD exercise networks, testing and lab environments to support cyber capability development. Permanent networks include closed development networks of multiple domains.
Deliverables A001 Progress Report (Monthly Status Report) A003 Technical Report--Study/Services
3.5 The contractor shall provide IA for 90 COS customers per current guidance directive(s) (currently DoDI 8510.01, Risk Management Framework (RMF) for DoD IT).
Task includes:
• Conducting IA testing for each SCR generated.
• Creating and maintaining documentation for Plan of Action and Milestone (POA&M) as required for the successful certification and accreditation (C&A) of each system version released prior to operational deployment.
• Obtaining and/or maintaining C&A of all ICPS platform systems/capabilities and supporting networks.
Deliverables
A003 Technical Report--Study/Services.
4 Product Deliverables and Performance Services Summaries The contractor shall provide deliverables as described in Table 1, Product Deliverables Summary. Format and delivery schedule for deliverables shall be outlined in the CDRLs.
TABLE 1. Product Deliverables Summary
CDRL DELIVERABLE
PRODUCT
DID
REFERENCE
PWS
REF
DELIVERY SCHEDULE
A001 Progress Report (Monthly Status Report)
DI-MGMT-
80227
3.1.1 – 3.5 Shall be delivered to the COR by the 15th of each month for the preceding month’s activities
A002 Meeting Minutes DI-ADMN- 81505
2.5.1, 2.9, 3.4.2
Minutes shall be provided to the COR within five working days after meeting TIM and
PMR
A003 Technical Report – Study/Services
DI MISC-
80508B
2.8,
3.1.1 - 3.2.2,
3.3.3 - 3.4.1,
3.4.3 - 3.5
As required by COR
A004 Technical Orders MIL-STD- 38784
3.3.1 As required by COR and
Program Management Office
(PMO)
A005 QA Test Plan DI-IPSC- 81438A
3.3.4 - 3.3.5, 3.4.3
As required by COR
A006 Software User Manual
DI-IPSC-
81443A
3.1.2, 3.3.3 - 3.3.4, 3.4.5
As required by COR
A007 Configuration Item Control Application(s)
Contractor recommended, COR approved format
3.3.2, 3.4.5 As required by COR
A008 Professional Employee Compensation
(PEC)
Government Format
NLT the 30th day after the end of the 3rd Option Year.
TABLE 2. Services Summary
Performance Element
Performance Objective PWS Reference
Standard (STD)/Acceptable Quality Level (AQL)
1 • Perform requirements identification/an alysis in support of business/product development planning. Draft requirement documents to be produced following government formatting guidelines in preparation for requirements vetting process.
(Examples:
Cyber Needs Form (CNF);
AF Form 1067, Modification Proposal).
3.1.1 • STD: Documented requirements are free of self-contradictions, operationally relevant, compatible with existing devices/interfaces, and don’t degrade existing capabilities;
• AQL: Meets STD >80% of time and requires no significant changes.
Element
Performance Objective PWS Reference
Standard (STD)/Acceptable Quality Level (AQL)
2 • Innovate and present COAs in response to SCRs.
3.1.3 • (a) STD: COAs are compliant with customer and/or 90 COS requirement documents, operationally relevant, compatible with existing devices/interfaces, and don’t degrade existing capabilities;
• AQL: Meets STD >80% of the time and requires no significant changes.
• (b) STD: Completes actions within timelines agreed upon between the contractor and 90 COS w/no significant changes;
• AQL: Meets STD >80% of time.
3 • Establish and maintain version control for all software and CIs being innovated, prototyped, and baseline deliverables.
3.3.2 • STD: Records must be accurately maintained IAW govt. approved CDRL submission with no significant changes;
• AQL: >90% of the time.
Performance Objective PWS Reference
Standard (STD)/Acceptable Quality Level (AQL)
4 • Develop QA test procedures and/or perform QA testing for all system changes and integration of third party applications.
3.3.5 • STD: Developed QA test procedures are compliant with customer and/or 90 COS requirement documents, operationally relevant, compatible with existing devices/interfaces, and don’t degrade existing capabilities;
• AQL: Meets STD >90% of time.
• STD: QA test procedures are performed timely within timelines agreed upon between the contractor and
90 COS;
• ALQ: Meets STD >90% w/no more than three re-runs required to complete tests.
5 • Provide Tier 3 technical support and resolution for cyber defense system hardware and software malfunctions, emerging requirements that require a change to the
3.4.5 • STD: Trouble tickets resolved or dispositioned for resolution within five business days of receipt;
• AQL: Meets STD >80% of time.
• STD: Reconfiguration and redeployment is compliant with customer and/or 90 COS requirement documents, operationally relevant, compatible with
Performance Objective PWS Reference
Standard (STD)/Acceptable Quality Level (AQL) system, or configuration problems concerning the fielded systems existing devices/interfaces, and don’t degrade existing capabilities;
• AQL: Meets STD >90% of time.
• STD: Completes actions within timelines agreed upon between the contractor and 90 COS w/no significant or repeated flaws;
• AQL: Meets STD >90% of
6 • Develop and conduct familiarization training and/or technical instruction for ICPS platform systems/capabili ties.
3.4.6 • STD: Training content, materials, delivery, and effectiveness will meet trainee needs based on objective feedback from trainees. AQL: Meets STD >80% of time.
• STD: Training developed/modified and conducted within timelines agreed upon between the contractor and 90 COS.
AQL: Meets STD >75% of
7 • Conduct IA testing for each SCR generated
3.5 • STD: Compliant with applicable IA standards;
AQL: Meets STD >95% of
Performance Objective PWS Reference
Standard (STD)/Acceptable Quality Level (AQL) time.
• STD: IA testing completed within timelines agreed upon between the contractor and 90 COS; AQL: Meets STD >95% of time.
5 Government Furnished Property, Materials, and Services
5.1 IAW FAR 45.000(b)(5), Government furnished property is not applicable to services being performed in this PWS. However, the Government will provide access to the Internet, hardware, software, office space, and any applicable documentation required for performance. The contractor shall work on a closed system environment where all code, documentation, and project management information will be kept. The contractor shall use a combination of virtual and physical machines in preparing deliverables. The project management software and virtual and physical machines are Government-furnished. The operating systems include Unix, Linux, VMware, and Windows (7, 8, 2003, 2008). Other systems the contractor will operate are Cisco and Juniper switches/routers, Adaptive Security Appliance (ASA), traffic generators, Bluecoat Proxy servers and other IDS/IPS sensors and equipment.
5.2 Online wiki systems will be provided for the purpose of product and project documentation.
These are administered and accessed through the closed development network.
5.3 All products assessed, evaluated, tested and developed under this requirement, including hardware, software, CIs, documentation, presentations, and notes, shall be considered the sole intellectual property of the 90 COS and delivered to the COR upon completion of the contract.
Any proprietary information and or intellectual property developed under this requirement are the sole property of 90 COS. All previously mentioned items shall be treated as AF proprietary information, and this information shall not be released without prior written permission from
CO.
5.4 The contractor shall be responsible for safeguarding all Government property provided for contractor use. At the close of each work period, Government facilities, property, and materials shall be secured.
5.5 Government telephones shall be used only for official government business.
6 Special Requirements
6.1 Quality
This section describes the Quality Control components for this effort. The following sub-sections provide details of various considerations on this effort.
6.1.1 Quality Control Plan (QCP). The contractor shall maintain an effective QCP and quality control program to ensure services are performed IAW the contract and this PWS. The contractor shall implement procedures to identify, prevent, and ensure non-recurrence of defective services.
Any modifications to the program during the period of performance shall be provided to the CO for review no later than 10 working days prior to effective date of the change. The QCP shall be subject to the Government’s review and acceptance. The Government may find the QCP "unacceptable" whenever the contractor’s procedures do not accomplish quality control objective(s). The contractor shall revise the QCP within 10 working days from receipt of notice that QCP is found "unacceptable."
6.1.2 Quality Assurance Surveillance Plan (QASP). The Government shall monitor the contractor’s performance under this requirement IAW the Government’s QASP.
6.2 Security and Safety
6.2.1 Information Security and Force Protection. The contractor shall comply with the Information Security and Force Protection requirements as defined by DoDM 5200.01 Vol 1-4 (DoD Information Security), AFI 16-1404 (Information Security Program Management), and AFI 10-245 (Air Force Antiterrorism Standards). The contractor shall participate in the 67 CW sustained Information Security and Force Protection/Anti-terrorism training program as provided/required by the Unit Security Manager (USM) and Unit Antiterrorism Representative (UATR). The 67 CW Unit Training Manager will evaluate the training posture of AF contract activities and operations. This requirement is set forth in AFI 16-1404, AFI 10-245 and applicable AF Space Command (AFSPC) and local supplements.
The Government considers the requirement of an active Contractor TOP SECRET (TS) Facility Clearance as a definitive responsibility matter. Clearance documentation shall be the sole responsibility of the Offeror. Offerors are advised to review their clearance documentation prior to the proposal due date. Prime Offerors without a TS Facility Clearance will not be considered for award. Offerors shall submit the DD254 with Blocks 6 and 7 completed. Offerors should review the DD254 new format as the block numbers may have changed.
The contractor shall follow the security requirements outlined in the Department of Defense (DD) Form 254, Department of Defense Security Classification Specification. On contract start date, a minimum of 90% of individuals working shall have a TS/SCI clearance and be Director of Central Intelligence Directives (DCID) 6/4 eligible with a current Single Scope Background Investigation (SSBI); the remaining personnel must hold a minimum of a Secret clearance pending the completion of an SSBI investigation and must work expeditiously to obtain their TS/SCI clearance within 90 days of contract award.
6.2.2 Operations Security (OPSEC). The contractor shall provide OPSEC protection for all sensitive/critical information as defined by AFI 10-701 (Operations Security), the 67 CW OPSEC Plan, and critical information list. The contractor shall participate in the 67 CW sustained OPSEC awareness training program as part of their on-going security education and training. The 67 CW OPSEC coordinator will evaluate the OPSEC posture of AF contract activities and operations.
6.2.3 Individual Clearances. IAW DD Form 254. The Contractor shall obtain a U.S. security clearance at the minimum level of TS/SCI for all contractor personnel required to have access to classified information or require IT-II or IT-I level access. Onsite contractor personnel should have an active clearance prior to reporting for duty in support of any contract. Interim clearances for newly hired personnel shall be processed as expeditiously as possible since some contractor personnel will be required to utilize the SIPRNET and/or JWICS to process classified materials;
however this will be on a case-by-case basis. Such clearance must be obtained through the Defense Investigative Services. The Contractor shall ensure that employees meet the personnel security clearance requirements of the National Industrial Security Program (NISPOM), Chapter 2, Section 2. The Contractor shall provide current listing of employees prior to the start of the contract and immediately upon any updates to an employee's status or information change. The list shall include employee's name, social security number, and level of security clearance. The Contractors Facility Security Officer (FSO) shall validate the list and provide to the Sponsoring Agency's Unit Security Manger (USM) via JPAS and via 67 CW Access Request Letter.
Template will be provided by the USM or 67 CW Security Office to the FSO prior to start of contract.
6.2.4 Access Credentials. Contractors will be issued facility access credentials upon in-processing and final indoctrination to SCI materials. Contractors are required to display the access credentials when inside of the facility and immediately remove the credential upon departure from the facility. The contractors will be provided a unique PIN which is not to be shared with any other individual. Contractors are required to notify the Unit Security Manager immediately in the event the access credential is lost or stolen. The Contractor shall obtain the pass and identification items required for contract performance. The Contractor shall obtain base identification badges from the appropriate security office for each Contractor employee. The Contractor shall obtain all other required access badges, such as computer facilities access badges, computer access ID numbers and passwords from the Government.
6.2.5 Physical Security. The contractor shall be responsible for safeguarding all Government equipment, information and property provided for contractor use. At the close of each work period, Government facilities, equipment, and materials shall be secured. When authorized in writing by the unit of assignment unit commander, contractors may be authorized to Open/Close the facility. Specific facility Opening/Closing training will be provided by the unit of assignment Unit Security Manager. The Contractor shall comply with established security procedures.
Security support requiring joint AF and Contractor coordination includes, but is not limited to, packaging classified information, mailing and receiving classified materials, implementing emergency procedures for protection of classified information, security checks, and internal security controls for protection of classified material and high value pilferable property.
6.2.6 Contractor-Supplied Personal Electronic Devices (PED). Only validated contractor-supplied PEDs, which serve a justified mission requirement in support of this contract, will be considered and authorized by the appropriate Special Security Office (SSO) and/or Special Security Representative (SSR). All required contractor-supplied PEDs will be listed in the Statement of Work and identified in the Department of Defense Form 254, Department of Defense Contract Security Classification Specification, in Block 13. Device listing must include Type, Model, Serial Number, and justification for usage. Contractors utilizing contractor-supplied PEDs will be required to adhere to establish usage policies and procedures to include being issued a property pass to carry contractor- supplied PEDs in and out of facilities in support of an AF contract. Exception: Individuals issued a contractor-supplied fitness device must contact their assigned 67 CW Unit Security Manager prior to introducing the device into the facility. Members must submit the required information/documentation to the SSR for approval.
Any/all fitness devices must be on the current NSA approved, Updated Fitbit Analysis listing, and/or meet the minimum AFSPC directed criteria.
6.2.7 Visitor Group Security Agreement (VGSA). The contractor shall sign a Contractor Visitor Group Security Agreement to protect classified information involved in performance under this contract or Task Order. The Agreement will outline responsibilities to include the following areas: Contractor security supervision; Standard Practice Procedures (SPP); access, accountability, storage, and transmission of classified material; marking requirements; security education; personnel security clearances; reports; security checks; security guidance; emergency protection; protection of government resources; DD Forms 254; periodic security reviews; and other responsibilities, as required.
6.2.8 TEMPEST/EMSEC/INFOSEC/COMPUSEC. The Contractor shall implement TEMPEST, Emissions Security (EMSEC), Communications Security, Information Security (INFOSEC), and Computer Security (COMPUSEC), measures IAW Government, host base, and assigned unit policies as required, to include participation in any/all training requirements for the above disciplines. The Contractor shall safeguard Government property and controlled forms provided for Contractor use. At the end of each work period and when authorized, the Contractor shall secure Government facilities, equipment, and materials.
6.2.9 Base Traffic Regulations. The Contractor shall comply with base regulations pertaining to the possession of weapons, firearms and ammunition, speed limits and use of cell phones.
6.2.10 Security Clearances. The Contractor’s Security Officer will work closely with the COR to ensure compliance with all security requirements. The contractor shall maintain a current listing of employees. This list shall include employees’ names, social security numbers, and level of security clearances. This employee list should be marked "Subject to the Privacy Act of 1974 for privacy purposes. The list shall be validated and signed by the company Facility Security Officer (FSO) and provided to the CO and COR prior to contract start date. The contractor shall provide updated listings whenever an employee’s status or information changes.
6.2.11 Safety. The contractor shall conform to the safety requirements contained in the contract for all activities related to the accomplishment of the work. The contractor shall take such additional immediate precautions as the COR may reasonably require for safety and mishap prevention purposes. Government offices possess an Emergency Response Plan which details how to maintain a safe work environment in case of an emergency. This plan is posted on the operations floor and at all building exits to ensure all contractor employees, Government facilities and property are secure.
6.2.12 Safety Mishap Notification. The contractor shall notify the COR or 90 COS Unit Safety Representative within one hour of all mishaps or incidents. The 90 COS Unit Safety Representative will contact the 688 CW/SE (Wing Safety Office) should the need arise. A written report of the mishap/incident shall be sent within three calendar days to the COR, who will forward it to the 90 COS Safety Office. For information not available at the time of initial written report, contractor shall provide the remaining information no later than 20 calendar days after the mishap, unless extended by the 90 COS Safety Office. Mishap notifications shall contain, as a minimum, the following information:
• Contract, Contract Number, Name and Title of Person(s) Reporting
• Date, Time and exact location of accident/incident
• Brief Narrative of accident/incident (Events leading to accident/incident)
• Cause of accident/incident, if known
• Estimated cost of accident/incident (material and labor to repair/replace)
• Nomenclature of equipment and personnel involved in accident/incident
• Corrective actions (taken or proposed)
• Other pertinent information
If requested by the COR or 90 COS Safety Office, contractor shall immediately secure the mishap scene/damaged property and impound pertinent maintenance and training records, until released by the 90 COS Safety Office. If the Government elects to conduct an investigation of the accident/mishap, contractor shall cooperate fully in the conduct of investigation until the investigation is completed.
The safety provisions of this contract shall apply to any subcontracts/subcontractors. The contractor shall include a clause in each applicable subcontract requiring the subcontractor's cooperation and assistance in accident reporting and investigation.
6.3 Mission Essential Services.
6.3.1 IAW DFARS 237.7602, all the functions under Section 3 requirements are considered to be mission essential and the contractor shall be required to continue to perform at the same level during national crisis and other Government non-work days.
6.3.2 The offeror shall provide with its offer a written contingency plan describing how they will continue to perform the essential contractor services listed in section 3 of the PWS, Mission Essential Contractor Services, IAW DFARS provision 252.237-7024.
6.4 Operational Contingency Requirement (OCR)
6.4.1 Contractor shall respond to within scope undetermined short term events/tasks necessary to support 90 COS ICPS. The tasks will include changes in scheduled development and deployment efforts with a short lead time, as well as, provide an OCR capability for 24x7 on-site and remote operations support as identified by the PWS provided by the CO. Historical usage and examples of OCRs can be found in Appendix 2. The COR shall provide a PWS outlining the task requirement with a period of performance not to exceed the current option performance period.
OCRs shall be added to the contract via a modification to the contract.
6.4.2 The contractor shall maintain awareness by researching current and emerging cyber defense related technologies and methodologies, software optimization technologies, and hardware acceleration products. The contractor shall prepare analyses of these technologies and their impacts to the ICPS systems.
6.5 Key Control
6.5.1 The contractor shall establish and implement methods of ensuring that all keys and key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons.
6.5.2 The contractor shall immediately report the occurrences of a lost or duplicate key to the
COR.
6.5.3 In the event keys, other than master keys, are lost or duplicated, the contractor shall, upon written direction of the CO, rekey or replace the affected lock…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.