Attachment_6_FSS_II_Draft_PWS_13_Apr_18.pdf
PDF 6 MB Posted
- Attached to
- Facility Support Services Federal contract opportunity
- Solicitation number
- FA9101-18-R-1000
View the file
Other files for this federal contract opportunity
Show all 50
Facility Support Services has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA9101-18-R-1000
Attachment 6
Draft Performance Work Statement
Arnold Air Force Base Facility Support Services
13 April 2018
1 Introduction
1.1 Mission
1.2 Background
1.3 Scope
2 General Requirements
2.1 Business Relations
2.2 Contract Administration and Management
3 Performance Requirements
3.1 Industrial Security, Test Security, and Security Management Support
3.3 Command, Control, and Communications
3.4 Fire and Emergency Services Program
3.5 Environmental Program
3.6 Safety Program
3.7 Occupational and Environmental Health (OEH)
3.8 Base Supply
3.9 Cargo Movement
3.10 Vehicle Operations and Maintenance
3.11 Interface Management
3.12 General Management
4 Special Requirements
4.1 Government Furnished Property
4.2 Transition
4.3 Applicable Directives
5 Acronyms
6 Deliverables
7 Performance Requirements Summary
APPENDICES
APPENDIX A – CLOSED AND RESTRICTED AREAS
APPENDIX B – FESAP CHECKLIST
APPENDIX C – MUTUAL AID AGREEMENTS
APPENDIX D – ABOVEGROUND STORAGE TANKS
APPENDIX E – ENVIRONMENTAL PERMITS
APPENDIX F – ENVIRONMENTAL PLANS
APPENDIX G – HAZARDOUS WASTE GENERATION
APPENDIX H – NPDES DATA
APPENDIX I – PERMITTED SEPTIC TANKS
APPENDIX K – SIGNIFICANT LEAKS OR SPILLS HISTORICAL DATA
APPENDIX L – ARNOLD AFB VEHICLE FLEET
APPENDIX M – FSS BUILDING MANAGER INVENTORY
Performance Work Statement (PWS) Facility Support Services (FSS)
1 Introduction
The Air Force Test Center's (AFTC) Arnold Engineering Development Complex (AEDC) is a national aerospace ground test facility that conducts tests, engineering analyses, and technical evaluations for research, system development, and operational programs of the Air Force (AF) and Department of Defense (DoD), other Government agencies, and industry. Using ground test facilities and computational engineering, AEDC supports propulsion, aerodynamic, reentry, trans-atmospheric, and space-flight systems testing. This testing underpins the technical knowledge required for the development and qualification of key warfighter aerospace weapons.
Testing is performed in an environment that simulates operational conditions. AEDC also performs research to develop new technology for advanced test facilities, test techniques, and measurement methodologies associated with ground tests.
1.1 Mission
AEDC exists to test and evaluate weapon, propulsion, aerodynamic and space systems at realistic conditions for the nation through modeling, simulation and ground test facilities.
The mission is essential to developing and fielding weapons systems for the nation's warfighters.
The FSS Contractor will be expected to perform in this mission, while smoothly integrated with the other Arnold Air Force Base (AFB) contractors and Government personnel, in a manner that makes AEDC the best value and most effective ground test and evaluation complex in the world.
1.2 Background
Arnold AFB, located in Tullahoma, TN, has been Government-managed and contractor-operated since its inception. Contractors conduct test operations, base operations, test facility and base infrastructure maintenance and improvement efforts, and many other services critical to operating and sustaining the nation's largest collection of aerospace ground test facilities. The AEDC Test Operations and Sustainment (TOS) contract provides the contractor workforce necessary to successfully operate and sustain AEDC's test facilities at Arnold AFB, TN, and geographically separated units (GSUs) at White Oak, MD, and Moffett Field, CA. Enterprise contracting initiatives beginning in 2015 resulted in information technology tasks, operation of the Precision Measurement Equipment Laboratory (PMEL), and technical management and engineering analysis support for test programs being performed under separate contracts. In addition, some portions of base operating support (BOS) tasks, historically part of the overall operating contract, were set aside for small business under an FSS contract.
1.3 Scope
This contract effort provides multiple aspects of BOS functions in support of AEDC’s test mission. The FSS contract provides supply, vehicle maintenance, cargo movement, operations center and command & control (C2) functions, industrial and test security, security services, and fire and emergency services. The FSS contract also provides support for overall AEDC Safety, Environmental, and Occupational Health programs.
2 General Requirements
The effort will be performed primarily at Arnold AFB in Tennessee. Performance will also be required at AEDC facilities housed as tenants on sites at Tunnel 9 in White Oak, MD and on the National Aeronautics and Space Administration (NASA) Ames Research Center (ARC) grounds at Moffett Field, CA where specified. Requirements listed in this PWS are assumed to be Arnold AFB unless specifically noted otherwise.
2.1 Business Relations
The Contractor shall successfully integrate and coordinate all activities needed to execute the requirements. The Contractor shall manage the timeliness, completeness, and quality of problem identification. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of sub-contractors. The Contractor shall coordinate and cooperate closely with associate Contractors involved in the execution of AEDC’s mission. The Contractor shall seek to ensure satisfaction of all internal and external customers, and ensure professional and ethical behavior of all Contractor personnel.
2.2 Contract Administration and Management
The Contractor shall perform all contract management functions required to ensure proactive and sustained contract excellence in providing accurate, safe, secure, timely, and efficient facility support services to meet the Government's established requirements.
2.2.1 Contract Management
The Contractor shall designate and locate at Arnold AFB a responsible corporate official with no responsibility other than for this contract and empowered to make and implement all decisions regarding the performance of this contract.
2.2.2 Contract Administration
The Contractor shall:
• Ensure performance of the business and administrative aspects of the contract;
• Report all Full-Time Equivalents (FTEs) in accordance with (IAW) Section 8108 of Public Law 112-10 of the DoD and Full-Year Continuing Appropriations Act, 2011;
• Ensure resources are efficiently and effectively managed and contract status (including Government-furnished resources) is reported to Government representatives; and
• Develop, implement, and manage formal associate Contractor agreements with the following contractors at Arnold AFB: TOS; Test Services; PMEL; Performance Based Remediation; and Base Communications and Information Technology Services (BCITS).
2.2.3 Personnel Administration
The Contractor shall:
• Maintain a qualified work force to support the Government and ensure AEDC maintains compliance with all applicable regulations. Conduct employee, supervisory, and management training programs;
• Maintain staffing records identifying company organizational designations, a brief description of the functions, and the number and types of personnel assigned; and
• Provide and administer an Equal Opportunity Affirmative Action Program that complies with all Federal statutes.
3 Performance Requirements
3.1 Industrial Security, Test Security, and Security Management Support
At Arnold AFB, the FSS Contractor will be designated as an “On-Base Cleared Facility” per DoD 5220.22-R and will be cleared under the provisions of the National Industrial Security Program (NISP). The Chief of Information Protection has been designated by the Installation Commander to provide security oversight and the Information Protection Office will be the Servicing Security Activity (SSA).
As the Prime Security Contractor and an “on-base cleared facility,” the FSS Contractor will be responsible for establishing & managing all physical space, listed in Appendix A and all other spaces determined by the SSA requiring additional safeguards. In addition, the FSS Contractor is required to meet all PWS 3.1 requirements at AEDC Moffett Field. The Contractor is responsible for establishing standard security practices and procedures for classified and commercial test areas as well as managing the Special Access Programs (SAP) Security Program under the direction of the Government Special Security Officer (GSSO). In order to fully implement AEDC Information Protection Program objectives, the Contractor will need to work with and perform security support functions in coordination with the Chief of Information Protection, the AEDC Government SAP Security Officer, AEDC Security Managers, respective program/project manager(s), and other Contractors performing work at AEDC.
In addition to requirements identified in the DD Form 254, this effort must ensure compliance with a variety of specialized security directives, regulations, and guides, including DoD Regulations, AFIs, and related AEDC policies/operating instructions (OIs). Contractor personnel must also have knowledge of DoDM 5205.07, Volumes 1-4 and the Joint Security Implementation Guide (JSIG), Foreign Disclosure, DoD regulations, pertinent Department of Navy regulations, SAF/AQ Policy Documents, and pertinent Executive Orders. The Contractor personnel must be familiar with protecting Automated Information Systems. The Contractor must be aware and adhere to revised publications listed in Section 3.1.5 to ensure proper compliance.
3.1.1 Test Security and Facility Clearance Level (FCL) Management
3.1.1.1 The Contractor shall have a valid Top Secret FCL and maintain an industrial security program compliant with DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), and other mandatory directives listed in the solicitation to protect information and operations critical to the successful accomplishment of AEDC’s mission. Additional mandatory directives are listed in Section 3.1.5.
There are certain Inherently Governmental Functions and activities that cannot be outsourced to a contractor. Inherently Governmental activities and functions include those that require either the exercise of substantial discretion in applying U.S. Government authority, or value judgments when making decisions for the U.S. Government. Although the Contractor will be tasked to support assigned Government Program Security Manager(s) with respective security program requirements and to assist in providing centralized security services, the Government security manager has the lead and is the decision maker. The Contractor is only providing support in this capacity to perform administrative security functions under the direction of the activity security manager.
Activity security management shall ensure that Contractors who are involved in security administration and support duties are clearly identified in their capacities, roles, and functions, to ensure there is no possible confusion regarding which security personnel may exercise inherently Governmental authorities and which may not. The Contractor should contact the contracting officer for clarification in the event of any conflict.
Inherently Governmental Security Functions, relating to this section of the PWS, include, but are not limited to:
(a) Approving and issuing security policies and procedures
(b) Making original classification decisions, or rendering classification determinations regarding classified information that is improperly or incompletely marked. (Correcting improper markings when the appropriate classification is not in question is not considered rendering a classification determination.)
(c) Deciding to downgrade or declassify information. (Adhering to security markings on information or to guidance stated in an appropriate security classification or declassification guide is not considered a downgrading or declassification decision.)
(d) Deciding challenges to classification and any appeals
(e) Making foreign disclosure decisions
(f) Making public release decisions
(g) Committing to expenditure of U.S. Government funds
(h) Conducting investigations of, or determining fault in, security incidents involving U.S.
Government or other Contractor personnel. (Contractors shall also conduct preliminary inquiries to determine if a security incident is a violation or an infraction.)
(i) Giving final approval or executing documents for filing in litigation if documents assert an official position of the DoD, any DoD Component, or any other Federal agency
3.1.1.2 The Contractor shall obtain and maintain a facility clearance at the classification level of Top Secret prior to performing any classified work on the contract.
3.1.1.3 The Contractor shall designate a full time Facility Security Officer (FSO) with independent authority to manage and enforce all aspects of the Industrial Security program requirements for the company and all personnel within their managed areas.
FSO Requirements are:
(a) Security training through the Defense Security Service (DSS)-FSO Program Management for Possessing Facilities Curriculum (IS030.CU) (Approximately 17 Courses) shall be obtained prior to contract start date. Additional courses or curriculum may be needed to obtain applicable certifications.
(b) DSS Professional Certifications must be obtained through Security Professional Education Development Program (SPeD) within 1 year of contract start date and maintain recertification every two years.
For more information on training and SPēD Certification: www.dss.mil, www.cdse.edu/documents/sped/SPeD_Candidate_Handbook_4-1-14.pdf. The FSO Tool Kit is available at: http://www.cdse.edu/toolkits/fsos/new-fso.html.
or
(c) Acquire ASIS International Professional Certifications prior to contract start date:
For more information on training and ASIS International Certification:
https://www.asisonline.org/Certification/Board-certifications/Pages/default.aspx.
3.1.1.3.1 The FSO and support staff must be trained IAW chapter 3 of The NISPOM, for a possessing facility, and cleared commensurate with and concurrent with the issuance of the Facility Clearance Level IAW DoD 5220.22-M, Section 2, 1-201.
3.1.1.3.2 The Contractor shall ensure the FSO is physically located at Arnold AFB in order to monitor and facilitate all security requirements.
Work schedules for security support are non-standard and dependent upon test schedules, inspections schedules, and emergency situations. The core operational hours of the security personnel are from 0730-1630 hours, Monday through Friday, not including opening or closing times, which may extend one or more hour(s) before or after the core hours for security support, including any visitor control or required customer assistance.
3.1.1.3.3 The Contractor shall ensure all subcontractors enter into a Visitor Group Security Agreement (VGSA) with the AEDC Commander, as determined by the SSA IAW AFI16- 1406. The VGSA must be signed by required parties and must address all security requirements before any classified work begins.
The Agreement will outline responsibilities in the following areas: Contractor security supervision; Standard Practice Procedures (SPP); access, accountability, storage, and transmission of classified material; marking requirements; security education; personnel security clearances; reports; security checks; security guidance; emergency protection; protection of Government resources; DD Forms 254; periodic security reviews; and other responsibilities, as required.
3.1.1.3.4 The Contractor shall manage a self-inspection program and is responsible to perform semi-annual self-inspections. The Contractor will provide answers and source documentation in the COR provided communicator(s) within the Management Internal Control Toolset (MICT).
The Contractor shall ensure accurate, reliable, and critical assessments are performed. The Government COR will validate Contractor responses and source documentation within MICT.
Industrial Security has one (1) checklist with approximately 90 total questions annually.
3.1.1.3.4.1 The Contractor shall provide the Government with written corrective action plans for all identified deficiencies to determine primary and contributing root causes within 30 days of deficiency discovery. If the first response does not close all deficiencies, the Contractor will provide updates every 30 days thereafter until all deficiencies are resolved or closed.
3.1.1.4 The Contractor shall provide SAP security management support for Arnold AFB and AEDC Moffett Field. Under the direction of the GSSO, the Contractor shall assist with management, administration, and sustainment of all aspects of a SAP security program compliant with all applicable DoD and AF requirements.
The Contractor shall assist the GSSO in providing SAP security management for test security, physical security, personnel security, information security, operations security (OPSEC), and SAP security education and training.
Deliverables
OT-2018-XXXXX SAP Accredited Area Standard Operating Procedure
OT-2018-XXXXX SAP Accreditation Package
OT-2018-XXXXX SAP Test Security Plan
3.1.1.4.1 Under the direction of the GSSO, the Contractor shall establish, maintain, and manage SAP Facilities as required to support mission requirements in compliance with DoDM 5205.07, Volumes 1-4 and the JSIG and Program Security Officer (PSO) guidance.
Access shall be limited to authorized persons who have an appropriate security clearance, need-to-know, and documented formal access to the information within the area.
3.1.1.4.2 The Contractor shall maintain a SAP billet plan for each supported program and ensure initial and annual Government approval of each plan.
3.1.1.4.3 The Contractor shall identify, obtain, and maintain U.S. Postal Service procedures approved by the PSO.
3.1.1.4.4 The Contractor shall appoint a full-time Program Security Representative (PSR) cleared at least equal to the highest level of classified information for which they require access and possess access to all SAPs assigned to the facility(s) for which he/she is responsible. The PSR shall have the position, responsibility, and authority as directed by the GSSO to effectively manage and enforce all SAP security requirements based upon guidance provided by the PSO.
The Contractor shall ensure the PSR, or an appointed alternate, is physically located at Arnold AFB and AEDC Moffett Field in order to monitor and facilitate all SAP security requirements.
Work schedules for SAP security support are non-standard and dependent upon test schedules, inspections schedules, and emergency situations. The core operational hours of the security personnel are from 0730-1630 hours, Monday through Friday, not including opening or closing times, which may extend one or more hour(s) before or after the core hours for security support including any visitor control or required customer assistance.
3.1.1.4.5 The Contractor shall provide Top Secret accountability for all Top Secret SAP information utilizing a PSO approved document control accountability system.
3.1.1.4.6 The Contractor shall appoint a full-time Information System Security Manager, Information System Security Officer(s), and sufficient System Administrator(s) cleared at least equal to the highest level of classified information for which they require access and possess access to all SAPs assigned to the facility(s) for which they are assigned.
The Contractor shall ensure the ISSM, ISSO and System Administrators are physically located at Arnold AFB and AEDC Moffett Field.
3.1.1.4.7 The Contractor shall ensure compliance with separation of duties as identified in JSIG Section 3.1.5.
3.1.1.4.8 The Contractor shall ensure that SAP Information Systems are operated, maintained, and disposed of IAW SAP security policies.
3.1.1.4.9 The Contractor shall develop and maintain a formal information systems security program and implement all information systems security policy, establish and maintain accreditation documentation and procedures for all SAP systems, ensure the development and accuracy of accreditation documentation, and recommend action to the approval authority.
3.1.1.4.10 The Contractor shall attend and participate in working groups, configuration management meetings, and planning meetings as required to represent SAP IA interests and ensure that administrative, analysis, and ID&C systems remain compliant with SAP security policies.
3.1.1.4.11 The Information System Security Manager shall ensure that Information System Security Engineer requirements are effectively integrated into information systems through purposeful security architecting, design, development, and configuration through coordination with the responsible Government organization / individual providing Information System Security Engineering services to SAP.
3.1.1.4.12 The Contractor shall use the Joint Access Database Environment, or any successor, for personnel security management functions for all AF SAPs IAW the AFADs Policy Directive dated 22 Jan 2008.
3.1.1.4.13 The Contractor shall provide IA support for test requirements, configuration management, lifecycle sustainment, budgeting, system accreditation, and day-to-day system administration including hardware and software requisition, installation, and maintenance as required for all SAP requirements.
3.1.1.4.13.1 The Contractor shall perform IA support IAW DoDM 5205.07, Volumes 1-4, and the JSIG, 9 October 2013, DoD Joint SAP Implementation Guide (DJSIG, 9 Oct 2013).
3.1.1.4.13.2 The Contractor shall ensure qualified and experienced IA personnel meeting DoD 8570 certification requirements are available to meet the day-to-day AEDC SAP system administration requirements to include after-duty hours as required.
3.1.1.4.14 The Contractor shall ensure all systems required for SAP support obtain Authority to Operate (ATO) to meet test requirements to include:
• Providing IA artifacts and maintaining updated Certification and Accreditation packages for SAP Information Systems
• Maintaining a continuous monitoring program to ensure the state of the systems’ environments do not change from the accredited configurations
Deliverable
OT-2018-XXXXX SCI/SAP Certification and Accreditation package
3.1.1.4.15 The Contractor shall submit Program Access Requests for SAP to the approval authority within five (5) working days after receiving Government approval of the access requirement. The SAP Nomination Process shall be followed for all SAP nominations.
3.1.1.4.16 The Contractor shall prepare Standard Operating Procedures (SOP) necessary for the implementation of SAP requirements. SOPs shall be developed and coordinated in compliance with DoDM 5205.07, Volumes 1-4, and the JSIG.
Deliverable
OT-2018-XXXXX SCI/SAP Accredited Area Standard Operating Procedure
3.1.1.5 The Contractor shall provide security support for all phases of unclassified, classified, and commercial testing and related test activities.
The Contractor shall establish and implement a security program compliant with DoD, service, and local directives and make recommendations for improvements to security test procedures;
integrate cost effective and threat based security processes, plans, and procedures. Test phases include planning, design, fabrication, installation, execution, removal, reporting, and analysis.
The protection/security of test articles or systems and data is required.
3.1.1.5.1 The Contractor shall develop, coordinate, document and implement specific security requirements for all test programs.
3.1.1.5.2 The Contractor shall develop a Test Security Plan for each test and related activity, as requested by the Government.
The Contractor should anticipate having to develop approximately 125 Test Security Plans annually. Each Test Security Plan will be reviewed, revised as necessary to remain compliant with current security policy, and coordinated for Government approval. Ensure the integration of US export and technology control laws, DoD/Agency policy and instructions and other applicable guidance into test security plans. Test Security Plans developed in support of SAP efforts must be approved by the PSO, the customer security representative, and the Government.
Test Security Plans for Sensitive Compartmented Information (SCI) efforts must be approved by the Government Project Manager and the AEDC Special Security Office.
The Test Security Plan, including physical security boundaries and facility-specific procedures, shall be briefed to all personnel supporting SAP and/or SCI tests. Training accomplishment shall be documented and maintained IAW Records Distribution Schedules located in the AF Records Information Management Systems (AFRIMS) and applicable AFIs.
3.1.1.5.3 The Contractor shall retain a copy of all program Security Classification Guides and verify they are current IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 1-4, AFI 16-1404, AFI 16-1406, and supplements.
3.1.1.5.4 The Contractor shall provide analytical, technical, and administrative security support services to Information Protection, Industrial Security, and SAP Security programs managed by the Government.
Technical and administrative support from qualified security personnel is required to ensure core programs are successfully executed IAW applicable DoD and AFIs. Support will be provided "on-site” to the Government at Arnold AFB and includes security reviews, evaluations, initial surveys, and assessments. Programs include but are not limited to: Industrial Security, Personnel Security, Information Security, OPSEC, Test Security, and Physical Security for the protection of controlled information.
The Contractor should anticipate supporting 5-10 security reviews, evaluations, initial surveys, and assessments annually; however, this may fluctuate depending upon mission needs.
3.1.1.5.5 The Contractor shall assist the Government to develop security requirements for contractual commitments IAW DoD 5220.22-M, AFI 16-1406, and supplements.
Examples include coordination of the DD FM 254, DoD Contract Security Classification Specification, VGSAs, and Security Clauses.
3.1.2 OPSEC / Foreign Government Protection
3.1.2.1 The Contractor shall assist the Government to develop, coordinate, and execute OPSEC program requirements Foreign Government Protection requirements for Arnold AFB and AEDC Moffett Field.
3.1.2.2 The Contractor shall develop an OPSEC program plan to address how the Contractor will protect critical and sensitive contracted information IAW AFI 10-701 and Arnold AFB OPSEC Plan 10-701.
Upon acceptance by the Government, the Contractor shall implement the OPSEC program plan.
Deliverable
DI-MGMT-80934C OPSEC Program Plan
3.1.2.3 The Contractor shall include a Foreign National Visitor Control Plan (FNVCP), or additional OPSEC requirements as an annex to the test plan when determined to be necessary or as required. Coordinate the FNVCP and OPSEC requirements with the Government.
Test Security Plans will be used by the test team and identify all security requirements related to specific test efforts. In order to appropriately access requirements, the Contractor has to gather information from various sources (i.e., pre-test planning meetings, DD FM 254s, security classification guides, program/project managers, customers, etc.) in order to develop an applicable Test Security Plan specific to the program or project. The Contractor should anticipate having to develop approximately 125 Test Security Plans annually. In addition, the FSS Contractor is required to meet all OPSEC and Foreign Government protection requirements at AEDC Moffett Field.
Test Security Plans that require additional security requirements or protection measures above the established baseline or NISPOM must be reviewed and approved by the Government.
OT-2018-XXXXX Test Security Plan
3.1.2.4 The Contractor shall conduct OPSEC Foreign National Vulnerability Assessments and Audits for visiting foreign guests and/or customers IAW DoD 5220.22-M, AFI 16-1406, AFI 10-701, and supplements.
3.1.2.5 The Contractor shall appoint an OPSEC trained person as a Point of Contact (POC) with overall OPSEC responsibilities to maintain awareness of foreign intelligence collection capabilities, limitations, methods, and practices.
The OPSEC POC shall at a minimum successfully complete the OPSEC Analysis and Program Management Course (OPSE-2500): The focus of this course is on the basic skill and knowledge needed to conduct an OPSEC risk analysis (apply the five steps) and to implement an OPSEC program. This course is intended for use by the DoD and other U.S. Government personnel and Contractors within NISP.
For course registration and information refer to: http://www.cdse.edu/catalog/classroom/OPSE- 2500.html and https://www.iad.gov/ioss/
3.1.2.6 The Contractor shall assist the Government program manager in the development and implementation of the Commander’s OPSEC policy and Critical Information List IAW AFI 10-701 and supplements.
3.1.2.7 The Contractor shall conduct OPSEC training IAW AFI 10-701.
The Contractor shall familiarize new employees for awareness and conduct refresher sessions needed in the areas of OPSEC and Critical Information.
3.1.2.8 The Contractor shall integrate and include OPSEC into all acquisition programs and Contractor support documents IAW AFI 10-701.
3.1.2.8 The Contractor shall coordinate with the Government to resolve/mitigate Web Risk Assessment, Telecommunications Monitoring Assessment Program, Vulnerability Assessment, and other OPSEC assessment findings as required IAW AFI 10-701.
3.1.2.10 The Contractor shall assist the Government to conduct Staff Assistance Visits with the Government as required or requested IAW AFI 10-701.
The Contractor should anticipate supporting 5-10 Staff Assistance Visits annually; however this may fluctuate depending upon mission needs.
3.1.2.11 The Contractor shall conduct and document OPSEC self-assessments and implement required changes.
3.1.2.12 The Contractor shall integrate OPSEC into all organization planning, operational processes, acquisition programs, and Contractor support documents.
Recognizing that sub-Contractors vary in size, resources, and length of subcontract, OPSEC programs implemented for subcontractors should be designed to afford at least a minimum level of OPSEC protection and understanding for all subcontracts with increasing levels of OPSEC protection and understanding for more sensitive subcontracts.
3.1.2.13 The Contractor shall comply with the OPSEC measures imposed by any program supported.
Organizations and personnel supporting customers may have OPSEC requirements associated with their activities and support. The following standard expectations are included in all work:
(a) Specific event-oriented activities are supported when directed by the supported program, or comply with the program's OPSEC Plan/Annex.
(b) OPSEC Awareness Education and Duty-Related Training as deemed necessary by the Government or program supported are provided to personnel assigned
(c) OPSEC protective measures (countermeasures) are applied as directed by Government or program sponsors.
3.1.3 Security Administrative Support
3.1.3.1 The Contractor shall provide security support sufficient to ensure full compliance with DoD, service, and local directives at Arnold AFB and AEDC Moffett Field.
3.1.3.2 The Contractor shall request security clearances for personnel when the Contractor determines that access is essential in the performance of tasks or services related to the fulfillment of the contract.
Requests for Contractor security clearances shall be kept to an absolute minimum necessary to perform contract requirements. The Contractor shall ensure that sufficient personnel have the appropriate security clearance to accomplish all tasks specified in this PWS prior to the performance start date.
3.1.3.3 The Contractor shall review Joint Personnel Adjudication System (JPAS) or the program replacing JPAS daily to obtain relevant security clearance and investigation information pertaining to present and future AEDC personnel and other personnel in whom the AEDC has a security interest.
3.1.3.4 The Contractor shall process Homeland Security Policy Directive 12 and other “Position of Trust” investigative requests for AEDC Government Contractor personnel through the AEDC Government Personnel Security Program Manager IAW AFI 31-501 or
AFI 16-1405.
The Contractor should anticipate processing ~125 investigative requests annually. Investigative requests and supporting documentation (Standard Form 85) are required for any new AEDC
Contractor personnel without a U.S. security clearance or other required background investigation for base/facility access and/or access to unclassified U.S. Government computers.
3.1.3.5 The Contractor shall provide electronic fingerprint services, required for official Government business, to all Government Contractors at AEDC requiring a background investigation.
The Contractor should anticipate processing ~300 fingerprints annually. Fingerprinting equipment will be provided as Government Furnished Equipment (GFE).
3.1.3.6 The Contractor shall provide a copy of all adverse information reports submitted to DSS pursuant to NISPOM 1-300, 301, 302, 303 and 304 to the Installation Commander via the SSA. Incident reports shall also be entered in the JPAS or the program replacing JPAS. Reports required to be submitted to the Federal Bureau of Investigation, IAW NISPOM 1-301, shall also be reported to the local detachment of The AF Office of Special Investigations. The Contractor shall report all adverse information concerning SAP briefed personnel to the PSO IAW DoDM 5205.07, Volumes 1-4 and the JSIG. Report all adverse information concerning SCI indoctrinated personnel to the AEDC Special Security Officer.
3.1.3.7 The Contractor shall use the JPAS or the program replacing JPAS for transmitting/receiving visit requests and to properly identify the security clearance level of visitors (to include test customers) IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 1-4, AFI 16- 1404, AFI 16-1406, and supplements.
3.1.3.8 The Contractor shall implement an Insider Threat program IAW guidance and standards developed by the Insider Threat Task Force established in section 6 of EO 13587 DoD Instruction (DoDI) 5240.26 and AFI 16-1402. The Program shall be designed to identify employees that have access within their closed and restricted areas, displaying potential espionage indicators. Adverse behavior which might indicate a potential threat to national security shall be reported as required IAW DoD 5220.22-M, AFI 31-501, and AFI 16-1406, and supplements.
For the purposes of the NISPOM, insider threat refers to the threat of an insider using his or her authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the U.S. through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of Government, company, contract or program information, resources or capabilities.
3.1.3.8.1 The Contractor shall establish and foster Counterintelligence (CI) focused culture, for all personnel having access within their closed and restricted areas in order to detect, deter, and expeditiously report suspicious activities.
OT-2018-XXXXX Test Security Plan
3.1.3.8.2 The Contractor shall control media and information IAW the respective classification level and security classification guides.
3.1.3.8.3 The Contractor shall brief all appropriate test support personnel on the requirements of the Test Security Plan or Program Protection Plan.
3.1.3.8.4 The Contractor shall ensure that each Government, Contractor, or subcontractor employee completes Program Protection Awareness Training, as required in the respective Program Protection Plan.
Critical Program Information (CPI) Training is specific to the protection of sensitive and CPI. If CPI exists, it will be identified in the Program Protection Plan provided by the Government Program Office. The Government will provide the basic training plan to be tailored for each facility handling/storing/processing identified CPI.
3.1.3.8.5 The Contractor shall schedule vault and safe inspections and periodic maintenance as required IAW AFI 16-1404 and DoD 5220.22-M.
3.1.3.8.6 The Contractor shall establish liaison with local CI and law enforcement organizations to determine the status of the local threat to the facility, personnel, and supported programs. Inform the Government of threats or any other information required IAW DoD 5220.22-M, AFI 10-701, AFI 16-1404, AFI 31-501, AFI 16-1405, AFI 16-1406, and supplements.
3.1.3.8.7 The Contractor shall support Government security managers with conducting and documenting specialized security initiatives, training and briefings IAW DoD 5220.22-M, AFI 10-701, AFI 16-1404, AFI 31-501, AFI 16-1405, AFI 16-1406, and supplements.
3.1.3.8.8 The Contractor shall operate and maintain a classified and controlled material destruction capability for Arnold AFB. The Contractor shall ensure classified destruction capabilities meet or exceed National Security Agency (NSA) classified destruction standards.
The Contractor should anticipate providing destruction capabilities for all types of media, e.g.
paper, CD/DVDs, hard drives, film, etc.
3.1.3.8.9 The Contractor shall provide bulk destruction and disposal capability for all classified and controlled unclassified material generated at Arnold AFB.
The Contractor should anticipate providing bulk destruction and disposal capability for approximately 3 to 5 tons of classified material and approximately 25 tons of CUI annually.
3.1.3.8.10 The Contractor shall control, track and issue all accountable security materials such as classified storage equipment, containers, vaults, and combination locks used in the AEDC Information Protection/Industrial Security Programs IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 1-4, AFI 16-1404, 16-1406, and supplements.
3.1.3.8.11 The Contractor shall ensure required security briefings are conducted to visitors and escort officials accessing all closed and restricted areas.
3.1.3.8.12 The Contractor shall provide an adequate amount of NSA approved shredders capable of destroying paper, other media and hard drives. NSA approved CD/DVD and paper shredders shall be strategically positioned throughout Arnold AFB testing environments to support day-to-day operational requirements IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 4, AFI 16-1406, AFI 10-701, and supplements. The Contractor shall train all designated personnel on the use of the FSS provided equipment.
The Contractor is required to provide NSA approved equipment (NSA/CSS EPL 0202M Annex A to NSA/CSS 02 02, NSA/CSS Evaluated Products List) for the destruction of classified material.
3.1.3.8.13 The Contractor shall ensure all Controlled Unclassified Information (CUI), including all data storage devices/media, at Arnold AFB is properly destroyed IAW DoD 5200.01-M, Vol. 4.
CUI may be destroyed by any of the means approved for the destruction of classified information or by any other means that would make it difficult to recognize or reconstruct the information.
Strip shredding is not permitted. Recycle bins are not approved for controlled information.
The Contractor should anticipate destroying or disposing of ~60,000 lbs annually; however this fluctuates depending upon mission needs.
3.1.3.8.14 The Contractor shall provide overnight transitory storage capability located in the Arnold AFB Base Defense Operations Center (BDOC) and AEDC Moffett Field approved for safeguarding classified material, up to the secret level, IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 3, AFI 16-1404, and supplements.
Overnight transitory storage is for use by AEDC visitors and transitory personnel. The Contractor shall advertise this capability at key visitor reception points.
3.1.3.8.15 The Contractor shall provide security-related technical assistance to the Government and Contractor personnel for briefings and conferences.
The Contractor should anticipate providing security-related technical assistance to Government and Contractor personnel for 150 briefings and conferences annually.
3.1.3.8.16 The Contractor shall participate in scheduled and ad-hoc security working groups IAW DoD 5220.22-M, AFI 10-701, AFI 16-1404, AFI 31-501, AFI 16-1405, AFI 16- 1406, and supplements.
For example, Installation Security Advisory Group, OPSEC Working Groups, Security Working Groups, or other security related working groups or Integrated Product Teams.
The Contractor should anticipate participating in 1-5 scheduled and ad-hoc 1-3 hour long security working groups annually; however this may fluctuate depending upon mission needs.
3.1.4 Controlled Spaces / Incident Management
The Contractor shall manage all controlled spaces and provide Security Incident management support sufficient to ensure full compliance with DoD, service, and local directives at Arnold AFB and AEDC Moffett Field.
3.1.4.1 The Contractor shall conduct entry and exit inspections in order to deter and detect unauthorized introduction or removal of classified material from closed and restricted areas IAW DoD 5220.22-M and DoD 5200.01- M, Vol. 1-4.
Ensure SOPs and/or OIs include Entry/Exit Control procedures for use by owner/users or area custodians of controlled areas established for classified operations include procedures for entry and exit checks.
3.1.4.2 The Contractor shall prepare written SPP necessary for the implementation of the NISPOM IAW DoD 5220.22-M, NISPOM and AFI 31-601, and supplements. SPPs must be submitted and approved for use by the Government (SSA) prior to performance start date of this contract.
If the company elects to change, modify, develop an addendum, annex, supplement, to their SPP, or add an internal OI, for any on-base security operations, it will require Government written approval of those security procedures.
Deliverable
OT-2018-XXXXX Standard Practice Procedures
3.1.4.3 The Contractor shall manage security requirements for all physical space required to support test operations and activities.
3.1.4.4 The Contractor shall establish, maintain, and manage classified space (Closed & Restricted Areas) IAW DoD 5220.22M, Chapter 5 Section 3, AFI 16-1406 and supplements.
Access shall be limited to authorized persons who have an appropriate security clearance and a need-to-know for the classified material/information within the area. List of Closed and Restricted areas can be found in Appendix A.
3.1.4.5 The Contractor shall manage space during commercial tests IAW established baseline security requirements provided by the Government, test customer, or as identified in the respective Test Security Plan.
Deliverable
OT-2018-XXXXX Standard Operating Procedures for Test Areas
3.1.4.6 The Contractor shall secure and issue program or project access badges and brief holders on requirements and responsibilities when required.
These badges are not to be confused with credentials issued by Visitor Control functions.
Comply with DoD 5220.22-M, AFI 16-1406, AFI 31-101, and supplements.
3.1.4.7 The Contractor shall train appointed personnel to manage and enforce all security requirements within their respective NISPOM closed and restricted areas IAW DoD 5220.22-M, DoD 5200.01-M Vol. 1-4, AFI 16-1406, and supplements.
3.1.4.8 The Contractor shall conduct and document initial indoctrination and annual training of all personnel that require access to the closed and restricted areas.
3.1.4.9 The Contractor shall establish, manage, and maintain internal test security/OIs, guard instructions, phone lists, Entry Authorization Lists, and other required controls for all classified, to include information protection requirements for North Atlantic Treaty Organization (NATO) and Critical Nuclear Weapons Design Information categories, and unclassified test programs IAW DoD 5220.22-M, AFI 16-1404 and AFI 16-1406, and supplements.
The Contractor will be required to manage AEDC’s NATO mission and serve as the NATO Control Point IAW DoDM 5200.01, Vol 1, Enc 2, AFI 16-1404 and the NATO Affairs (USSAN) Instructions. Assist in the preparation of security instructions and plans for other appropriate functional areas with security concerns, as required or requested. Ensure each area is following guidance contained in applicable NISPOM, AF, program, and other cognizant security agency directives.
3.1.4.10 The Contractor shall test and verify alarms and other physical security equipment used in closed and restricted areas IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 1-4, AFI 31- 101, AFI 16-1404, AFI 16-1406, and supplements.
3.1.4.11 The Contractor shall establish, maintain, and follow procedures to verify and log all visitors and media that enter or are brought into a closed or restricted area IAW DoD 5220.22-M, AFI 16-1406, and supplements.
3.1.4.12 The Contractor shall ensure individuals requiring temporary access to the secure facility/area that require escort are escorted by the respective owner/users of the area IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 1-4, AFI 16-1406, and supplements.
3.1.4.13 The Contractor shall ensure all media (e.g. computer hard drives, hardware) within all closed and restricted areas are marked, stored and destroyed IAW the DoD 5220.22- M, DoD 5200.01-M, Vol. 1-4, AFI 16-1406, and supplements.
3.1.4.14 The Contractor shall ensure proper packaging, pick-up, procedures, and transmittal of classified material within their closed and restricted areas IAW DoD 5220.22-M, DoD 5200.01-M, Vol. 1-4, AFI 16-1406, and supplements.
3.1.4.15 The Contractor shall conduct and support security investigations, preliminary inquiries, and other actions required for resolution of security incidents IAW DoD 5220.22- M, DoDM 5205.07, Volumes 1-4 and the JSIG, AFI 16-1406, and supplements.
Contractors will conduct preliminary inquiries to determine if a security incident is a violation or an infraction within their controlled areas. If Government or other Contractors are involved, the Contractor will contact the SSA or SSO to ensure other Contractors and Government personnel cooperate with the investigation. The Contractor shall assist the Government in gathering facts, providing recommendations and ensuring immediate mitigation actions were taken to protect classified and / or CUI. Inherently Governmental Security Functions and decisions will be made by the Government ONLY. Refer to examples noted in PWS 3.1.1.1.
3.1.5 Mandatory and Guidance Documents
All references included are current as of the date on the cover sheet of this PWS. This list is subject to change based on operational/mission requirements, as well as revisions to the listed documents. The Contractor shall comply with future revisions issued for the documents listed.
Document
Title
Mandatory (M) or
Guidance (G)
E.O. 12829 National Industrial Security Program M
E.O. 13526 Classified National Security Information M
E.O. 13556 Controlled Unclassified Information M
E.O. 13467 Reforming Process relating to Suitability for Government Employment, Fitness for Contractor Employees, and Eligibility for Access to Classified National security Information
M
E.O. 13587 Structural Reforms To Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information
M
ICD 503
Intelligence Community Information Systems Security Risk Management, Certification, and Accreditation
M
ICD 700 Protection of National Intelligence M
ICD 701 Security Policy Directive for Unauthorized Disclosures of Classified Information M
ICD 702 Technical Surveillance Countermeasures M
ICD 704
Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information
M
ICD 704.1
Personnel Security Investigation Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Assess Program Information
M
ICD 704.2
Personnel Security Adjudicative Guidelines for Determining Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information
M
ICD 704.3
Denial and Revocation of Access to Sensitive Compartmented Information, Other Controlled Access Program Information, and Appeals Processes
M
ICD 704.4 Reciprocity of Personnel Security Clearance and Access Determinations M
ICD 705 Sensitive Compartmented Information Facilities M
ICS 705-1 Physical and Technical Security Standards for Sensitive Compartmented Information Facilities
M
ICS 705-2 Standards for the Accreditation and Reciprocal Use of Sensitive Compartmented Information M
ICD 705
Technical Specifications for Construction and
Management of Sensitive Compartmented Information Facilities, Version 1.2, 23 April 2012
ICD 710 Classification and Control Marking System M
CNSSI 5006
National Instruction for Approved Telephone Equipment (formerly the Telephone Security Guide (TSG) Standard 6)
M
CNSSAM
TEMPEST/1/13 (U) Red/black Installation Guidance M
JAFAN 6/0 Special Access Program Security Manual M
JAFAN 6/3 Protecting Special Access Program Information Within Information Systems
M
JAFAN 6/3 Implementation Guide G
JAFAN 6/9 Physical Security Standards for Special Access Program Facilities M
Joint Pub 3-
Joint Doctrine for Operations Security G
Joint Pub 3-54 Joint Doctrine for Operations Security G
JSIG Joint Security Implementation Guide (JSIG), 9 October 2013
DJSIG
Department of Defense Intelligence Information
System (DoDIIS) – Joint Security Implementation Guide (DJSIG), August 2011
Department of Defense Joint Special Access
Program (SAP) Implementation Guide (JSIG, 09 Oct 2013
DoDD
3000.09 Autonomy in Weapon Systems G
5000.01 The Defense Acquisition System G
DoDD 5100.55
United States Security Authority for North Atlantic Treaty Organization Affairs M
DoDD
5200.02 DoD Personnel Security Program M
DoDD 5205.07
Special Access Program (SAP) Policy M
DoDD 5230.09
Clearance of DoD Information for Public Release
5230.11
Disclosure of Classified Military Information to Foreign Governments and International Organizations
M
DoDD 5230.25
Withholding of Unclassified Technical Data from Public Disclosure M
DoDD O- 5240.02
Counter…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.