Exhibit_B_DIDs.pdf

PDF 829 KB Posted

Attached to
Facility Support Services Federal contract opportunity
Solicitation number
FA9101-18-R-1000
Issued by
Department of the Air Force Materiel Command Test Center

About this file

Exhibit B, Data Item Descriptions

View the file

Other files for this federal contract opportunity

Other files attached to Facility Support Services, newest first.
File Type Posted
Section_B_Pages_Amend_0001.pdf PDF
QandA_No._9.pdf PDF
Exhibit_A_CDRLs.pdf PDF
Attachment_9,_Section_M_FRFP.pdf PDF
Attachment_L-6,_Relevancy_Matrix.xlsx XLSX spreadsheet
Attachment_7_USAF_Owned_Registered_Vehicles.pdf PDF
Attachment_L-3,_PPQ_Cover_Letter.pdf PDF
Attachment_5_FES-IMS_Property_Listing.pdf PDF
Attachment_L-4_Past_Performance_Client_Authorization_Letter.pdf PDF
FSS_II_Cover_Letter_to_RFP.pdf PDF
Exhibit_E,_ASO_and_URS_and_AEMTC_CBA.pdf PDF
Attachment_L-8,_Cost_Model_FRFP.xlsx XLSX spreadsheet
Attachment_L-2,_Past_and_Present_Performance_Questionnaire_FSSII.pdf PDF
PPI_Tool_FSS_II.accdb MDB file
FSS_II_Notional_Acquisition_Schedule_31Oct18.pdf PDF
QandA_No._5.pdf PDF
Industry_Day_No._3_Registration_Form.docx DOCX document
Industry_Day_No._3_Announcement.pdf PDF
Attachment_2,_DD254.pdf PDF
Attachment_7,_USAF_Owned_Registered_Vehicles.pdf PDF
Attachment_3,_SCA_and_CBA_WDs.pdf PDF
Attachment_L-6,_Relevancy_Matrix.xlsx XLSX spreadsheet
Attachment_L-5,_Subcontractor_Consent_Letter.pdf PDF
Attachment_L-8,_Cost_Model.xlsx XLSX spreadsheet
Attachment_L-3,_PPQ_Cover_Letter.pdf PDF
FSS_II_dRFP_SF33.pdf PDF
Attachment_L-1,_PPI_Tool.pdf PDF
Exhibit_C,_ASO_and_AEMTC_CBA.pdf PDF
Attachment_1_PWS_17_Aug_18.pdf PDF
Attachment_6,_GFP.pdf PDF
Attachment_8,_Section_L.pdf PDF
PPI_Tool_FSS_II.accdb MDB file
Attachment_L-2,_Past_and_Present_Performance_Questionnaire_FSSII.pdf PDF
Exhibit_A_Contract_Data_Requirements_List.pdf PDF
Exhibit_D,_ASO_and_PSI_and_IGUA_CBA.pdf PDF
Exhibit_E,_ASO_and_URS_and_AEMTC_CBA.pdf PDF
FSS_II_dRFP_Cover_Letter.pdf PDF
Advisory_MultiStep_Process_OCI_Mitigation_Plans.pdf PDF
FSS_II_Draft_Exhibit_A_Contract_Data_Requirements_List.pdf PDF
Questions_and_Answers_No._2.pdf PDF
Request_for_Information_No._1.pdf PDF
Attachment_8_(CLARIFICATION)_-_Industry_Day_No._2_Registration_Form.docx DOCX document
Attachment_8_-_Industry_Day_No._2_Registration_Form.docx DOCX document
Attachment_7_-_Industry_Day_No._2_Agenda.pdf PDF
Attachment_5__Draft_PWS_Announcement.pdf PDF
Attachment_4_-_Industry_Day_No.2_Announcement.pdf PDF
Sources_Sought_QandA_No._1.pdf PDF
Attachment_1_(Update)_-_Contractor_Capability_Survey.pdf PDF
Attachment_3_-_Industry_Day_No._1_Agenda.pdf PDF
Attachment_1_-_Contractor_Capability_Survey.pdf PDF
Show all 50

Facility Support Services has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA9101-18-R-1000

Exhibit B

Data Item Descriptions

9 November 2018

DATA ITEM DESCRIPTION

Title: JOINT SPECIAL ACCESS PROGRAM IMPLEMENTATION GUIDE (JSIG) SYSTEM

AUTHORIZATION PACKAGE (SAP)

Number: DI-ADMN-81969 Approved Date: 20140807 AMSC Number: F9488 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: 20 (AFRL/RYS) Applicable Forms: N/A Use/Relationship: The JSIG SAP is used to identify, control, and authorize a contractor’s proposed stand-alone computer systems and/or networks created and used during the performance of this contract. The contract Information System Security Officer (ISSO) or Information System Security Manager (ISSM) must submit the SAP documentation for a proposed system or network to the Authorizing Official (AO), Delegated Authorizing Official (DAO), or the Program Security Officer (PSO). The AO, DAO, or the PSO must provide written approval of any new information system or network before processing can begin.

a. The SAP describes the methods to: (1) identify systems, security responsibilities and requirements; (2) define overall security standard practice guidance and procedures; (3) identify potential problem areas and determine solutions; and (4) develop security awareness inputs into the overall system security process.

b. This Data Item Description (DID) defines the data required to obtain information systems authorization in accordance with the JSIG. A copy of the JSIG can be obtained from the government program office.

c. This DID contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.

Requirements:

1. Reference documents: The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as cited in the ASSIST at the time of the solicitation or contract.

a. Department of Defense (DoD) JSIG

b. DoD JSIG Template Handbook.

c. Government Program Office Guidance.

(Copies of these documents are available from the Government Agency awarding the contract.)

2. Format: The JSIG SAP Documentation shall be presented in Microsoft Word formats outlined by the DoD JSIG, DoD JSIG Template Handbook and the Government Information Assurance Officer (IAO). The initially used format arrangement shall be used for all subsequent submissions.

3. Content: A JSIG system/network authorization package typically consists of:

a. Authorization Package Cover Letter.

DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited.

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T16:54Z

Check the source to verify that this is the current version before use.

DI-ADMN-81969

b. Authorization to Operate (ATO) Letter.

c. Security Assessment Report (SAR).

d. Risk Assessment Report (RAR).

e. System Security Plan (SSP).

f. Security Control Traceability Matrix (SCTM).

g. Plan of Action and Milestones (POA&M).

h. ISSO/ISSM Appointment Letter.

i. ISSO/ISSM 8570 Certification (per DoD 8570.01-M, Information Assurance Workforce Improvement Program).

(Copies of this document are available online at http://www.dtic.mil/whs/directives/index.html.)

j. General User’s Guide (GUG).

k. Privileged User’s Guide (PUG).

l. Software List.

m. Software Approval Forms for High-Risk.

n. Hardware List.

o. Any other supporting documentation required via above documentation (facility accreditation, etc.)

3.1. An SSP will be developed and maintained for each proposed stand-alone system or network.

3.2. If an approved Interagency Standing Operating Procedure (IASOP) exists for previously authorized systems/networks, and will apply to the proposed system/network, submit a copy of the IASOP in addition to the items a through o, above.

3.3. The SAP documentation will be revised when any modifications are made to any portion of the system, network, personnel, or documentation.

3.4. Classification of documentation will be applied in accordance with security classification guides or classification tables. “Distribution Statement F. Further dissemination only as directed by (inserting controlling DoD office) (date of determination) or higher DoD authority.”

applies to this package.

4. End of DI-ADMN-81969.

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T16:54Z

Title: Program Progress Report

Number: DI-MGMT-80555A Approval Date: 14 Nov 2006 AMSC Number: 7640 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: NS/DA02 Applicable Forms: N/A

Use/relationship: The Program Progress Report provides the Government with the means to evaluate and monitor the progress made by the contractor of tasks in accomplishing the goals established for the program.

This Data Item Description (DID) contains format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.

This DID is applicable when the monitoring for the progress of a program is required.

This DID supersede DI-MGMT-80555.

Requirements:

1. Reference documents. None.

2. Format. The Program Progress Report shall be in contractor’s format.

2.1 Title page. The title page shall contain the following:

2.1.1 Title. The title shall identify the subject of the report, program name, or task.

2.1.2 Name of contractor. The name of the contractor preparing the report.

2.1.3 Contract number. The procurement instrument identification number.

2.1.4 Key person. The individual assigned to the task or who produced the report.

2.1.5 Reporting period. The dates the reporting period begins and ends.

2.2 Paper size. The report shall be on 8 ½ x 11 inch or metric size A4 paper and typewritten of otherwise duplicated on nonfading ink.

Source: https://assist.dla.mil -- Downloaded: 2018-10-12T14:03Z

DI-MGMT-80555A

3. Contents. The report shall contain the following:

3.1 Work summary. A brief summary of work performed during the reporting period providing positive or negative comments.

3.2 Schedule. A statement as to whether task or program is on schedule and if not, efforts planned to meet schedule shall be explained.

3.3 Studies. Discussion of all studies conducted during the reporting period and the results.

3.4 Experimental work/test procedures. An explanation of experimental work accomplished, description of test procedures applied (cite applicable military specification, paragraph number and test parameters), results of test and conclusions determined.

3.5 Designs. A description and illustration of all designs produced, along with required changes made to a previous design and a brief statement of any problems encountered.

3.6 Test equipment. Description, nomenclature and serial number of all test equipment used on the project including appropriate schematic or block diagrams.

3.6.1 List the serial number of all equipment(s) subjected to the testing.

3.6.2 Provide a brief description of all special test equipment designed of constructed for use on the project including appropriate schematic of block diagrams.

3.7 Test performed. Identification and description of all test (s) performed (cite applicable military specification, paragraph number, and test parameters).

3.7.1 Provide control settings of the test sample.

3.7.2 Resolutions of measurement equipment and range of input signals.

3.8 Failures. A brief explanation of any failures associated with test and appropriate photographs, sketches, etc. to show failures, their causes or other unusual conditions.

3.9 Difficulties/problems. Describe any difficulties or problems encountered or which previously existed which could alter the progression of work along with recommendations of resolution.

3.10 Plan. Steps followed during execution of tasks.

DI-MGMT-80555A

3.11 Completion dates. Projected completion dates for each task.

3.12 Percentage. Percentage of task completed to date and percentage of allocated funds expended on tasks.

3.13 Additional information. Other information which may cause a significant change in the work schedule.

4. END OF DI-MGMT-80555A

Title: OPERATIONS SECURITY (OPSEC) PLAN

Number: DI-MGMT-80934C Approval Date: 20101213 AMSC Number: 9178 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: NS/I925 Applicable forms: N/A

Use/Relationship: The OPSEC Plan is used to identify and monitor a contractor’s OPSEC activities during the performance of a contract. It is intended to be a living document that will require periodic updates throughout the life of the contract. The OPSEC plan; (1) Describes the OPSEC environment to include identification of critical information, the OPSEC threat and vulnerabilities an adversary might exploit to acquire critical information, (2) Documents the OPSEC risk analysis, (3) Identifies proposed and actual OPSEC measures, (4) Defines and assigns specific OPSEC responsibilities and ties the OPSEC Plan to the contractor’s corporate OPSEC Program, and (5) Serves as a repository of the OPSEC history of the contract.

a. This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.

b. This DID is applicable only when the contracting activity determines that the sensitivity of the contracted effort warrants OPSEC protections.

c. The contractor’s implementation of the OPSEC Plan, approved by the contracting activity, is subject to joint audit and/or inspection by the Defense Security Service and the contracting activity.

d. This DID supersedes DI-MGMT 80934B.

Requirements:

1. Reference documents: The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices and revisions, shall be as specified in the contract.

a. “Applying OPSEC to U.S. Government Acquisitions and Contracts”. This document is available from the Interagency OPSEC Support Staff (IOSS) at the following web address:

www.ioss.gov.

b. Department of Defense Manual (DODM) 5205.02M, DOD Operations Security (OPSEC) Program Manual, dated November 3, 2008.

Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z

DI-MGMT-80934C

c. Department of Defense Contract Security Classification Specification (DD 254). This document is included as a part of all Request for Proposals (RFP) and Contracts involving classified data.

d. Contract Data Requirements List (CDRL). This document is included as a part of all RFP and contracts containing data deliverable requirements.

e. National Industrial Security Program Operating Manual (NISPOM) 5220.22M, dated February 28. 2006.

2. Format: The OPSEC Plans shall be submitted in contractor determined format and, at a minimum, consist of the following sections listed in the Content Section below.

3. Content:

3.1 COVER PAGE

The cover page for an OPSEC Plan shall clearly present, at a minimum, the following information:

1. Title of the Acquisition Program

2. Title of the Document (i.e. “Operations Security Plan”)

3. Reference to the government contract number

4. Date of latest revision

5. Name, signature and title of the preparer of the OPSEC Plan

6. Name, signature and title of the approver of the OPSEC Plan.

7. Reference for whom the document was prepared (Contracting activity)

8. Reference by whom the document was prepared (Corporation)

9. All appropriate distribution or classification statements

3.2 TABLE OF CONTENTS PAGE

The Table of Contents for an OPSEC Plan shall outline each section contained in the OPSEC Plan.

3.3 PREFACE PAGE

The purpose of the Preface is to provide a brief, unclassified, overview of the program and the need for OPSEC measures. The specific objectives of the contracted effort shall be introduced with reference to all strategic participants and partnerships required to make the program a success. The anticipated development of any innovative concepts or technologies shall also be introduced in the Preface.

The Preface shall reference all links between the OPSEC Plan and any corporate OPSEC Program(s). The Preface may conclude by referencing requirement documents such as the contract number, Contract Security Classification Specification (DD254), Contract Data

Requirements List (DD1423) and any other pertinent guidance provided by the contracting activity. It shall also provide an OPSEC point of contact, with contact information, for additional guidance or assistance such as the OPSEC program manager or contractor program manager.

3.4 OPSEC PLAN INTRODUCTION

3.4.1 Purpose and Scope: The purpose of the OPSEC Plan shall be effectively communicated in this section and include a description of the scope of the OPSEC Plan (unique physical locations, subcontractors, suppliers, period of performance, etc.).

3.4.2 Authorities: The requirement to protect critical information shall be documented within this section. Documenting the requirement can be achieved by referencing the Corporate OPSEC Program (Policy) and Plan, DODM 5205.-2M, specific contract documents including the DD254 for contracts involving classified data, or other contracting activity specific guidance.

3.4.3 OPSEC Plan Major Activity Timeline: This section shall include a list of all major OPSEC Plan activities such as quarterly OPSEC Working Group Meetings, Annual Assessments, scheduled OPSEC awareness training, Sub-contractor OPSEC Assessments and Surveys, Threat and Vulnerability Reviews, etc. This section shall also include scheduled OPSEC Plan reviews.

3.4.4 Responsibilities: The OPSEC Plan shall identify whom is responsible for the major activities described in the Plan. For example (not intended as an inclusive list):

The OPSEC Manager shall be identified by name and include a list of duties that may include:

1. Coordinate all OPSEC policy responsibilities/ procedures within the program.

2. Revise the Program OPSEC Plan as necessary.

3. Convene and coordinate the annual Program OPSEC Assessment.

4. Disseminate updated threat information to program personnel.

5. Assist in the review of contract requirements for OPSEC considerations.

6. Conduct OPSEC briefing(s) upon customer approval of the plan.

7. Principal advisor to the Contractor Program Manager on all OPSEC matters.

8. Develop/Disseminate Program Critical Information List (CIL).

9. Promote OPSEC awareness within the program.

The Contractor Program Manager shall be identified by name and include a list of duties that may include:

1. Responsible for the overall implementation of the program/contract.

2. Ensure proper OPSEC procedures are implemented by program personnel.

3. Ensure all subcontractors and suppliers supporting the program develop and implement procedures in compliance with the Program OPSEC Plan.

4. Remain cognizant of emerging OPSEC threats and vulnerabilities that may adversely impact upon the success of the program.

5. Actively participate in periodic Program OPSEC assessments.

6. Remain cognizant of any changes in critical information and communicate them to the Program OPSEC Manager.

7. Promote OPSEC awareness within the program.

A short description of the expectations and responsibilities of all program personnel (including subcontractors and suppliers) shall be provided and may typically include:

1. Remain compliant with all applicable OPSEC Plans.

2. Maintain an awareness of all applicable CIL.

3. Attend all OPSEC program briefings.

4. Timely reporting of any OPSEC concerns to the Contractor Program Manager and/or the Program OPSEC Manager.

5. Generation of OPSEC Plans (sub-contractors or suppliers only).

3.4.5 Organizational OPSEC Communications and Interfaces: A description as to how the OPSEC Plan will be communicated to all personnel supporting the program (hardcopy, via a webpage, briefings, etc.).

3.4.5.1 Internal: In this section the OPSEC Plan shall identify all anticipated OPSEC interfaces internal to the corporation such as the senior corporate leadership, corporate OPSEC Working Group, OPSEC coordinators, program personnel, etc.

3.4.5.2 External: In this section the OPSEC Plan shall identify all anticipated external points of contact such as the contracting activity, Defense Contract Management Agency (DCMA), The Defense Security Service (DSS), Federal Bureau of Investigation (FBI) and local law enforcement and their primary role within the OPSEC program (i.e. DCMA audits acquisition management practices, DSS provides security oversight, FBI and law enforcement may provide threat data). Subcontractor and supplier OPSEC points of contact shall be similarly identified.

3.4.6 Marking, Handling and Distribution of Documents: This section shall provide a description of marking, handling, storage, access and transmission authorizations and procedures for any critical information provided to, or generated by, the contractor.

Reference to the program classification guide, Freedom of Information Act and any additional guidance provided by the contracting activity may be cited as applicable.

3.5 THREAT

3.5.1 General Threat: This section shall identify and demonstrate an understanding of the overall threat to program critical information throughout the anticipated duration of the contract/program. For example, an information systems program might note the following:

DSS analysis of 2008 threat data shows, “Information systems, especially C4ISR related systems remained the primary sought-after technology for East Asia and Pacific Region countries. Direct requests (often via the Internet) and other suspicious Internet activity continued to be the preferred method of collection. Information systems are primary targets for Near East adversaries of the United States. Near East commercial entity activity indicates a growing collusion between commercial entities and government associated entities such as universities, public agencies and research and development centers. Adversaries using HUMINT and OSINT collection methods represent a significant threat to program critical information. i

The section shall conclude with a brief description of all identified intelligence collection methods that may be expected to be used by an adversary to acquire critical information.

Note: A general description of intelligence collection methods may be found in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov.

3.5.2 Program Detailed Threat: This section shall be similar to section 3.5.1 above referencing any known direct threats to acquisition specific elements of critical information within the program/contract. As complete a description of each threat as possible shall be provided while maintaining the overall plan classification at the unclassified level. Since detailed threat information may derive from classified sources, reference to source documents as provided by the government contracting activity or other reputable source is permitted.

3.5.3 Threat Analysis: Each threat identified in sections 3.5.1 and 3.5.2 shall be analyzed to determine the level of threat to the corresponding critical information. The results of this analysis shall be presented in this section. A description of the specific threat analysis method used by the contractor to quantify each threat shall be included in this section.

Note: For additional guidance and a sample threat analysis methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.02.

3.5.4 Changes Within Threat Environment: The Threat section shall conclude with a statement that addresses how new threat data is to be received and incorporated into the OPSEC Plan to ensure OPSEC risk remains in compliance with all applicable guidance.

3.6 CRITICAL INFORMATION

3.6.1 General: Critical information shall be identified within this section of the plan and a comprehensive program Critical Information List (CIL) shall be included.

3.6.2 Critical Information List: Guidance on the creation of a CIL is contained within “Applying OPSEC to Government Acquisitions and Contracts,” available at www.ioss.gov, DODM 5205.02M, or may be provided by the contracting activity. Ideally the CIL shall remain unclassified to facilitate wide internal distribution, but may provide reference to classified information as applicable.

3.7 VULNERABILITY

3.7.1 General: The Vulnerability section of the OPSEC Plan shall describe the analysis of activities (indicators) that point to OPSEC vulnerabilities an adversary can exploit to acquire critical information. This section shall contain a list of all identified OPSEC vulnerabilities.

3.7.2 List of OPSEC Vulnerabilities: Each vulnerability shall be described in sufficient detail as to communicate to the contracting activity the extent of the vulnerability. The Vulnerability List shall remain unclassified, but may provide reference to classified information if applicable. Reference to classified reports and other information shall include an unclassified description of the documentation (report title, number, etc.) and the source responsible for publication of the information.

Note: A list of typical OPSEC vulnerabilities which may require OPSEC measures may be found within “Applying OPSEC to Government Acquisitions and Contracts”, available at www.ioss.gov or may be provided by the contracting activity. These sample vulnerabilities are not all inclusive and the submitted vulnerability list shall be tailored to the specific acquisition or contract.

3.7.3 Vulnerability Analysis: Once potential program vulnerabilities have been identified, the magnitude of each vulnerability shall be determined using a consistent methodology identified and documented in this section of the OPSEC Plan. The results of this analysis shall also be described in this section.

Note: For additional guidance and a sample vulnerability methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.

3.8 RISK ASSESSMENT

3.8.1 General: The OPSEC risk of a program represents the probability of compromise of critical information and the impact to the program/contract taking into account the threat and vulnerabilities. The acceptable level of OPSEC risk (as determined by senior leadership, or the contracting activity) shall be described in this section in terms consistent with the selected OPSEC methodology.

3.8.2 Risk Assessment: The specific OPSEC risk shall be described in terms consistent with the OPSEC methodology selected for determining OPSEC threat and vulnerability.

The method, and the results of the assessment, shall be presented in this section. The conclusion of the risk assessment shall result in an ordinal ranking of OPSEC risk (highest to lowest).

Note: Additional guidance and a sample risk methodology are available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.

3.9 OPSEC MEASURES

3.9.1 General: This section of the OPSEC Plan shall identify specific OPSEC

Measures proposed for mitigating OPSEC risk to acceptable levels including the cost to implement each measure. A sampling of common OPSEC measures is available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov . This list is not to be considered exhaustive and is provided as guidance for the development of the program/contract specific list of potential OPSEC measures.

3.9.2 Residual Risk: This section shall contain an analysis of residual OPSEC risk, in terms consistent with the OPSEC methodology selected, as a result of implementation of each OPSEC measure presented in section 3.9.1. This section shall identify which OPSEC measures will be implemented and the rationale for those that will not.

3.10 OPSEC Program Chronology: This section shall document significant program OSPEC events throughout the lifecycle of the program. Significant events may include changes to the CIL, changes in program leadership or results of program assessments and surveys (including subcontractors). At a minimum, this section shall include a brief description of the event, date of occurrence, actions taken by the contractor and final disposition. A known compromise of critical information need only be referenced in keeping with the intended classification of this document.

Note: The history contained herein may be used by the government as a part of an OPSEC or security audit conducted by the contracting activity, DSS or other authorized agency.

3.11 ACRONYMS: This section shall include a complete list of acronyms used in the Program OPSEC Plan (i.e., CDRL – Contract Data Requirements List, DID – Data Item Description, etc.).

3.12 REFERENCES: This section shall include a complete list of all references cited in the Program OPSEC Plan (i.e. DoD Manual 5205.02-M, dated November 3, 2008, Contract Number, Corporate OPSEC Plan(s)/Program(s), etc.).

i The specific example provided derives from annual documentation produced by the Defense Security Service, Counterintelligence Office in 2009. Current assessments may be found at https://www.dss.mil/isp/count intell/count intell.html.

4. END OF DI-MGMT-80934C.

Title: Statement of Work (SOW)

Number: DI-MGMT-81606 Approval Date: 15 February 2001 AMSC Number: G7426 Limitation: N/A DTIC Applicable: N/A GIDEP Applicable: No

Office of Primary Responsibility: G/TS-ALS

Applicable Forms: None

Use/relationship:

The Statement of Work (SOW) shall describes the actual work to be performed on an acquisition procurement as specified by the procuring activity. The SOW shall be procured when requiring contractor support to assist with developing DoD acquisition packages.

Requirements:

l. Contract. This data item is generated by the contract which contains a specific and discrete work task to develop this data product.

2. Content. The content of the SOW shall contain information that fullfils the acquiring activities requirements as identified by the Government on the DD Form 1423, Contract Data Requirements List (CDRL).

3. Format. The format for the SOW shall be in contractors format unless otherwise specified by the DD 1423, or the COR.

End of DI-MGMT-81606

Source: https://assist.dla.mil -- Downloaded: 2018-08-09T21:17Z

Title: DOD Information Assurance Certification and Accreditation Process (DIACAP) and

Risk Management Framework (RMF) Deliverable Data

Number: DI-MGMT-82000 Approval Date: 20151014

AMSC Number: 9594 Limitation:

DTIC Applicable: GIDEP Applicable:

Office of Primary Responsibility: AS Project Number: MGMT-2015-021

Applicable Forms:

Use/relationship: The DIACAP and RMF Deliverable Data will be used to satisfy the requirements of the DIACAP and/or RMF process.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described by the contract.

Requirements:

1. Format. The DIACAP and/or RMF artifacts shall be delivered in a format approved by the

Government’s Designated Accrediting Authority (DAA), Authorizing Official (AO), or Information

Systems Security Manager (ISSM).

2. Content. The content of the DIACAP and/or RMF artifacts shall contain the necessary artifacts required by the DAA, AO, or ISSM to successfully achieve Platform IT Risk Approval (PRA), Interim Authority to Test (IATT), Interim Authority to Operate (IATO), or Authority to Operate

(ATO).

2.1 Introduction. This section shall contain a narrative of the DIACAP/RMF package content.

2.1.1 IATT Request. The IATT Request shall use the approved DAA, AO, or ISSM format. The

IATT Request shall identify the ‘who’, ‘what’, ‘why’, ‘where’, ‘when’, and ‘how’ of the requested

Test event. IATT Request shall be delivered not less than 30 days prior to the start of the Test

Event.

2.1.2 Certification and Accreditation (C&A) or Security Plan. The C&A or Security Plan shall use the approved DAA, AO, or ISSM format. The C&A Plan shall contain at a minimum, System

Information, Mission Description, Concept of Operations (CONOPS), Environment, Operating and

Computing Environment, Physical Security Measures, Facilities Descriptions, Threat Analysis, System Architecture Description, Components, Configurations, Accreditation Boundaries, Connection Process Guide (CPG) Compliant Network Diagrams, External Interfaces and Data Flow, Internal Data Flow, Contingency Plan, Incident Response Plan, User Descriptions and Clearances, Security Roles, Hardware Lists, Software Lists, Ports, Protocols, and Services (PPS), Configuration

Management Plan, Information Assurance Vulnerability Management (IAVM) Plan, and C&A Tasks and Milestones. The C&A Plan shall be approved and signed by the ISSM, User Rep, Program

Manager (PM), and DAA or AO.

Source: https://assist.dla.mil -- Downloaded: 2018-04-23T17:18Z

DI-MGMT-82000

2.1.3 C&A Project Plan. The C&A Project Plan shall use the approved DAA, AO, or ISSM format.

The C&A Project Plan shall be approved and signed by the ISSM, Echelon II Representative, and

PM. The C&A Project Plan shall define the various C&A Tasks and Milestones needed to achieve

PRA, IATT, IATO, or ATO.

2.1.4 Collaboration Brief. The Collaboration Brief shall use the approved DAA, AO, or ISSM format. The Collaboration Brief is submitted with the DIACAP/RMF package and is used to describe the System and System Risk during the Collaboration meeting.

2.1.5 DIACAP Implementation Plan (DIP). The DIP shall use the approved DAA, AO, or ISSM format. The DIP shall be used during the DIP Concurrence meeting with the Echelon II, Navy CA, and ODAA. The DIP shall define which IA Controls (IACs) will be ‘Implemented’, ‘Inherited’, ‘Non-Compliant’, or ‘Not Applicable’. The DIP shall be approved by the DAA, AO, and ISSM prior to execution of the IA Test Plan.

2.1.6 PIT Implementation Plan (PIP). The PIP shall use the approved DAA, AO, or ISSM format.

The PIP shall be used during the PIT Concurrence meeting with the Echelon II, Navy CA, and

ODAA. The PIP shall define which IACs will be ‘Implemented’, ‘Inherited’, ‘Non-Compliant’, or

‘Not Applicable’. The PIP shall be approved by the DAA, AO, and ISSM prior to execution of the

IA Test Plan.

2.1.7 IA Test Plan. The IA Test Plan shall use the approved DAA, AO, or ISSM format. The IA

Test Plan shall define all required Vulnerability Scans, Security Technical Implementation Guides

(STIGs), Security Readiness Guides (SRGs), Secure Content Automation Protocol (SCAP) benchmarks, and IA Controls or Security Overlays to be applied to the System. The IA Test Plan shall be approved by the DAA, AO, and ISSM during the DIP or PIP Concurrence Meeting.

2.1.8 PIT Designation Request. The PIT Designation Request shall use the approved DAA, AO, or

ISSM format. The PIT Designation Request is the formal request to the DAA or AO that the System shall be designated as Platform IT (versus an Information System (IS)). The PIT Designation

Request shall be approved and a PIT Designation Letter shall be signed by the DAA or AO prior to the execution of the IA Test Plan.

2.1.9 PIT Determination Brief. The PIT Determination Brief shall use the approved DAA, AO, or

ISSM format. The PIT Determination Brief shall be used in conjunction with the PIT Designation

Request to formally request the System be designated Platform IT (versus and Information System).

2.1.10 Plan of Action and Milestones (POA&M). The POA&M shall use the approved DAA, AO, or ISSM format. The POA&M shall be considered a ‘living’ document and shall regularly be updated throughout the entire lifecycle of the System through Decommission. The POA&M shall contain all Not Applicable IA Controls, All Non-Compliant IA Controls, and all Non-Compliant

Vulnerability Findings as identified in the Vulnerability Scans, STIGs, SRGs, and SCAP

Benchmarks. At a minimum, the POA&M shall be updated monthly.

2.1.11 Privacy Impact Assessment (PIA). The PIA shall use the approved DAA, AO, or ISSM format. The PIA shall be approved and signed by the ISSM, PM, and the Command PIA Officer.

2.1.12 Vulnerability Scans. In accordance with the approved IA Test Plan, the System shall be scanned using the approved vulnerability scanning tools as identified by the DAA, AO, or ISSM.

DI-MGMT-82000

The vulnerability scanner shall be updated with the latest signatures and scanning engines prior to the execution of each vulnerability scan. At a minimum, vulnerability scans shall be conducted monthly against the System. Non-compliant findings shall be documented in the System POA&M on a minimum monthly basis. At a minimum, vulnerability scans shall be submitted electronically to the

ISSM or uploaded into the DIACAP/RMF package. Vulnerability scans shall be handled in accordance with the System’s classification level. Vulnerability reports shall be in a format approved by the DAA, AO, or ISSM.

2.1.13 STIGs, SRGs, SCAP Benchmarks. In accordance with the approved IA Test Plan, the

System shall be hardened using the required and approved STIGs, SRGs, and SCAP Benchmarks.

Non-compliant STIG, SRG, and SCAP Benchmark findings shall be documented in the System

POA&M on a minimum monthly basis. Updates to the STIGs, SRGs, and SCAP Benchmarks are released on a monthly, quarterly, and yearly basis. Updates to the STIGs, SRGs, and SCAP

Benchmarks shall be implemented into the System as they are released. Non-compliant STIG, SRG, and SCAP Benchmark findings shall be documented in the System POA&M on a minimum monthly basis. STIG, SRG, and SCAP Benchmark artifacts shall be provided in a format approved by the

DAA, AO, or ISSM. STIG, SRG, and SCAP Benchmark artifacts shall be handled in accordance with the System’s classification level. At a minimum, STIG, SRG, and SCAP Benchmarks shall be submitted electronically to the ISSM or uploaded into the DIACAP/RMF Package on a minimum monthly basis.

2.1.14 Scorecard. The Scorecard shall use the approved DAA, AO, or ISSM format. The

Scorecard shall be maintained and updated on a minimum monthly basis.

2.1.15 Contingency Plan. The Contingency Plan shall use the approved DAA, AO, or ISSM format.

The Contingency Plan shall be submitted in conjunction with the System’s C&A Plan. The

Contingency Plan shall be approved and signed by the PM, ISSM, and DAA or AO.

2.1.16 IAVM Plan. The IAVM Plan shall use the approved DAA, AO, or ISSM format. The IAVM

Plan shall be submitted in conjunction with the System’s C&A Plan. The IAVM Plan shall be approved and signed by the PM, ISSM, and DAA or AO.

2.1.17 Cyber Security Waivers. Cyber Security Waivers shall use the approved DAA, AO, or ISSM format. All Cyber Security Waivers shall be approved and signed by the ISSM, PM, and First Flag or Equivalent prior to submission to the DAA or AO.

END OF: DI-MGMT-82000

Source: https://assist.dla.mil -- Downloaded: 2014-06-22T15:01Z

Title: SPECIAL ACCESS PROGRAM (SAP) ACCREDITED AREA STANDARD

OPERATING PROCEDURE (SOP)

Number: OT-2018-30025 Approval Date: 20180815 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A Applicable Forms: N/A

Use/Relationship: A written security Standard Operating Procedure (SOP), prepared for the Arnold Engineering Development Complex (AEDC) Government Special Access Program (SAP) Security Officer (GSSO), provides instructions for proper protection, use, and dissemination of classified material by assuring information, personnel, physical, communications, industrial, and Information Assurance (IA) security standards identified in the Performance Work Statement (PWS) 3.1. The SAP Accredited Area SOP is a living document that will require periodic updates throughout the life of the accredited area.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract PWS. This DID is for one-time use for AEDC solicitation FA9101-18-R-1000, AEDC Facility Support Services

(FSS).

Requirements:

1. Reference documents. None.

2. Format. The contractor’s electronic format is acceptable. The SAP Accredited Area SOP shall be available to authorized users via electronic and hardcopy forms.

3. Content. The SAP Accredited Area SOP content shall comply with all security standards identified in PWS 3.1.

End of OT-2018-30025

DISTRIBUTION STATEMENT A. Approved for public release. Distribution is unlimited.

Title: SPECIAL ACCESS POGRAM (SAP) CERTIFICATION AND ACCREDITATION

PACKAGE

Number: OT-2018-30026 Approval Date: 20180815 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A Applicable Forms: N/A

Use/Relationship: A Special Access Program (SAP) Certification and Accreditation package, prepared for the Arnold Engineering Development Complex (AEDC) Government Special Access Program (SAP) Security Officer (GSSO), includes physical security and TEMPEST documentation for the establishment and accreditation of the accredited area. The SAP certification and accreditation package includes information to ensure the facility meets prescribed physical, technical, and personnel security standards identified in the contract Performance Work Statement (PWS) 3.1. The accreditation package is a living document that will require periodic updates throughout the life of the accredited area.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract PWS. This DID is for one-time use for AEDC solicitation FA9101-18-R-1000, AEDC Facility Support Services

(FSS).

Requirements:

1. Reference documents. None.

2. Format. The contractor’s electronic format is acceptable. The package shall be available to authorized users via electronic and hardcopy forms.

3. Content. The content shall comply with the required level of detail, consistent with task delineation, and address all security requirements in accordance with Government direction.

The package shall contain a signature approval block for the GSSO.

End of OT-2018-30026

Title: TEST SECURITY PLAN FOR COLLATERAL CLASSIFIED, SPECIAL ACCESS

PROGRAM (SAP), AND COMMERCIAL TESTS

Number: OT-2018-30027 Approval Date: 20180830 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A Applicable Forms: N/A

Use/Relationship: The test security plan prepared for all commercial, unclassified, collateral classified, and SAP research, development, test, and evaluation (RDT&E) test programs conducted at Arnold Engineering Development Complex (AEDC) will be used by all associated test team members. The test security plan identifies all security requirements related to specific test efforts. The test security plan provides all employees supporting a test with test-specific security guidance and procedures.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for AEDC solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.

2. Format. The test security plan shall be in the contractor’s electronic format, and available to authorized users via electronic and hardcopy forms.

3. Content. The plan shall:

a. Identify the test program and provide an overview of the test.

b. Identify the customer/sponsor and test facility.

c. Identify classification, specific local or customer guidance, related Security

Classification Guides, and any Technical Assistance Agreements and Technology Control Plans.

d. Identify Baseline Protection Requirements for data and the test areas (Physical Space).

OT-2018-30027

e. Identify the Risk Assessment Authorization (RAA), if required:

(1) Identify any foreign national involvement and subsequent visitor control procedures.

(2) Identify any Controlled Unclassified Information (CUI) and specific guidance.

(3) Identify any Operations Security (OPSEC) concerns and specific measures and guidance.

(4) Identify any Critical Program Information (CPI) and specific Program Protection

Plan (PPP) requirements or guidance.

f. Provide data marking guidance, including distribution limitations, export control, and any dissemination markings to be included with classification marking.

g. Provide all physical security and Automated Identification System (AIS) requirements and a checklist on how to implement them, including detailed diagrams or drawings.

h. Provide standard requirements for each test program (test photography, etc.).

i. Identify other Test, Industrial, Information, Personnel, or Physical Security requirements.

j. Provide a list of definitions, abbreviations, acronyms, terms, symbols, and notations used.

k. The plan shall contain signature approval blocks (or electronic equivalent) for the

Government Project Manager, Information Systems Security Officer, FSS Facility Security Officer, and Servicing Security Activity (AEDC/TSD-IP).

l. When applicable, an annex will be added to contain a Foreign National Technology Control Plan per DoDD 5230.20, Visits and Assignments of Foreign Nationals.

(Copies of this document are available online at http://www.esd.whs.mil/.)

End of OT-2018-30027

Title: STANDARD PRACTICE PROCEDURES (SPP) DOCUMENT

Number: OT-2018-30028 Approval Date: 20180830 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A Applicable Forms: N/A

Use/Relationship: The Standard Practice Procedures (SPP) document will be used to ensure effective implementation of the requirements of Department of Defense Manual (DoDM) 5220.22, National Industrial Security Program Operating Manual (NISPOM). (Copies of this document are available online at www.esd.whs.mil/.) The SPP contains specific guidance for the contractor's operations and involvement with classified information at the contractor's facility/areas located at Arnold Engineering Development Complex (AEDC).

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for AEDC solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.

2. Format. The contractor’s electronic format, conforming to DoDM 5220.22, Section 1-203, is acceptable. The SPP document shall be available to authorized users via electronic and hardcopy forms.

3. Content. The SPP content shall comply with DoDM 5220-22, Section 1-203, and be consistent with the required level of detail, consistent with task delineation, and address all security requirements in accordance with Government direction. The SPP shall contain signature approval blocks for all FSS “Key Management Personnel” and the Servicing Security Activity (AEDC/TSD-IP).

End of OT-2018-30028

Title: INFORMATION PROTECTION (IP) STANDARD OPERATING PROCEDURE (SOP)

FOR SECURED AREAS

Number: OT-2018-30029 Approval Date: 20180830 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A Applicable Forms: N/A Use/Relationship: A written Information Protection (IP) Standard Operating Procedure (SOP) provides instructions and guidance to ensure compliance with requirements contained in Department of Defense Manual (DoDM) 5200.01, Vol 3, DoD Information Security Program: Protection of Classified Information (Copies of this document are available online at http://www.esd.whs.mil/.), Air Force, program, and other cognizant security agency directives for secured and commercial test areas. The IP SOPs are living documents that will require periodic updates throughout the life of the area.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.

2. Format. The contractor’s electronic format is acceptable. The IP SOP shall be available to authorized users via electronic and hardcopy forms.

3. Content. The IP SOP content shall:

a. Be consistent with the required level of detail and task delineation.

b. Address all security requirements in accordance with Government direction and applicable standards within the contract PWS.

c. Include Entry/Exit Control procedures for use by owner/users or area custodians of established secured and commercial test areas.

d. Include procedures for Installation Random Antiterrorism Measures (IRAMs) within established secured and commercial test areas.

e. Contain signature approval blocks for the FSS Facility Security Officer and the

Servicing Security Activity (AEDC/TSD-IP).

End of OT-2018-30029

Title: BLOOD BORNE PATHOGENS (BBP)/EXPOSURE CONTROL PLAN

Number: OT-2018-30030 Approval Date: 20180828 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A Applicable Forms: N/A

Use/Relationship: The Blood Borne Pathogens (BBP)/Exposure Control Plan will be used to outline the mandatory requirements for all security guards with the potential for exposure to BBP during the performance of their assigned duties.

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.

2. Format. The contractor’s electronic format is acceptable. The plan shall be readily available to all security guards.

3. Content. The plan shall contain the exposure determination of personnel (those reasonably anticipated, as a result of performing their day-to-day duties, to have potential skin, eye, or mucous membrane contact with blood or other potentially infectious fluids or materials). This determination shall include:

a. A list of all duty positions in which personnel are likely to be exposed to contaminated material.

b. A list of all tasks and procedures, or groups of closely-related tasks and procedures, in which exposure may occur; tasks and procedures will be performed by personnel who handle contaminated material.

c. The methods available to prevent contact with blood and other potentially infectious fluids or materials.

d. Procedures for those who reasonably believe they have contacted a potentially infectious fluid or material.

OT-2018-30030

e. Procedures for placing warning labels on containers or plastic bags containing blood or other potentially infectious material. Labels must comply with Occupational Safety and Health Agency (OSHA) Standard 1910.1030, Bloodborne Pathogens.

(Copies of this document are available online at https://www.osha.gov/law-regs.html.)

f. Procedures for keeping records of all incidents and occupational exposures per OSHA Standard 1910.1030.

g. Procedures for evaluating circumstances surrounding exposure incidents.

End of OT-2018-30030

Title: HAZARDOUS COMMUNICATION (HAZCOM) PLAN

Number: OT-2018-30031 Approval Date: 20180828 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A Applicable Forms: N/A

Use/Relationship: The Hazardous Communication (HAZCOM) Plan shall ensure supervisors and employees who handle, use, or are potentially exposed to hazardous chemicals in the course of official duties are provided information and training on the Air Force HAZCOM Program and the specific hazards in their work areas in accordance with

3.1.6.2.3 of AFI 90-821, Hazard Communication (HAZCOM) Program. (Copies of this document are available online at http://www.e-publishing.af.mil/.)

This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).

Requirements:

1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.

2. Format. The plan shall be in the contractor’s electronic, .xls or .xlsx compatible, format.

3. Content. The content shall comply with the requirements for a HAZCOM Plan per AFI 90- 821 and shall include the following data:

a. AEDC Safety, Health, and Environmental Standard A9, Hazard Communication.

(Copies of this document are available via email from AEDC/SE at aedc.se.workflow@us.af.mil.)

b. Authorized Use List

c. Safety Data Sheets (SDS)

End of OT-2018-30031

Title: SECURITY SERVICES WORK INSTRUCTIONS

Number: OT-2018-30032 Approval Date: 20180828 AMSC Number: N/A Limitation: FA9101-18-R-1000 DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A Applicable Forms: N/A

Use/Relationship: Security Services Work Instructions…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.