FSS_II_Draft_PWS_20_Jul_18.pdf

PDF 6 MB Posted

Attached to
Facility Support Services Federal contract opportunity
Solicitation number
FA9101-18-R-1000
Issued by
Department of the Air Force Materiel Command Test Center

View the file

Other files for this federal contract opportunity

Other files attached to Facility Support Services, newest first.
File Type Posted
Amendment_0001_SF30.pdf PDF
QandA_No._9.pdf PDF
QandA_No._7.pdf PDF
Exhibit_A_CDRLs.pdf PDF
Attachment_9,_Section_M_FRFP.pdf PDF
Attachment_2,_DD_254.pdf PDF
FSS_II_SF33.pdf PDF
Attachment_L-7,_Cross_Reference_Matrix.xlsx XLSX spreadsheet
Exhibit_D,_ASO_and_PSI_and_IGUA_CBA.pdf PDF
Attachment_L-1,_PPI_Tool.pdf PDF
Attachment_L-5,_Subcontractor_Consent_Letter.pdf PDF
Attachment_8,_Section_L_FRFP.pdf PDF
Attachment_1_PWS_9_Nov_18.pdf PDF
Attachment_3,_SCA_and_CBA_WDs.pdf PDF
Exhibit_C,_ASO_and_AEMTC_CBA.pdf PDF
QandA_No._6.pdf PDF
FSS_II_Notional_Acquisition_Schedule_-_Sep_2018.pdf PDF
Industry_Day_3_Panel_Cancellation.pdf PDF
Draft_Attachment_8,_Section_L_(UPDATE).pdf PDF
QandA_No._5.pdf PDF
Industry_Day_No._3_Agenda.pdf PDF
Industry_Day_No._3_Announcement.pdf PDF
QandA_No._4.pdf PDF
Attachment_2,_DD254.pdf PDF
Attachment_7,_USAF_Owned_Registered_Vehicles.pdf PDF
Attachment_3,_SCA_and_CBA_WDs.pdf PDF
Attachment_L-6,_Relevancy_Matrix.xlsx XLSX spreadsheet
Attachment_L-5,_Subcontractor_Consent_Letter.pdf PDF
Attachment_L-8,_Cost_Model.xlsx XLSX spreadsheet
Attachment_L-3,_PPQ_Cover_Letter.pdf PDF
FSS_II_dRFP_SF33.pdf PDF
Attachment_L-7,_Cross_Reference_Matrix.xlsx XLSX spreadsheet
Attachment_5,_ACES_FD_Property_Listing.pdf PDF
Exhibit_B_Data_Item_Descriptions.pdf PDF
Attachment_L-4_Past_Performance_Client_Authorization_Letter.pdf PDF
Exhibit_D,_ASO_and_PSI_and_IGUA_CBA.pdf PDF
Exhibit_E,_ASO_and_URS_and_AEMTC_CBA.pdf PDF
FSS_II_dRFP_Cover_Letter.pdf PDF
Attachment_9,_Section_M.pdf PDF
FSS_II_Draft_PWS,_CDRLs_and_DIDs_Announcement.pdf PDF
FSS_II_Draft_Exhibit_A_Contract_Data_Requirements_List.pdf PDF
Questions_and_Answers_No._2.pdf PDF
Request_for_Information_No._1.pdf PDF
Attachment_8_-_Industry_Day_No._2_Registration_Form.docx DOCX document
Attachment_7_-_Industry_Day_No._2_Agenda.pdf PDF
Attachment_8_-_Industry_Day_No._2_Registration_Form.pdf PDF
Attachment_6_FSS_II_Draft_PWS_13_Apr_18.pdf PDF
Sources_Sought_QandA_No._1.pdf PDF
Attachment_2_(Update)_-_Industry_Day_No._1_Announcement.pdf PDF
Attachment_2_-_Industry_Day_No._1_Announcement.pdf PDF
Show all 50

Facility Support Services has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA9101-18-R-1000

Attachment 1

Draft Performance Work Statement

Arnold Engineering Development Complex Facility Support Services II

20 July 2018

1 Introduction

1.1 Mission

1.2 Background

1.3 Scope

2 General Requirements

2.1 Business Relations

2.2 Contract Administration and Management

3 Performance Requirements

3.1 Industrial Security, Test Security, and Security Management Support

3.3 Command, Control, and Communications

3.4 Fire and Emergency Services Program

3.5 Environmental Program

3.6 Safety Program

3.7 Occupational and Environmental Health (OEH)

3.8 Base Supply

3.9 Cargo Movement

3.10 Vehicle Operations and Maintenance

3.11 Interface Management

3.12 General Management

4 Special Requirements

5 Acronyms

6 Deliverables

7 Performance Requirements Summary

APPENDICES

APPENDIX A – CLOSED AND RESTRICTED AREAS

APPENDIX B – FESAP CHECKLIST

APPENDIX C – MUTUAL AID AGREEMENTS

APPENDIX D – ABOVEGROUND STORAGE TANKS

APPENDIX E – ENVIRONMENTAL PERMITS

APPENDIX F – ENVIRONMENTAL PLANS

APPENDIX G – HAZARDOUS WASTE GENERATION

APPENDIX H – NPDES DATA

APPENDIX I – PERMITTED SEPTIC TANKS

APPENDIX K – SIGNIFICANT LEAKS OR SPILLS HISTORICAL DATA

APPENDIX L – ARNOLD AFB VEHICLE FLEET

APPENDIX M – FSS BUILDING MANAGER INVENTORY

Performance Work Statement (PWS)

Facility Support Services (FSS)

1 Introduction

The Air Force Test Center's (AFTC) Arnold Engineering Development Complex (AEDC) is a national aerospace ground test facility that conducts tests, engineering analyses, and technical evaluations for research, system development, and operational programs of the Air Force (AF) and Department of Defense (DoD), other Government agencies, and industry. Using ground test facilities and computational engineering, AEDC supports propulsion, aerodynamic, reentry, trans-atmospheric, and space-flight systems testing. This testing underpins the technical knowledge required for the development and qualification of key warfighter aerospace weapons.

Testing is performed in an environment that simulates operational conditions. AEDC also performs research to develop new technology for advanced test facilities, test techniques, and measurement methodologies associated with ground tests.

1.1 Mission

AEDC exists to test and evaluate weapon, propulsion, aerodynamic and space systems at realistic conditions for the nation through modeling, simulation and ground test facilities.

The mission is essential to developing and fielding weapons systems for the nation's warfighters.

The FSS Contractor will be expected to perform in this mission, while smoothly integrated with the other Arnold Air Force Base (AFB) contractors and Government personnel, in a manner that makes AEDC the best value and most effective ground test and evaluation complex in the world.

1.2 Background

Arnold AFB, located in Tullahoma, TN, has been Government-managed and contractor-operated since its inception. Contractors conduct test operations, base operations, test facility and base infrastructure maintenance and improvement efforts, and many other services critical to operating and sustaining the nation's largest collection of aerospace ground test facilities. The AEDC Test Operations and Sustainment (TOS) contract provides the contractor workforce necessary to successfully operate and sustain AEDC's test facilities at Arnold AFB, TN, and geographically separated units (GSUs) at White Oak, MD, and Moffett Field, CA. Enterprise contracting initiatives beginning in 2015 resulted in information technology tasks, operation of the Precision Measurement Equipment Laboratory (PMEL), and technical management and engineering analysis support for test programs being performed under separate contracts. In addition, some portions of base operating support (BOS) tasks, historically part of the overall operating contract, were set aside for small business under an FSS contract.

1.3 Scope

This contract effort provides multiple aspects of BOS functions in support of AEDC’s test mission. The FSS contract provides supply, vehicle maintenance, cargo movement, operations center and command & control (C2) functions, industrial and test security, security services, and fire and emergency services. The FSS contract also provides support for overall AEDC Safety, Environmental, and Occupational Health programs.

2 General Requirements

The effort will be performed primarily at Arnold AFB in Tennessee. Performance will also be required at AEDC facilities housed as tenants on sites at Tunnel 9 in White Oak, MD and on the National Aeronautics and Space Administration (NASA) Ames Research Center (ARC) grounds at Moffett Field, CA where specified. Requirements listed in this PWS are assumed to be Arnold AFB unless specifically noted otherwise.

2.1 Business Relations

The Contractor shall successfully integrate and coordinate all activities needed to execute the requirements. The Contractor shall manage the timeliness, completeness, and quality of problem identification. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of sub-contractors. The Contractor shall coordinate and cooperate closely with associate Contractors involved in the execution of AEDC’s mission. The Contractor shall seek to ensure satisfaction of all internal and external customers, and ensure professional and ethical behavior of all Contractor personnel.

2.2 Contract Administration and Management

The Contractor shall perform all contract management functions required to ensure proactive and sustained contract excellence in providing accurate, safe, secure, timely, and efficient facility support services to meet the Government's established requirements.

2.2.1 Contract Management

The Contractor shall designate and locate at Arnold AFB a responsible corporate official with no responsibility other than for this contract and empowered to make and implement all decisions regarding the performance of this contract.

2.2.2 Contract Administration

The Contractor shall:

Ensure performance of the business and administrative aspects of the contract;

Report all Full-Time Equivalents (FTEs) in accordance with (IAW) Section 8108 of Public Law 112-10 of the DoD and Full-Year Continuing Appropriations Act, 2011;

Ensure resources are efficiently and effectively managed and contract status (including Government-furnished resources) is reported to Government representatives; and

Develop, implement, and manage formal associate Contractor agreements with the following contractors at Arnold AFB: TOS; Test Services; PMEL; Performance Based Remediation; and Base Communications and Information Technology Services (BCITS).

2.2.3 Personnel Administration

The Contractor shall:

Maintain a qualified work force to support the Government and ensure AEDC maintains compliance with all applicable regulations. Conduct employee, supervisory, and management training programs;

Maintain staffing records identifying company organizational designations, a brief description of the functions, and the number and types of personnel assigned; and

Provide and administer an Equal Opportunity Affirmative Action Program that complies with all Federal statutes.

3 Performance Requirements

3.1 Industrial Security, Test Security, and Security Management Support

At Arnold AFB, the FSS Contractor will be designated as an “On-Base Cleared Facility” per DoD 5220.22-R and will be cleared under the provisions of the National Industrial Security Program (NISP). The Chief of Information Protection has been designated by the Installation Commander to provide security oversight and the Information Protection Office will be the Servicing Security Activity (SSA).

As the Prime Security Contractor and an “on-base cleared facility,” the FSS Contractor will be responsible for establishing & managing all physical space, listed in Appendix A and all other spaces determined by the SSA requiring additional safeguards. In addition, the FSS Contractor is required to meet all PWS 3.1 requirements identified for AEDC Moffett Field. The Contractor is responsible for establishing standard security practices and procedures for classified and commercial test areas as well as managing the Special Access Programs (SAP) Security Program under the direction of the Government Special Security Officer (GSSO). In order to fully implement AEDC Information Protection Program objectives, the Contractor will need to work with and perform security support functions in coordination with the Chief of Information Protection, the AEDC Government SAP Security Officer, AEDC Security Managers, respective program / project manager(s), and other Contractors performing work at AEDC.

In addition to requirements identified in the DD Form 254, this effort must ensure compliance with a variety of specialized security directives, regulations, and guides, including DoD Regulations, AFIs, and related AEDC policies / operating instructions (OIs). Contractor personnel must also have knowledge of DoDM 5205.07, Volumes 1-4 and the Joint Security Implementation Guide (JSIG), Foreign Disclosure, DoD regulations, pertinent Department of Navy regulations, SAF/AQ Policy Documents, and pertinent Executive Orders. The Contractor personnel must be familiar with protecting Automated Information Systems. The Contractor must be aware and adhere to revised publications listed in Section 3.1.5 to ensure proper compliance.

3.1.1 Test Security and Facility Clearance Level (FCL) Management

3.1.1.1 The Contractor shall have a valid Top Secret FCL and maintain an industrial security program compliant with DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), and other mandatory directives listed in the solicitation to protect information and operations critical to the successful accomplishment of AEDC’s mission. Additional mandatory directives are listed in Section 3.1.5.

There are inherently governmental functions and activities that cannot be outsourced to a contractor. Inherently governmental activities and functions include those that require either the exercise of substantial discretion in applying U.S. Government authority, or value judgments when making decisions for the U.S. Government. Although the Contractor will be tasked to support assigned Government Program Security Manager(s) with respective security program requirements and to assist in providing centralized security services, the Government security manager has the lead and is the decision maker. The Contractor is only providing support in this capacity to perform administrative security functions under the direction of the activity security manager.

Activity security management shall ensure that Contractors who are involved in security administration and support duties are clearly identified in their capacities, roles, and functions, to ensure there is no possible confusion regarding inherently governmental authorities. The Contractor should contact the contracting officer for clarification in the event of any conflict.

Inherently governmental Security Functions that the Contractor shall not perform include, but are not limited to:

(a) Approving and issuing security policies and procedures

(b) Making original classification decisions, or rendering classification determinations regarding classified information that is improperly or incompletely marked. (Correcting improper markings when the appropriate classification is not in question is not considered rendering a classification determination.)

(c) Deciding to downgrade or declassify information. (Adhering to security markings on information or to guidance stated in an appropriate security classification or declassification guide is not considered a downgrading or declassification decision.)

(d) Deciding challenges to classification and any appeals

(e) Making foreign disclosure decisions

(f) Making public release decisions

(g) Committing to expenditure of U.S. Government funds

(h) Conducting investigations of, or determining fault in, security incidents involving U.S.

Government or other Contractor personnel. (Contractors shall also conduct preliminary inquiries to determine if a security incident is a violation or an infraction.)

(i) Giving final approval or executing documents for filing in litigation if documents assert an official position of the DoD, any DoD Component, or any other Federal agency

3.1.1.2 The Contractor shall obtain and maintain a facility clearance at the classification level of Top Secret prior to performing any classified work on the contract.

Performance Standards

a) STD: No Security Violations that result in a loss or compromise of classified information.

b) STD: Score / Achieve no less than a Satisfactory rating 650 on the Defense Security Service’s (DSS) Assessment Rating Matrix and no less than a “Satisfactory” on all other, internal and external security reviews, inspections, audits, and / or vulnerability assessments.

3.1.1.3 The Contractor shall designate a full time Facility Security Officer (FSO) with independent authority to manage and enforce all aspects of the Industrial Security program requirements for the company and all personnel within their managed areas.

FSO Requirements are:

(a) Security training through the DSS-FSO Program Management for Possessing Facilities Curriculum (IS030.CU) (Approximately 17 Courses) shall be obtained prior to contract start date. Additional courses or curriculum may be needed to obtain applicable certifications.

(b) DSS Professional Certifications must be obtained through Security Professional Education Development Program (SPeD) within 1 year of contract start date and maintain recertification every two years.

For more information on training and SPēD Certification: www.dss.mil, www.cdse.edu/documents/sped/SPeD_Candidate_Handbook_4-1-14.pdf. The FSO Tool Kit is available at: http://www.cdse.edu/toolkits/fsos/new-fso.html.

or

(c) Acquire ASIS International Professional Certifications prior to contract start date:

For more information on training and ASIS International Certification:

https://www.asisonline.org/Certification/Board-certifications/Pages/default.aspx.

Performance Standards

a) STD: The designated FSO, or those otherwise performing security duties, shall complete required security training and briefings considered appropriate by the SSA; obtain and maintain required DSS professional certifications or ASIS International professional certifications.

b) STD: The FSO must obtain a Top Secret Personal Clearance prior to contract start date and maintain during contract execution.

3.1.1.3.1 The FSO and support staff, to include staff located at AEDC Moffett Field must be trained IAW chapter 3 of the NISPOM, for a possessing facility, and cleared commensurate with and concurrent with the issuance of the Facility Clearance Level IAW DoD 5220.22-M, Section 2, 1-201.

Performance Standard

STD: Training must meet NISPOM and DSS requirements and curriculum for FSO Program Management for Possessing Facilities.

3.1.1.3.2 The Contractor shall ensure the FSO is physically located at Arnold AFB in order to monitor and facilitate all security requirements.

Work schedules for security support are non-standard and dependent upon test schedules, inspections schedules, and emergency situations. The core operational hours of the security personnel are from 0730-1630 hours, Monday through Friday, not including opening or closing times, which may extend one or more hour(s) before or after the core hours for security support, including any visitor control or required customer assistance.

Performance Standards

a) STD: FSO shall be available to meet with the Government on urgent security issues within two hours of initial request.

b) STD: No test or programmatic impacts occur as a result of the absence of responsible security personnel.

3.1.1.3.3 The Contractor shall ensure all subcontractors enter into a Visitor Group Security Agreement (VGSA) with the AEDC Commander, as determined by the SSA IAW AFI16- 1406. The VGSA must be signed by required parties and must address all security requirements before any classified work begins.

The Agreement will outline responsibilities in the following areas: Contractor security supervision; Standard Practice Procedures (SPP); access, accountability, storage, and transmission of classified material; marking requirements; security education; personnel security clearances; reports; security checks; security guidance; emergency protection; protection of Government resources; DD Forms 254; periodic security reviews; and other responsibilities, as required.

3.1.1.3.4 The Contractor shall manage a self-inspection program and is responsible to perform semi-annual self-inspections at Arnold AFB and AEDC Moffett Field. The Contractor will provide answers and source documentation in the COR provided communicator(s) within the Management Internal Control Toolset (MICT).

The Contractor shall ensure accurate, reliable, and critical assessments are performed. The Government COR will validate Contractor responses to applicable communicators and source documentation within MICT.

3.1.1.3.4.1 The Contractor shall provide the Government with written corrective action plans for all identified deficiencies at Arnold AFB and Moffett Field to determine primary and contributing root causes within 30 days of deficiency discovery. If the first response does not close all deficiencies, the Contractor will provide updates every 30 days thereafter until all deficiencies are resolved or closed.

Performance Standard

STD: Air Force Smart Operations for the 21st Century (AFSO21) processes or similar tool shall be used to determine efficiencies or improve processes and procedures.

3.1.1.4 The Contractor shall provide SAP security management support for Arnold AFB.

Under the direction of the GSSO, the Contractor shall assist with management, administration, and sustainment of all aspects of a SAP security program compliant with all applicable DoD and AF requirements.

The Contractor shall assist the GSSO in providing SAP security management for test security, physical security, personnel security, information security, operations security (OPSEC), and SAP security education and training.

Performance Standard

STD: Receive no less than a Satisfactory rating from external inspections.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.1 Under the direction of the GSSO, the Contractor shall establish, maintain, and manage SAP Facilities as required to support mission requirements in compliance with DoDM 5205.07, Volumes 1-4 and the JSIG and Program Security Officer (PSO) guidance.

Access shall be limited to authorized persons who have an appropriate security clearance, need-to-know, and documented formal access to the information within the area.

Performance Standard

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.2 The Contractor shall maintain a SAP billet plan for each supported program and ensure initial and annual Government approval of each plan.

3.1.1.4.3 The Contractor shall identify, obtain, and maintain U.S. Postal Service procedures approved by the PSO.

3.1.1.4.4 The Contractor shall appoint a full-time Program Security Representative (PSR) cleared at least equal to the highest level of classified information for which they require access and possess access to all SAPs assigned to the facility(s) for which he / she is responsible. The PSR shall have the position, responsibility, and authority as directed by the GSSO to effectively manage and enforce all SAP security requirements based upon guidance provided by the PSO.

The Contractor shall ensure the PSR, or an appointed alternate, is physically located at Arnold AFB in order to monitor and facilitate all SAP security requirements.

Work schedules for SAP security support are non-standard and dependent upon test schedules, inspections schedules, and emergency situations. The core operational hours of the security personnel are from 0730-1630 hours, Monday through Friday, not including opening or closing times, which may extend one or more hour(s) before or after the core hours for security support including any visitor control or required customer assistance.

Performance Standards

a) STD: The designated PSR, or those otherwise performing SAP security duties, shall complete required security training and briefings considered appropriate by the GSSO/PSO.

b) STD: The PSR shall be available to meet with the Government within two hours on all urgent security issues upon request.

c) STD: No test or programmatic impacts occur as a result of the absence of responsible security personnel.

d) STD: Score / Achieve no less than a Satisfactory rating on the SAP related security inspections.

3.1.1.4.5 The Contractor shall provide Top Secret accountability for all Top Secret SAP information utilizing a PSO approved document control accountability system.

3.1.1.4.6 The Contractor shall appoint a full-time Information System Security Manager, Information System Security Officer(s), and sufficient System Administrator(s) cleared at least equal to the highest level of classified information for which they require access and possess access to all SAPs assigned to the facility(s) for which they are assigned.

The Contractor shall ensure the ISSM, ISSO and System Administrators are physically located at Arnold AFB.

3.1.1.4.7 The Contractor shall ensure compliance with separation of duties as identified in JSIG Section 3.1.5.

3.1.1.4.8 The Contractor shall ensure that SAP Information Systems are operated, maintained, and disposed of IAW SAP security policies.

Performance Standard

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.9 The Contractor shall develop and maintain a formal information systems security program and implement all information systems security policy, establish and maintain accreditation documentation and procedures for all SAP systems, ensure the development and accuracy of accreditation documentation, and recommend action to the approval authority.

Performance Standard

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.10 The Contractor shall attend and participate in working groups, configuration management meetings, and planning meetings as required to represent SAP IA interests and ensure that administrative, analysis, and ID&C systems remain compliant with SAP security policies.

Performance Standard

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

3.1.1.4.11 The Information System Security Manager shall ensure that Information System Security Engineer requirements are effectively integrated into information systems through purposeful security architecting, design, development, and configuration through coordination with the responsible Government organization / individual providing Information System Security Engineering services to SAP.

Performance Standard

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.12 The Contractor shall use the Joint Access Database Environment, or any successor, for personnel security management functions for all AF SAPs IAW the AFADs Policy Directive dated 22 Jan 2008.

3.1.1.4.13 The Contractor shall provide IA support for test requirements, configuration management, lifecycle sustainment, budgeting, system accreditation, and day-to-day system administration including hardware and software requisition, installation, and maintenance as required for all SAP requirements.

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.13.1 The Contractor shall perform IA support IAW DoDM 5205.07, Volumes 1-4, and the JSIG, 9 October 2013, DoD Joint SAP Implementation Guide (DJSIG, 9 Oct 2013).

Performance Standards

a) STD: Receive a satisfactory rating from all internal and external inspections.

b) STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.13.2 The Contractor shall ensure qualified and experienced IA personnel meeting DoD 8570 certification requirements are available to meet the day-to-day AEDC SAP system administration requirements to include after-duty hours as required.

Performance Standards

a) STD: The designated SAP ISSM, ISSO(s), and System Administrator(s), or those otherwise preforming SAP IA duties, shall complete required technical training, security training, and briefings considered appropriate by the PSO.

b) STD: The SAP ISSM, or designated and qualified alternate, shall be available to meet with the Government on all urgent security issues within two hours of initial notification.

c) STD: No test or programmatic impacts occur as a result of the absence of responsible SAP IA personnel.

d) STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.14 The Contractor shall ensure all systems required for SAP support obtain Authority to Operate (ATO) to meet test requirements to include:

Providing IA artifacts and maintaining updated Certification and Accreditation packages for SAP Information Systems

Maintaining a continuous monitoring program to ensure the state of the systems’ environments do not change from the accredited configurations

Performance Standards

a) STD: 100% of systems must have an approved Authority to Operate (ATO) prior to testing.

b) STD: All SAP ATO packages must be renewed within 1 month of their expiration.

Deliverables

A001 SAP Accredited Area Standard Operating Procedure

A002 SAP Certification and Accreditation Package

A003 JSIG System Authorization Package (SAP)

A004 DIACAP and RMF Deliverable Data

A005 Test Security Plan

3.1.1.4.15 The Contractor shall submit Program Access Requests for SAP to the approval authority within five (5) working days after receiving Government approval of the access requirement. The SAP Nomination Process shall be followed for all SAP nominations.

3.1.1.4.16 The Contractor shall prepare Standard Operating Procedures (SOP) necessary for the implementation of SAP requirements. SOPs shall be developed and coordinated in compliance with DoDM 5205.07, Volumes 1-4, and the JSIG.

Deliverable

A001 SAP Accredited Area Standard Operating Procedure

3.1.1.5 The Contractor shall provide security support for all phases of unclassified, classified, and commercial testing and related test activities performed at Arnold AFB and AEDC Moffett Field.

The Contractor shall establish and implement a security program compliant with DoD, service, and local directives and make recommendations for improvements to security test procedures;

integrate cost effective and threat based security processes, plans, and procedures. Test phases include planning, design, fabrication, installation, execution, removal, reporting, and analysis.

The protection / security of test articles or systems and data is required.

Performance Standards

a) STD: No Security Violations that result in a loss or compromise of classified information.

b) STD: Score / Achieve no less than a Satisfactory rating 650 on the DSS Assessment Rating Matrix and no less than a “Satisfactory” on all other, internal and external security reviews, inspections, audits, and / or vulnerability assessments.

3.1.1.5.1 The Contractor shall develop, coordinate, document and implement specific security requirements for all test programs performed at Arnold AFB and AEDC Moffett Field to include any special security training required for each test.

Performance Standard

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate security planning, training and execution.

Deliverable

A005 Test Security Plan

3.1.1.5.2 The Contractor shall develop a Test Security Plan for each test and related activity, as requested by the Government for tests performed at Arnold AFB and AEDC Moffett Field.

The Contractor should anticipate having to develop approximately 125 Test Security Plans annually. Each Test Security Plan will be reviewed, revised as necessary to remain compliant with current security policy, and coordinated for Government approval. Ensure the integration of US export and technology control laws, DoD / Agency policy and instructions and other applicable guidance into test security plans. Test Security Plans developed in support of SAP efforts must be approved by the PSO, the customer security representative, and the Government.

Test Security Plans for Sensitive Compartmented Information (SCI) efforts must be approved by the Government Project Manager and the AEDC Special Security Office.

The Test Security Plan, including physical security boundaries and facility-specific procedures, shall be briefed to all personnel supporting SAP and / or SCI tests. Training accomplishment shall be documented and maintained IAW Records Distribution Schedules located in the Air Force Records Information Management Systems (AFRIMS) and applicable AFIs.

Performance Standard

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate security planning and execution.

Deliverable

A005 Test Security Plan

3.1.1.5.3 The Contractor shall retain a copy of all program Security Classification Guides and verify they are current IAW DoD 5220.22-M, DoDM 5200.01, Vol. 1-4, AFI 16-1404, AFI 16-1406, and supplements.

Performance Standard

STD: Maintain 100% of applicable test related Security Classification Guides on site.

3.1.1.5.4 The Contractor shall provide analytical, technical, and administrative security support services to Information Protection, Industrial Security, and SAP Security programs managed by the Government.

Technical and administrative support from qualified security personnel is required to ensure core programs are successfully executed IAW applicable DoD and AFIs. Support will be provided "on-site” to the Government at Arnold AFB and includes security reviews, evaluations, initial surveys, and assessments. The Contractor shall be required to visit AEDC Moffett Field at least once per year to conduct a Staff Assistance Visit or inspection. Programs include but are not limited to: Industrial Security, Personnel Security, Information Security, OPSEC, Test Security, and Physical Security for the protection of controlled information.

The Contractor should anticipate supporting 5-10 security reviews, evaluations, initial surveys, and assessments annually; however, this may fluctuate depending upon mission needs.

STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate technical security planning support.

3.1.1.5.4.1 The Contractor shall provide High Definition (HD) photography equipment and support of photography requirements within their managed spaces regardless of its security classification.

The Contractor should anticipate Arnold AFB personnel and / or Test Customers to request photography services within the test mission area. The Contractor shall provide policy, procedures, and control of all HD photography equipment to support test related photography and screen / review all photographs before release to ensure required protection and markings are applied.

Performance Standards

a) STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate photography quality or support.

b) STD: Maintain 100% accountability of equipment and media review to ensure proper marking and release.

3.1.1.5.4.2 The Contractor shall provide Portable Electronic Device (PED) approval / disapproval services and procedures for Arnold AFB and AEDC Moffett Field personnel and test customers.

The Contractor shall provide specific policy / procedures to the workforce when a PED is required within their closed and restricted managed areas. The Contractor must be able to evaluate the risk associated with each PED based on its capabilities to transmit data or inadvertently compromise sensitive information. PEDs may include but are not limited to hearing aids, medical devices, laptops, Electronic Notebooks, FitBits, Keyfobs, etc.

Performance Standard

STD: No security compromises resulting from ineffective security policy, procedures and / or controls.

3.1.1.5.5 The Contractor shall assist the Government to develop security requirements for contractual commitments IAW DoD 5220.22-M, AFI 16-1406, and supplements.

Examples include coordination of the DD FM 254, DoD Contract Security Classification Specification, VGSAs, and Security Clauses.

3.1.2 OPSEC / Foreign Government Protection

3.1.2.1 The Contractor shall assist the Government to develop, coordinate, and execute all OPSEC program requirements and Foreign Government Protection requirements for Arnold AFB and AEDC Moffett Field.

3.1.2.2 The Contractor shall develop an OPSEC program plan to address how the Contractor will protect critical and sensitive contracted information IAW AFI 10-701 and Arnold AFB Critical Information and Indicator List IAW AFI 10-701, para 8.2.5.1.

Upon acceptance by the Government, the Contractor shall implement the OPSEC program plan for Arnold AFB and AEDC Moffett Field.

Deliverable

A006 OPSEC Program Plan

3.1.2.3 The Contractor shall include a Foreign National Visitor Control Plan (FNVCP), or additional OPSEC requirements as an annex to the test plan when determined to be necessary or as required for tests performed at Arnold AFB and AEDC Moffett Field.

Coordinate the FNVCP and OPSEC requirements with the Government.

Test Security Plans will be used by the test team and identify all security requirements related to specific test efforts. In order to appropriately access requirements, the Contractor has to gather information from various sources (i.e., pre-test planning meetings, DD FM 254s, security classification guides, program / project managers, customers, etc.) in order to develop an applicable Test Security Plan specific to the program or project. The Contractor should anticipate having to develop approximately 125 Test Security Plans annually.

Test Security Plans that require additional security requirements or protection measures above the established baseline or NISPOM must be reviewed and approved by the Government.

Performance Standards

a) STD: No security compromises or test delays resulting from ineffective security.

b) STD: All FNVCP’s shall be properly marked and logged and controlled for all classified and Controlled Unclassified Information (CUI).

Deliverable

A005 Test Security Plan

3.1.2.4 The Contractor shall conduct OPSEC Foreign National Vulnerability Assessments and Audits for visiting foreign guests and / or customers visiting Arnold AFB and AEDC Moffett Field, IAW DoD 5220.22-M, AFI 16-1406, AFI 10-701, and supplements.

STD: No security compromises or test delays resulting from ineffective vulnerability assessments and audits.

3.1.2.5 The Contractor shall appoint an OPSEC trained person as a Point of Contact (POC) with overall OPSEC responsibilities to maintain awareness of foreign intelligence collection capabilities, limitations, methods, and practices.

The OPSEC POC shall at a minimum successfully complete the OPSEC Analysis and Program Management Course (OPSE-2500): The focus of this course is on the basic skill and knowledge needed to conduct an OPSEC risk analysis (apply the five steps) and to implement an OPSEC program. This course is intended for use by the Department of Defense and other U.S.

Government personnel and Contractors within NISP.

For course registration and information refer to: http://www.cdse.edu/catalog/classroom/OPSE- 2500.html and https://www.iad.gov/ioss/

Performance Standard

STD: Fully integrated OPSEC Support Staff training completed within 30 days of contract start date.

3.1.2.6 The Contractor shall assist the Government program manager in the development and implementation of the Commander’s OPSEC policy and Critical Information and Indicator List IAW AFI 10-701 and supplements.

Performance Standard

STD: Fully integrated OPSEC program execution within 30 days of contract start date.

Deliverable

A006 OPSEC Plan

3.1.2.7 The Contractor shall conduct OPSEC training IAW AFI 10-701.

The Contractor shall familiarize new employees for awareness and conduct refresher sessions needed in the areas of OPSEC and Critical Information.

3.1.2.8 The Contractor shall integrate and include OPSEC into all acquisition programs and Contractor support documents IAW AFI 10-701.

STD: Integrate OPSEC into all acquisition programs and contractor documentation.

Deliverable

A006 OPSEC Plan

3.1.2.8 The Contractor shall coordinate with the Government to resolve / mitigate Web Risk Assessment, Telecommunications Monitoring Assessment Program, Vulnerability Assessment, and other OPSEC assessment findings as required IAW AFI 10-701.

Performance Standard

STD: Conduct OPSEC Web Risk and Vulnerability Assessments monthly.

Deliverable

A006 OPSEC Plan

3.1.2.10 The Contractor shall assist the Government to conduct Staff Assistance Visits with the Government as required or requested IAW AFI 10-701.

The Contractor should anticipate supporting 5-10 Staff Assistance Visits annually; however this may fluctuate depending upon mission needs.

3.1.2.11 The Contractor shall conduct and document OPSEC in all self-assessments and implement required changes when required.

Performance Standard

STD: Include all OPSEC requirements in mid-term self-assessments.

Deliverable

A006 OPSEC Plan

3.1.2.12 The Contractor shall integrate OPSEC into all organization planning, operational processes, acquisition programs, and Contractor support documents.

Recognizing that sub-Contractors vary in size, resources, and length of subcontract, OPSEC programs implemented for subcontractors should be designed to afford at least a minimum level of OPSEC protection and understanding for all subcontracts with increasing levels of OPSEC protection and understanding for more sensitive subcontracts.

3.1.2.13 The Contractor shall comply with the OPSEC measures imposed by any program supported.

Organizations and personnel supporting customers may have OPSEC requirements associated with their activities and support. The following standard expectations are included in all work:

(a) Specific event-oriented activities are supported when directed by the supported program, or comply with the program's OPSEC Plan / Annex.

(b) OPSEC Awareness Education and Duty-Related Training as deemed necessary by the Government or program supported are provided to personnel assigned

(c) OPSEC protective measures (countermeasures) are applied as directed by Government or program sponsors.

Performance Standard

STD: No more than one validated compliant per quarter.

3.1.3 Security Administrative Support

3.1.3.1 The Contractor shall provide security support sufficient to ensure full compliance with DoD, service, and local directives at Arnold AFB and AEDC Moffett Field.

3.1.3.2 The Contractor shall request security clearance investigations for their personnel located at Arnold AFB and AEDC Moffett Field when the Contractor determines that access to classified is essential in the performance of tasks or services related to the fulfillment of the contract.

Requests for Contractor security clearances shall be kept to an absolute minimum necessary to perform contract requirements. The Contractor shall ensure that sufficient personnel have the appropriate security clearance to accomplish all tasks specified in this PWS prior to the performance start date.

Performance Standard

STD: 100% of all security investigations shall be reviewed for quality and completeness prior to submission to minimize delays with processing.

3.1.3.2.1 The Contractor shall ensure potential candidates for hire have been properly vetted prior to submitting a federal investigation or offering them a position at Arnold AFB or AEDC Moffett Field to ensure the candidate can obtain and maintain access to classified, CUI, and / or base access.

The Government’s intent is to reduce the amount of costly investigations for those who could not likely acquire or maintain access to Government facilities / information and to ensure only the highest quality of personnel are admitted onto AEDC based on their behavioral / criminal history.

Performance Standard

STD: 100% of potential candidates shall be sufficiently pre-vetted to ensure the candidate can obtain and maintain access to potential classified, CUI and base access.

3.1.3.2.2 The Contractor shall review Joint Personnel Adjudication System (JPAS) or the program replacing JPAS daily to obtain relevant security clearance and investigation information pertaining to present and future AEDC affiliated personnel performing classified work at Arnold AFB, AEDC Moffett Field, and other personnel in whom the AEDC has a security interest.

Performance Standard

STD: 100% of personnel security clearances shall be reviewed prior to gaining access to classified and / or controlled and restricted areas managed by the Contractor.

3.1.3.2.3 The Contractor shall process Homeland Security Policy Directive 12 and other “Position of Trust” investigative requests for all Arnold AFB and AEDC Moffett Field Government Contractor personnel through the AEDC Government Personnel Security Program Manager IAW AFI 31-501 or AFI 16-1405.

The Contractor should anticipate processing ~125 Tier 1 investigative requests annually.

Investigative requests and supporting documentation (Standard Form 85) are required for any new AEDC Contractor personnel without a U.S. security clearance or other required background investigation for base / facility access and / or access to unclassified U.S. Government computers.

Performance Standard

STD: 100% of all security investigations shall be reviewed for quality and completeness prior to submission to minimize delays with processing.

3.1.3.2.4 The Contractor shall provide electronic fingerprint services, required for official Government business, to all Government Contractors located at Arnold AFB requiring a background investigation. The Contractor will ensure Government Contractors located at AEDC Moffett Field can obtain fingerprint services at or near the immediate area.

The Contractor should anticipate processing ~300 fingerprints annually. Contractor fingerprint services shall be provided to the Government in the rare event the Governments fingerprinting equipment fails to operate. Fingerprinting equipment will be provided as Government Furnished Property (GFP).

Performance Standard

STD: Zero Rejection Rate. (All fingerprints submitted must be deemed classifiable and acceptable by Office of Personnel Management (OPM), Federal Bureau of Investigation (FBI), etc.). Exceptions would be evaluated on a case-by-case basis, e.g. mechanical or physical disfigurations.

AQL: No more than a 5% Rejection Rate. (95% of all fingerprints submitted must be deemed classifiable and acceptable by OPM, FBI, etc.)

3.1.3.2.5 The Contractor shall provide a copy of all adverse information reports submitted to DSS IAW NISPOM 1-300, 301, 302, 303 and 304 to the Installation Commander via the SSA. Incident reports shall also be entered in the JPAS or the program replacing JPAS.

Reports required to be submitted to the FBI, IAW NISPOM 1-301, shall also be reported to the local detachment of The AF Office of Special Investigations. The Contractor shall report all adverse information concerning SAP briefed personnel to the PSO IAW DoDM 5205.07, Volumes 1-4 and the JSIG. Report all adverse information concerning SCI indoctrinated personnel to the AEDC Special Security Officer.

Performance Standards

a) STD: No programmatic impacts from adverse personnel suitability issues.

b) STD: Score / Achieve no less than a Satisfactory rating on Inspections.

3.1.3.2.6 The Contractor shall use the JPAS or the program replacing JPAS for transmitting / receiving visit requests and to properly identify the security clearance level of visitors (to include test customers) performing at Arnold AFB and AEDC Moffett Field, IAW DoD 5220.22-M, DoDM 5200.01, Vol. 1-4, AFI 16-1404, AFI 16-1406, and supplements.

3.1.3.3 The Contractor shall implement an Insider Threat program at Arnold AFB and AEDC Moffett Field, IAW guidance and standards developed by the Insider Threat Task Force established in section 6 of EO 13587 DoD Instruction (DoDI) 5240.26 and AFI 16- 1402. The Program shall be designed to identify employees that have access within their closed and restricted areas, displaying potential espionage indicators. Adverse behavior which might indicate a potential threat to national security shall be reported as required IAW DoD 5220.22-M, AFI 31-501, and AFI 16-1406, and supplements.

For the purposes of the NISPOM, insider threat refers to the threat of an insider using his or her authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the U.S. through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of Government, company, contract or program information, resources or capabilities.

Performance Standards

a) STD: No programmatic impacts from personnel suitability issues.

b) STD: Score / Achieve no less than a Satisfactory rating on Inspections.

3.1.3.3.1 The Contractor shall establish and foster Counterintelligence (CI) focused culture at Arnold AFB and AEDC Moffett Field, for all personnel having access within their closed and restricted areas in order to detect, deter, and expeditiously report suspicious activities.

Performance Standards

a) STD: No security compromises or test delays resulting from ineffective security.

b) STD: Instructions will be available to all personnel within these areas that describe the proper way to mark, log, and control all classified and Controlled Unclassified Information.

Deliverable

A005 Test Security Plan

3.1.3.3.2 The Contractor shall control media and information located at Arnold AFB and AEDC Moffett Field, IAW the respective classification level and security classification guides.

Performance Standard

STD: All controlled media shall be located and retrieved within 24 hours or as required.

3.1.3.3.3 The Contractor shall brief all appropriate test support personnel located at Arnold AFB and AEDC Moffett Field on the requirements of the Test Security Plan or Program Protection Plan.

3.1.3.3.4 The Contractor shall ensure that each Government, Contractor, or subcontractor employee located at Arnold AFB and AEDC Moffett Field completes Program Protection Awareness Training when required in the respective Program Protection Plan.

Critical Program Information (CPI) Training is specific to the protection of sensitive and CPI. If CPI exists, it will be identified in the Program Protection Plan provided by the Government Program Office. The Government will provide the basic training plan to be tailored for each facility handling / storing / processing identified CPI.

Performance Standards

a) STD: Zero security violations.

b) STD: 100% of personnel supporting a test are trained prior to performing any work related to identified CPI.

3.1.3.3.5 The Contractor shall provide the Government vault / safe inspections and schedule periodic maintenance as required IAW AFI 16-1404 and DoD 5220.22-M.

3.1.3.3.6 The Contractor shall establish liaison with local CI and law enforcement organizations to determine the status of the local threat to the facility, personnel, and supported programs. Inform the Government of threats or any other information required IAW DoD 5220.22-M, AFI 10-701, AFI 16-1404, AFI 31-501, AFI 16-1405, AFI 16-1406, and supplements.

The Contractor shall engage with local CI and law enforcement organizations located at or near AEDC Moffett Field and provide feedback and advice to the acting Government director.

3.1.3.3.7 The Contractor shall support Government security managers with conducting and documenting specialized security initiatives, training and briefings IAW DoD 5220.22-M, AFI 10-701, AFI 16-1404, AFI 31-501, AFI 16-1405, AFI 16-1406, and supplements.

Performance Standard

STD: Assist with at least one security initiative per…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.