About this file

Draft Task Order 1 Section C

View the file

Other files for this federal contract opportunity

Other files attached to US Cyber Command (USCYBERCOM) Multiple Award Indefinite Delivery/Indefinite Quantity (MA IDIQ): Advanced Notice, newest first.
File Type Posted
DRAFT_EVALUATION_FACTORS.pdf PDF
UPDATED_Due_Diligence_Experience_Reference_Attachment.docx DOCX document
USCYBERCOM_AdvanceNotice_Cover_Letter.pdf PDF
Draft_Labor_Category_Descriptions.pdf PDF
Draft_RFP_Section_C H.pdf PDF
Due_Diligence_Experience_Reference_Attachment.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Task Order DRAFT Section C

Indefinite Delivery Indefinite Quantity (IDIQ)

United States Cyber Command (USCYBERCOM)

DRAFT Task Order:

Section C

Cyberspace Operations Support Services

TASK ORDER – DRAFT STATEMENT OF WORK

Task Order DRAFT Section C C-1

C.1 BACKGROUND

United States Cyber Command (USCYBERCOM) requires contractor support to assist its vital mission. USCYBERCOM plans, coordinates, integrates, synchronizes, and conducts activities to direct the operations and defense of specified Department of Defense (DOD) information networks, to prepare, and when directed, conduct full-spectrum military cyberspace operations to enable actions in all domains, and to ensure United States (US)/Allied freedom of action in cyberspace and deny the same to our adversaries.

The Command is charged with pulling together existing cyberspace resources, creating synergy that does not currently exist and synchronizing war-fighting effects to defend the information security environment.

USCYBERCOM centralizes command of cyberspace operations, strengthens DOD cyberspace capabilities, and integrates and bolsters DOD’s cyber expertise. Consequently, USCYBERCOM improves DOD’s capabilities to ensure resilient, reliable information and communication networks, counter cyberspace threats, and assure access to cyberspace.

USCYBERCOM’s efforts will also support the Armed Services’ ability to confidently conduct high-tempo, effective operations as well as protect command and control systems and the cyberspace infrastructure supporting weapons system platforms from disruptions, intrusions and attacks.

USCYBERCOM is a sub-unified command subordinate to U. S. Strategic Command

(USSTRATCOM). The Cyber Mission Force (CMF) is a USCYBERCOM Joint Force

Headquarters (JFHQ) and the US military’s first joint tactical command with a dedicated mission focused on cyberspace operations: to plan, direct and synchronize cyberspace operations to deter, deny, and if necessary, defeat adversary cyber actors to defend the nation.

The USCYBERCOM Directorate of Operations (J3) establishes and provides cyber warfare capabilities to meet both deterrent and defensive National Security objectives. The J3 optimizes planning, integration, coordination, execution and force management of the cyber warfare mission in support of the Joint warfighter. The J3 provides situational awareness of adversary attack opportunities and exercises operational and tactical control of cyber forces and capabilities, as directed. The J3 is organizationally divided into a Current Operations and Future

Operations construct. Current Operations encompasses operating and defending the DOD

Information Network (DODIN) and includes the Fires & Effects Division, which manages both the Joint Fires Process and the Joint Targeting Cycle and is responsible for publishing of a daily

Cyberspace Tasking Order via the CYBERCOM Command and Control portal. Future

Operations spans planning for a range of potential activities from those impacting DOD information networks to those with regional and/or global implications.

Task Order DRAFT Section C C-2

C.2 SCOPE

This Task Order (TO) will provide Cyber Operations support services to USCYBERCOM J3

Directorate. This TO falls within the scope of the following IDIQ task areas:

a. Cyberspace Operations

b. Cyberspace Planning

c. Cyberspace Training & Exercises

d. Strategy/Policy/Doctrine Development and Campaign Assessments

e. Information Technology/Communications (IT/Comms)

f. Business Administration

g. Engagement Activities

Key Tasks to be performed within the scope of this TO include but are not limited to:

a. Provide Mission Essential coverage to support cyberspace operations

b. Identify requirements and concepts of operation (CONOPS) that focus on the execution of DODIN Operations and Defensive Cyberspace Operations Internal Defensive

Measures (DCO-IDM) and assist in the development, synchronization, integration and assessment of operational standards in support of achieving the Joint Information

Environment (JIE) end-state

c. Contribute to efforts to secure, operate and defend the DODIN and its critical dependencies in order to provide full spectrum cyberspace operations ensuring freedom of maneuver in that domain and denying our adversaries the same

d. Contribute to USCYBERCOM strengthening relationships with key partner nations, coordinating, synchronizing, deconflicting, and integrating operational planning efforts for full spectrum cyberspace operations

e. Plan, coordinate, and deconflict Offensive Cyber Operations (OCO), Defensive Cyber

Operations (DCO), DODIN Operations throughout the entire Joint Operational Planning

Process (JOPP)

f. Identifies gaps with pairing capabilities against targets to achieve an effect in accordance with tactical objectives, operational goals, and strategic end-states

g. Prepare Courses of Action (COAs), to include Advanced level targeting, capabilities pairing, and Operational Assessments.

C.3 OBJECTIVE

The Objectives of this TO are as follows:

a. Define and analyze cyberspace capabilities needed and cyberspace operations to meet both deterrent and decisive National Security objectives;

b. Conduct planning, integration, coordination, and execution, of the cyberspace operations mission in support of the Joint warfighter; and

c. Receive, track, and resolve cyber issues and provide input to the Commander situational awareness reports of cyberspace operations.

Task Order DRAFT Section C C-3

C.4 TASKS

C.4.1 TASK 1 – PROVIDE PROGRAM MANAGEMENT

The contractor shall provide program management support under this TO. This includes the management and oversight of all activities performed by contractor personnel, including subcontractors, to satisfy the requirements identified in this Performance Work Statement

(PWS). The contractor shall identify a Program Manager (PM) by name who shall provide management, direction, administration, quality assurance, and leadership of the execution of this

TO.

C.4.1.1 SUBTASK 1.1 – COORDINATE A PROJECT KICK-OFF MEETING

The contractor shall schedule, coordinate, and host a Project Kick-Off Meeting (Section F, to be provided at time of solicitation release) at the location approved by the Government. The meeting will provide an introduction between the contractor personnel and Government personnel who will be involved with the TO. The meeting will provide the opportunity to discuss technical, management, and security issues, and travel authorization and reporting procedures. At a minimum, the attendees shall include Key contractor Personnel, representatives from the directorates, other relevant Government personnel, and the FEDSIM COR. The contractor shall provide a Kick-Off Agenda and Kick-Off Meeting Presentation (Section F, to be provided at time of solicitation release) that shall provide, at a minimum, the following type of information:

1. Introduction of team members and personnel:

a. Roles and Responsibilities. Include staffing plan and project organization

b. Overview of the contractor organization to support varying locations of work.

2. Communication Plan/Lines of communication overview (between both the contractor and

Government)

3. Approach to reaching proposed staffing levels to allow for operational support for time constraint occurrences identified in Section C.4.1.9, Transition-In Plan.

4. TO Management:

a. Overview/outline of the Project Management Plan (PMP)

b. Overview of project tasks

c. Overview of the Quality Control Program

d. TO logistics

5. TO Administration:

a. Review of Government-furnished information and equipment (GFI/GFE)

b. Invoice review and submission procedures

c. Travel notification and processes

d. Security requirements/issues/facility/network access procedures

e. Sensitivity and protection of information

f. Reporting requirements, e.g., Monthly Status Report (MSR)

6. Additional administrative items.

Task Order DRAFT Section C C-4

The contractor shall draft and provide a Kick-Off Meeting report (Section F, to be provided at time of solicitation release) in accordance with Section C.4.1.7, Prepare Meeting Reports, documenting the Kick-Off Meeting discussion and capturing any action items.

C.4.1.2 SUBTASK 1.2 – PREPARE A MONTHLY STATUS REPORT (MSR)

The contractor shall develop and provide an MSR (Section J, to be provided at time of solicitation release) using Microsoft (MS) Office Suite applications, by the tenth of each month via electronic mail to the Technical Point of Contact (TPOC) and the COR. The MSR shall include the following:

a. Activities during reporting period, by task (include: on-going activities, new activities, activities completed; progress to date on all above mentioned activities). Start each section with a brief description of the task.

b. Problems and corrective actions taken. Also include issues or concerns and proposed resolutions to address them.

c. Personnel gains, losses, and status (security clearance, etc.).

d. Government actions required.

e. Summary of trips taken, conferences attended, etc. (attach Trip Reports to the MSR for reporting period).

f. Accumulated invoiced cost for each CLIN up to the previous month.

g. Projected cost of each CLIN for the current month.

The MSR shall be prepared in accordance with the sample provided in Section J (to be provided at time of solicitation release).

C.4.1.3 SUBTASK 1.3 – CONVENE TECHNICAL STATUS MEETINGS

The contractor PM shall convene a monthly Technical Status Meeting with the TPOC, COR, and other Government stakeholders. The purpose of this meeting is to ensure all stakeholders are informed of the monthly activities and MSR, provide opportunities to identify other activities and establish priorities, and coordinate resolution of identified problems or opportunities. The contractor PM shall provide minutes of these meetings, including attendance, issues discussed, decisions made, and action items assigned, to the COR within five workdays following the meeting.

C.4.1.4 SUBTASK 1.4 – PREPARE A PROJECT MANAGEMENT PLAN (PMP)

The contractor shall document all support requirements in a PMP. The contractor shall prepare and deliver a Final PMP (Section F, The MSR shall be prepared in accordance with the sample provided in Section J.1, Attachment B - Monthly Status Report Template.

The PMP shall contain at a minimum the following:

a. Describe the proposed management approach.

b. Contain detailed Standard Operating Procedures (SOPs) for all tasks.

c. Include milestones, tasks, and subtasks required in this TO.

d. Provide for an overall Work Breakdown Structure (WBS) and associated responsibilities and partnerships between Government organizations.

Task Order DRAFT Section C C-5

e. Include the contractor’s Quality Control Plan (QCP)

The contractor shall provide the Government with a draft PMP (Section F, to be provided at time of solicitation release) on which the Government will make comments. The final PMP shall incorporate the Government’s comments.

C.4.1.5 SUBTASK 1.5 – UPDATE THE PROJECT MANAGEMENT PLAN (PMP)

The PMP is an evolutionary document that shall be updated annually at a minimum (Section F, to be provided at time of solicitation release). The contractor shall work from the latest

Government-approved version of the PMP.

C.4.1.6 SUBTASK 1.6 – PREPARE TRIP REPORTS

The contractor shall submit a Trip Report (Section F, to be provided at time of solicitation release), as requested by the TPOC and/or FEDSIM COR. The contractor shall submit Trip

Reports three working days after completion of a trip for all long-distance travel. The Trip

Report shall include the following information:

a. Personnel traveled

b. Dates of travel

c. Destination(s)

d. Purpose of trip

e. Summarized cost of the trip

f. Approval authority

g. Summary of action items and deliverables

The contractor shall keep a historical summary/spreadsheet of all long-distance travel, to include, at a minimum, the name of the employee, location of travel, duration of trip, and trip estimate.

Trip reports shall at minimum be prepared with the information in the sample provided in

Section J, to be provided at time of solicitation release.

C.4.1.7 SUBTASK 1.7 – PREPARE MEETING REPORTS

The contractor shall prepare and submit Meeting Reports (Section F, to be provided at time of solicitation release), as requested by the TPOC and/or FEDSIM COR, to document results of meetings. The Meeting Report shall include the following information:

a. Meeting attendees and their contact information – at minimum identify organizations represented

b. Meeting dates

c. Meeting location

d. Meeting agenda

e. Purpose of meeting

Task Order DRAFT Section C C-6

f. Summary of events (issues discussed, decisions made, and action items assigned).

C.4.1.8 SUBTASK 1.8 – UPDATE QUALITY CONTROL PLAN (QCP)

The contractor shall update the QCP submitted with their proposal (Section F, to be provided at time of solicitation release), and provide a final QCP (Section F, to be provided at time of solicitation release) as required in Section F. The contractor shall periodically update the QCP, as required in Section F, as changes in program processes are identified (Section F, to be provided at time of solicitation release).

C.4.1.9 SUBTASK 1.9 - TRANSITION-IN

The contractor shall ensure that there will be minimum service disruption to vital Government business and no service degradation during and after transition. All transition activities will be completed 90 of days after approval of final Transition Plan (Section F, to be provided at time of solicitation release) contractor shall propose a draft Transition-In Plan within five workdays of award.

For the purposes of this TO, staffing is defined as the submission of current, accurate, and complete Security In-Process (SIP) forms on individuals with an active Top Secret

(TS)Clearance with Sensitive Compartmented Information (SCI) eligibility (within scope – five years) and a current adjudicated counter-intelligence (CI) polygraph (within scope – seven years) to the USCYBERCOM Staff Security Office (SSO). If inaccuracies are identified the forms will be rejected by the USCYBERCOM SSO and resubmission may be required. The Government shall not be held responsible for inaccurate or inconsistent SIP forms that delays staffing. For tracking purposes, the COR shall be copied on all final or updated SIP form submissions to the

USCYBERCOM SSO. The transition-in plan shall describe a solution for attaining the following minimum staffing levels:

a. All TO Positions: All TO requirements require 50% staffing at award and 100% staffing within 60 days. The apportionment of the appropriate staff, until reaching full staffing level at 100%, shall be coordinated with, and approved by, the COR.

b. During the transition-in period, the contractor shall prepare to meet all TO requirements and ensure all incoming personnel are trained and qualified to perform no later than the full performance start date.

c. During the transition-in period, the contractor’s personnel shall interface with

Government personnel and other contractor personnel for purposes of transferring knowledge, lessons learned, and continuity of information and documents for the commencement of performance.

d. When optional or surge support services are executed, the requirements require 50% staffing upon receipt of funding and 100% staffing within 60 days. The apportionment of the appropriate staff, until reaching full staffing level at 100%, shall be coordinated with, and approved by, the COR.

All facilities, equipment, and materials to be utilized by the contractor personnel during performance of the TO after the full performance start date will be accessible to contractor personnel during the transition-in period. The contractor shall implement its Transition-In Plan

Task Order DRAFT Section C C-7 no later than (NLT) ten calendar days after award (Section F, to be provided at time of solicitation release).

C.4.1.10 SUBTASK 1.10 -TRANSITION-OUT

The Transition-Out Plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor/Government personnel at the expiration of the TO. The contractor shall provide a Transition-Out Plan (Section F, to be provided at time of solicitation release) NLT 90 calendar days prior to expiration of the TO. The contractor shall identify how it will coordinate with the incoming contractor and/or Government personnel to transfer knowledge regarding the following:

a. Project management processes

b. Points of contact

c. Location of technical and project management documentation

d. Status of ongoing technical initiatives

e. Appropriate contractor to contractor coordination to ensure a seamless transition

f. Transition of Key Personnel

g. Schedules and milestones

h. Actions required of the Government.

The contractor shall also establish and maintain effective communication with the incoming contractor/Government personnel for the period of the transition via weekly status meetings.

The contractor shall implement its Transition-Out Plan no later than (NLT) 90 calendar days prior to expiration of the TO (Section F, to be provided at time of solicitation release). All facilities, equipment, and material utilized by the contractor personnel during performance of the

TO shall remain accessible to the contractor personnel during the transition-out period pursuant to the applicable security in-processing and out-processing guidelines.

C.4.2 TASK 2 – PROVIDE CYBERSPACE OPERATIONS SUPPORT

Task Order DRAFT Section C C-8

The contractor shall provide cyberspace operations support. Cyberspace operations support includes operational requirements development, gap analysis activities, operations orders process, operations assessment process, and critical technical research and analysis as described below:

A. Operational Requirements Development

The contractor shall assist in identifying requirements and making recommendations for the prioritization of requirements for development. The contractor shall support USCYBERCOM’s requirements process through facilitation of and participation in requirement boards and working group activities.

B. Gap Analysis Activities

The contractor shall support gap analysis activities by comparing, documenting, and reporting shortfalls in proposed cyber capabilities. The contractor shall assess how well the capability meets the requirement, document any gaps that may exist, and ensure that the capability aligns with DOD and cyber policy and meets the intent of the development objective or capability. The contractor shall provide written documentation to address areas of concern for shortfalls and recommended courses of action (COAs).

C. Operations Orders Process

The USCYBERCOM J3 is responsible for the USCYBERCOM orders development process, as well as ensuring plans and orders are feasible, acceptable, and compliant with USCYBERCOM guidance and doctrine. J3 facilitates the transition of plans to orders by developing, implementing, and managing the operational orders process. The Operations Orders (OPORDs) team serves as the focal point for all inbound and outbound orders routed through

USCYBERCOM.

The contractor shall perform the following operations orders process support:

a. Develop, coordinate, and maintain USCYBERCOM orders and directives;

b. Coordinate and collaborate on draft orders and directives from external partners, as required.

c. Gather and prepare supporting documentation, coordinate drafts, obtain approval, and provide the final documents for publishing.

d. Update orders and directives based upon evolving cyberspace environments;

e. Assist Action Officers with orders process in accordance with the USCYBERCOM

Orders Operating Instruction.

f. Advise USCYBERCOM leadership on all aspects of orders processing.

D. Operational Assessment Process

The operational assessments process feeds the USCYBERCOM Commander’s decision cycle, helping to determine the results of tactical actions in the context of overall mission objectives

Task Order DRAFT Section C C-9 and providing potential recommendations for the refinement of future plans. Operational assessments provide the Commander with the current state of the operational environment, the progress of the campaign or operation, and recommendations to account for discrepancies between the actual and predicted progress.

The contractor shall perform the following operations assessment process support:

a. Develop, analyze, and update metrics to assess J3 operational performance and effectiveness.

b. Incorporate metrics into a strategic assessment process;

c. Maintain a repository of Measures of Performance (MOPs) and Measures of

Effectiveness (MOEs) metric results.

d. Continuously monitor and provide updates to a current situation within the construct of an operation and the progress of that operation.

e. Evaluate an operation against MOEs and MOPs to determine progress relative to the mission objectives and end states.

f. Develop recommendations and guidance to the USCYBERCOM Technical Points of

Contact (TPOCs) and/or the Commander for improvement in the operation to help drive the Commander’s decision cycle.

E. Critical Technical Research and Analysis

The contractor shall conduct critical and technical research and analysis to define Commander’s

Critical Information Requirements (CCIR), Priority Intelligence Requirements (PIR), and

Essential Elements of Friendly Information (EEFI) for reporting cybersecurity incidents.

C.4.2.1 SUBTASK 2.1 – PROVIDE DODIN OPERATIONS SUPPORT

DODIN Operations conducts global, operational planning to secure, operate and defend the

DODIN and its critical dependencies in order to provide full spectrum cyberspace operations ensuring freedom of maneuver in that domain and denying our adversaries the same. The contractor shall provide subject matter expertise in DODIN operations, cyber defense, tactics, techniques and procedures (TTP) and systems, cyberspace operations community architecture, current and emerging cyber threats, and potential offensive and defensive capabilities for countering cyber threats. Additionally, the contractor shall provide subject matter expertise in electronic communications concepts to include the systems development life cycle, equipment specifications, network management, and analytical techniques.

The contractor shall provide the following DODIN operations support:

a. Analyze boundary protection statistics as provided by the Defense Information Systems

Agency (DISA) and/or other organizations, and report issues to USCYBERCOM leadership.

b. Publicize the current defense policy to the DOD community and evaluate requests for boundary defense policy changes or exceptions from applicable staff elements, Joint

Forces Head Quarters (JFHQs), subordinate headquarters, Service Cyber components, CCMD, components and agencies with cyber related missions.

Task Order DRAFT Section C C-10

c. Conduct research and produce reports and presentations that focus on rapidly emerging cyber threats and cyber adversary TTP. Conduct proof of concept development of cyber capabilities for countering ongoing or impending cyber adversary actions against US

Government networks.

d. Recommend TTPs for countering cyber threats.

C.4.2.1.1 – PROVIDE INFORMATION NETWORK DEFENSE

Information network defense is responsible for identifying and integrating network defense requirements into programs and projects that execute the “operate and defend” aspect of

USCYBERCOM’s mission. The contractor shall provide telecommunications, networking, and

DOD network design subject matter expertise.

The contractor shall provide the following information network defense support:

a. Monitor testing of systems, plan and direct Rehearsal of Concept (ROC) drills in coordination with DISA and applicable USCYBERCOM J-Directorates, JFHQs, subordinate headquarters, Service Cyber components, Combatant Command (CCMD), components and agencies with cyber related missions (as required) in efforts to validate operational procedures throughout the development of new defensive tools, including,but not limited to: Email Security Gateway from before Initial Operational Capability (IOC) to Full Operational Capability (FOC).

b. Coordinate with applicable USCYBERCOM J-Directorates, JFHQs, subordinate headquarters, Service Cyber components, CCMD, components and agencies with cyber related missions to identify, assess, and develop effective options for cyberspace defense strategies.

c. Support DCO planning, CONOPS development, and mission execution through expert knowledge of USCYBERCOM components, infrastructure, processes, capabilities, authorities, and partner operations.

d. Provide expert information and recommendations to applicable USCYBERCOM J-

Directorates, JFHQs, subordinate headquarters, Service Cyber components, CCMD, components and agencies with cyber related missions to support implementation of strategies and plans.

e. Coordinate and collaborate with partners and stakeholders to ensure seamless integration of services, systems, and networks into existing and future joint DODIN infrastructure.

f. Coordinate with applicable USCYBERCOM J-Directorates, JFHQs, subordinate headquarters, Service Cyber components, CCMD, components and agencies with cyber related missions to identify, assess, develop, and codify across the enterprise a common

Cyber Key Terrain (C-KT) Program.

g. Conduct research and produce reports and presentations that focus on rapidly emerging cyber threats and cyber adversary TTP.

C.4.2.1.2 - PROVIDE PLATFORM INFORMATION TECHNOLOGY (PIT)-CONTROL

SYSTEMS (CS) SUPPORT

USCYBERCOM coordinates securing and defending DOD-owned PIT-CS as required to keep the operational environment safe, secure, and resilient against current and emerging cyber

Task Order DRAFT Section C C-11 threats. The contractor shall provide subject matter expertise in PIT-CS cybersecurity threats and vulnerabilities, and on current safeguards for CS.

The contractor shall provide the following PIT-CS support:

a. Guidance on PIT-CS incident prevention, information, and analysis.

b. Input to organizational policies and procedures related to PIT-CS incident response.

c. Analyze the operational impacts of PIT-CS incidents and provide the information to the applicable DOD organization.

d. Create and participate in test PIT-CS incident response plans.

e. Participate, assist, and advise various Operational Planning Groups (OPGs) and

Operational Planning Teams (OPTs) by providing functional expertise and guidance on

PIT- CS incidents.

f. Develop after action reports for post-PIT-CS assessment and incident response activities.

g. Gather forensic information to support PIT-CS incident analysis.

h. Recommend safeguards to prevent PIT-CS intrusions.

i. Remediate PIT-CS after an incident.

j. Conduct research and produce reports and presentations that focus on rapidly emerging cyber threats and cyber adversary TTP.

C.4.2.1.3 – PROVIDE MOBILE DEFENSE OPERATIONS

The USCYBERCOM J3 must understand the threat from mobile devices that house distributed sensitive data storage and access mechanisms, lack consistent patch management and firmware updates, and have a high probability of being hacked, lost or stolen. Mobile phones and tablets have become critical systems for a wide variety of production applications from enterprise resource planning (ERP) to project management. The contractor shall provide subject matter expertise on hardware and software, security tools for mobile systems, common mobile exploit methods, and wireless network analysis tools for identifying and exploiting wireless networks used by mobile devices.

The contractor shall provide the following mobile defense operations support:

a. Conduct analysis of post-forensic reports and research of compromised mobile devices on the DODIN and provide recommendations for mitigation and planning.

b. Conduct security assessments of mobile applications for use on the DODIN and platforms.

c. Participate, assist, and advise various OPGs and OPTs by providing functional expertise and guidance on mobile devices.

d. Coordinate with applicable USCYBERCOM J-Directorates, JFHQs, subordinate headquarters, Service Cyber components, CCMD, components and agencies with cyber related missions to identify, assess, and develop effective options for mobile defense strategies.

Task Order DRAFT Section C C-12

e. Conduct research and produce reports and presentations that focus on rapidly emerging

C.4.2.2 SUBTASK 2.2 – PROVIDE INTERNATIONAL/NATIONAL CYBERSPACE

OPERATIONS SUPPORT

The USCYBERCOM J3 conducts activities in support of the various CCMDs, including strengthening relationships with key partner nations, coordinating, synchronizing, deconflicting, and integrating operational planning efforts for full spectrum cyberspace operations.

The contractor shall provide the following international/national cyberspace operations support:

a. Communicate complex programmatic cyber planning information, orally and in writing, to elicit understanding and support from professional peers and non-specialists.

b. Contribute to the development and refinement of COAs and other Cyber guidance materials utilized by the Command and its external Cyber program partners.

c. Evaluate national/international operations and recommend opportunities for

USCYBERCOM to execute authorities to meet DOD Cyber objectives.

d. Provide expert information and recommendations to applicable USCYBERCOM J-

Directorates, JFHQs, subordinate headquarters, Service Cyber components, CCMD, components and agencies with cyber related missions to support implementation of strategies and plans.

e. Assist and advise various OPGs and OPTs by providing functional expertise and guidance as to the intent of negotiated and established national/international agreements.

f. Participate in post-event analyses to determine the success of Cyber strategies, initiatives, or plans.

g. Attend strategic working group meetings, facilitate discussions, gather information, analyze the data, and produce written products in support of USCYBERCOM’s force management efforts.

h. Review and provide feedback on cyber related strategy, policy, and doctrine received from higher headquarter(s).

i. Report on evolving cyberspace policy trends and issues within the US Government

j. Review and evaluate cyberspace policy directives and CONOPs.

k. Assist with responses to Congressionally Directed Actions (CDA) and Congressional

Questions for the Record (QFR).

l. Provide input to the JQRR submission for USCYBERCOM.

m. Provide support with technical and policy analyses of cyber issues.

n. Attend conferences, seminars, and special meetings as identified by the Government.

o. Contribute to the Office of the Secretary of Defense (OSD) and

USSTRATCOM/USCYBERCOM policies and directives on cybersecurity and internet access.

p. Provide substantive input in converting cybersecurity policies into operational plans for defense of the DODIN, as well as maintain a set of detailed options and filtering/defense policies for expected DODIN operations and defense scenarios, attacks, and changes in DODIN defensive posture.

Task Order DRAFT Section C C-13

q. Assist in advocating USCYBERCOM cyberspace policy and doctrine within the

DOD and across the US Government through the Joint Interagency Coordination

Group (JIACG). Provide analysis, recommendations, and guidance on cyberspace policy.

r. Assist in establishing USCYBERCOM engagement through a JIACG and provide representation to policy and doctrine forums of the DOD.

s. Recommend policy for the deconfliction of military cyberspace operations with other

US Government organizations, specified partners, and allies as necessary.

C.4.2.3 – SUBTASK 2.3 PROVIDE JIE OPERATIONS SPONSOR GROUP (JOSG)

OPERATIONS SUPPORT

The JIE effort will realign, restructure, and modernize how the DOD IT networks and systems are constructed, operated, and defended. JIE will consolidate and standardize the design and architecture of the DOD’s networks to improve mission effectiveness, increase cybersecurity, and optimize resources and IT efficiencies. USCYBERCOM leads the JOSG, which serves as the operational sponsor for the JIE. The JOSG is responsible for developing, integrating, and synchronizing operational procedures in support of the JIE initiative. The JOSG follows the direction of the JIE Planning and Coordination Cell (PCC) and updates the JIE Executive

Committee through the PCC.

The contractor shall provide the following JOSG operations support:

a. Develop operational artifacts required to support delivery of JIE.

b. Support the JIE Technical Synchronization Office (JTSO) in identifying gaps and overlaps across existing DODIN Operations (OPS) and DCO technical capabilities

c. Assess and deconflict JIE with DODIN OPS and DCO, and provide recommendations to align DODIN planning efforts with JIE.

d. Assist in the development and refinement of the JIE Command and Control (C2)

Construct and the JIE Operational CONOPs

e. Develop, integrate, and maintain operational TTPs and Standard Operating Procedures

(SOPs) in support of the JIE.

f. Coordinate and collaborate with JTSO and the USCYBERCOM Command, Control, Communications, Computers & Information Technology (C4IT) Directorate (J6) to ensure seamless integration of services, systems, and networks into existing and future joint DODIN infrastructure

g. Assess and recommend network management policies and procedures for implementation in JIE in coordination with JIE partners, stakeholders, and the C4IT Directorate.

h. Organize, coordinate, and participate in JOSG working groups and other JIE workshop type of events.

i. Develop, staff, and maintain accurate USCYBERCOM orders and directives.

j. Develop and conduct update briefs, presentations, and papers to USCYBERCOM leadership to ensure situational awareness and status are conveyed related to the assigned project areas.

Task Order DRAFT Section C C-14

C.4.2.3.1 - PROVIDE JOSG REQUIREMENTS SUPPORT

The JOSG is responsible for developing the operational requirements needed to drive the implementation of JIE. The JOSG tracks the requirements from creation to implementation.

The contractor shall provide the following JOSG requirements support:

a. Coordinate with JIE stakeholders to identify JIE operational requirements.

b. Develop recommended prioritization and sequencing of JIE operational capability implementation and transition.

c. Ensure capabilities align with DOD governing policies and meet the intent of the development objective or capability.

d. Analyze proposed capabilities, recommend COAs, and develop solutions to address areas of concern for shortfalls in JIE implementation.

e. Develop processes and procedures to implement and ensure JIE operational requirements are met DOD wide.

f. Identify DODIN Operations and DCO enterprise management tool requirements and evaluate operational standards and tools for use within JIE.

g. Coordinate with JIE stakeholders to advise and assist with the planning and identification of cyber defense requirements associated with JIE operational requirements.

C.4.2.3.2 - PROVIDE JOSG OPERATIONS COMPLIANCE AND IMPLEMENTATION

SUPPORT

The JOSG is responsible for shaping operational performance metrics for JIE and tracking JIE implementation and ensuring compliance with established standards.

The contractor shall provide the following JOSG operations compliance and implementation support:

a. Coordinate with DOD Chief Information Officer (CIO) and other stakeholders to develop, distribute, and sustain operational metrics for the JIE.

b. Track all DOD components’ compliance with JIE MOEs/MOPs and applicable DOD JIE policies.

c. Devise methods to test and evaluate each component’s compliance with JIE requirements and all other applicable standards.

d. Develop and maintain processes, procedures, and TTPs for the Operations Center accreditation process.

e. Develop and monitor JIE Service Level Agreement (SLA) performance and metrics.

f. Provide evaluation results, reports, and recommendations to USCYBERCOM and JIE leadership.

g. Support defensive cyber operations planning and mission execution through expert knowledge of USCYBERCOM components, processes, capabilities, authorities, and partner operations.

h. Analyze and evaluate voice/video/data system solutions and provide support for joint full spectrum (terrestrial and space) system and network integration in the JIE.

C.4.2.4 – SUBTASK 2. 4 – PERFORM CYBER FIRES PLANNING AND ANALYSIS

Task Order DRAFT Section C C-15

Cyber fires planning and analysis supports planning in OCO and DCO throughout the entire

Joint Operations Planning Process (JOPP). Cyber fires planning and analysis requires the coordination of joint strategic and operational planning and execution of joint fires, to include targeting, capability pairing, and threat mitigation in support of CMF and other operations.

Knowledge of cyber TTPs is required in order to provide recommendations to USCYBERCOM leadership on all aspects of joint fires and threat mitigation.

The contactor shall perform the following cyber fires planning and analysis:

a. Plan, organize, determine, and recommend necessary policies, regulations, directives, programs, doctrine, and procedures for the establishment and maintenance of assigned and anticipated joint fires coordination and execution.

b. Provide support to future operations planners to integrate cyber capabilities into plans.

c. Collaborate with DISA, the National Security Agency (NSA), service providers, and other organizations to ensure that USCYBERCOM requirements are implemented.

d. Collaborate with operators in the Joint Operations Center (JOC), subordinate headquarters, and cyber teams to integrate capabilities.

e. Coordinate with all applicable J-Directorates, JFHQs, subordinate headquarters, Service

Cyber components, CCMD, components and agencies with cyber related missions.

f. Act as liaison between capability Subject Matter Experts (SMEs) and the planning teams in order to assist the planners understand the technical aspects of specific capabilities in support of a specific planning effort.

g. Identify and develop cyber TTPs that advise the future operations planners on achieving

Cyberspace Operations in support of operations and exercise objectives.

h. Recommend requirements for the development of cyberspace capabilities. Provide recommendations to prioritize requirements for automated cyberspace capabilities in support of operations and assessments.

i. Provide capability SME support by participating in USCYBERCOM requirements working groups to define cyber capabilities/tools and recommend COAs.

j. Analyze and report on technical issues relating to current and future DOD plans, programs, policies, and activities related to cyberspace operations.

k. Participate in special programs and teams for fires planning and analysis.

l. Support the collateral Review and Approval Process for Cyberspace Operations (RAP-CO) process.

C.4.2.4.1 – PROVIDE CYBER TASKING CYCLE SUPPORT

The Cyber Tasking Cycle (CTC) is the official method used to task cyber forces to execute missions. The cyber tasking cycle is utilized at all echelons of joint command to globally synchronize and deconflict forces. The USCYBERCOM J3 is responsible for managing the products that are driven by the CTC.

The contactor shall provide the following cyber tasking cycle support:

a. Assist with the creation, implementation, and management of the Master Cyber

Operations Plan (MCOP) creation and implementation.

b. Synchronize and deconflict the Cyber Tasking Order (CTO).

c. Attend and provide input during the Operations Synchronization meetings.

Task Order DRAFT Section C C-16

d. Coordinate with CMF and other subordinate units to facilitate the Cyber Tasking Cycle processes.

e. Provide time sensitive, critical data inputs into the C2 system and validate data.

f. Make recommendations on changes in the C2 system based upon evolving task cycle.

C.4.2.4.2 – PROVIDE FIRES SME OUTREACH AND EXERCISE PROGRAM

The fires SME outreach program provides information and knowledge to different groups, courses, units, and organizations outside of USCYBERCOM on the USCYBERCOM fires process as it continues to evolve. This program has become even more important with the standup of the CMF units.

The contactor shall provide the following fires SME outreach and exercises program support:

a. Conduct outreach programs on USCYBERCOM Fires processes.

b. Maintain the master Fires Brief with the most updated information.

c. Assist USCYBERCOM by attending and briefing at selected courses, events, to include, but not limited to selected exercise academics, the Joint Advanced Warfighter Course

(JACWC), the Army Cyberspace Operations Course, the Air Force Weapons School, and the Joint Targeting School.

d. Maintain contact with the external groups, courses, units, and organizations and provide approved, updated fires briefings and supporting documentation in a timely manner

e. Participate in exercises, including CCMD exercises and planning conferences, and provide feedback and after action reports.

C.4.2.4.3 – PERFORM SPECIAL TECHNICAL OPERATIONS (STO)/SPECIAL

ACCESS PROGRAM (SAP) CYBER FIRES PLANNING AND ANALYSIS

STO/SAP cyber fires planning and analysis entails the synchronization and deconfliction of collateral and STO/SAP capabilities within the JOPP. STO/SAP cyber fires planning and analysis requires the ability to pass an additional layer of security review and must adhere to need-to-know and material contribution criteria. The contractor shall provide subject matter expertise in cyberspace operations and cyber fires in order to effectively integrate with

USCYBERCOM Fires and Effects.

The contactor shall provide the following STO/SAP Cyber Fires Planning and Analysis:

a. Support the Review and Approval (RAP) process, and develop CONOPs for employment of STO/SAP capabilities in support of (ISO) USCYBERCOM supported and supporting cyberspace operations.

b. Integrate STO/SAP capabilities in current and future operations and plans ISO

USCYBERCOM and CCMDs.

c. Assist with STO/SAP assessments and document findings.

C.4.2.5 SUBTASK 2.5 – PROVIDE INFORMATION ASSURANCE VULNERABILITY

MANAGEMENT (IAVM) SUPPORT

Task Order DRAFT Section C C-17

The IAVM Program supports secure cyberspace operations through the identification and analysis of disclosed vulnerabilities to determine their operational impact to the DODIN.

Vulnerabilities found to pose a significant risk to the DODIN are addressed by the IAVM

Program through dissemination of IAVM Directives (Information Assurance Vulnerability

Alerts (IAVA) and Information Assurance Vulnerability Bulletins (IAVB) mandating DODIN-wide implementation of mitigation or remediation actions. The contractor shall provide subject matter expertise in computer network theory, cybersecurity standards, policies, and methods, as it applies to the lifecycle of cyberspace threats, attack vectors, and methods of exploitation.

The contractor shall provide the following IAVM support:

a. Identify and draft mitigation strategies for vulnerabilities without Service Provider remediation for the Government’s review.

b. Establish communications with Service Providers for the incorporation of newly identified vulnerability mitigation strategies ensuring adherence to specialized and proprietary DODIN asset requirements.

c. Develop and inform the mitigation/remediation strategy in response to publicly disclosed vulnerabilities of vendor software/hardware products.

d. Review daily, weekly, monthly, and annual vulnerability metric roll-ups associated with affected and non-compliant DOD assets.

e. Utilize risk scoring and monitoring tools/capabilities to review manually uploaded and automated information from DOD component to report vulnerability orders and directives compliance.

f. Develop, coordinate, and maintain accurate USCYBERCOM orders and directives.

g. Create situational awareness products to provide USCYBERCOM leadership and DOD components with detailed information related to vulnerabilities and appropriate mitigation strategies.

h. Assist with the prioritization of newly identified software/hardware vulnerabilities based upon severity, potential operational impact, exploitation, and other factors to assess risk to DODIN assets.

i. Analyze known issues affecting DOD components and liaise with the appropriate Service

Provider for a defined and attainable solution.

j. Collaborate and coordinate with JFHQ’s, DOD CC/S/A/FA, Intelligence Agencies, Law

Enforcement (LE), and US Government organizations.

k. Develop, document, and convey IAVM operational requirements to enhance capabilities identifying, tracking, and remediating system and network vulnerabilities as well as automated vulnerability management capabilities.

l. Monitor the progress of and collaborate with internal and external organizations to ensure

IAVM operational requirements and strategies are fulfilled and adhered.

m. Consolidate, analyze, and brief reports on new and existing adversary TTPs.

C.4.2.5.1 - PERFORM INFORMATION ASSURANCE VULNERABILITY ALERTS

(IAVA) COMPLIANCE

IAVA directives address recently disclosed vulnerabilities that introduce immediate and severe risk to DODIN assets. Corrective actions are mandatory due to the severity of the vulnerability.

USCYBERCOM directs mitigations strategies for enterprise vulnerabilities through orders, Task Order DRAFT Section C C-18 directives, and policies. The contractor shall provide subject matter expertise on IAVM Program process and methods, automated cybersecurity capabilities, including Host Based Security

System (HBSS), Assured Compliance Assessment Solution (ACAS), Continuous Monitoring

Risk Score (CMRS), and the USCYBERCOM IAVM System.

The contractor shall perform the following IAVA compliance:

a. Track compliance of USCYBERCOM orders and directives for implementation of appropriate security controls against DODIN assets.

b. Communicate (written and oral) with JFHQ’s and CC/S/A/FAs concerning IAVA strategy compliance, and review and track Plan of Action and Milestones (POA&M) approval and documentation, implementation of appropriate system security controls, and DOD policies.

c. Provide status reports and metrics to USCYBERCOM leadership for DOD Components on IAVA compliance.

d. Review daily, weekly, monthly, and annual compliance metrics roll-ups to support

USCYBERCOM operational deadlines.

e. Review monthly POA&M audits on selected IAVA orders and directives to validate

DOD components compliance status.

f. Develop and provide programmatic review for IAVA POA&M audits, non-compliant assets, and incidents resulting from unmitigated vulnerabilities.

g. Develop, coordinate, and maintain accurate USCYBERCOM orders and directives.

h. Maintain the IAVM oversight program, associated policies, and provide strategic guidance for DOD component implementation.

i. Conduct trend analysis of incidents to determine compliance with USCYBERCOM orders and directives.

j. Collaborate with JFHQ’s regarding supporting organizations’ unacceptable DODIN ratings, inspection failures, and incidents to develop briefs, watch lists, and responses to requests for information.

k. Maintain situational awareness of IAVA strategy programmatic issues and brief quarterly

IAVA compliance watch list.

C.4.2.6 SUBTASK 2.6 – PROVIDE FUSION SUPPORT

Fusion is the collaboration, correlation, and analysis of cyberspace incident reports derived from reliable sources, network sensors, vulnerability management devices, open source information, and DOD component provided situational awareness of known adversary activities.

Threat detection analysis and coordination provides monitoring, correlation, and prevention of cyber threat activity targeting the DODIN. The contractor shall provide subject matter expertise on government and industry fusion capabilities, best security practices, advanced log analysis, forensics, network monitoring, network flow analysis, packet capture analysis, network proxies, firewalls, and anti-virus capabilities. The contractor shall provide forensics analysis to determine adversary methods of exploiting information system security controls, the use of malicious logic, and the lifecycle of network threats and attack vectors.

Task Order DRAFT Section C C-19

The contractor shall provide the following fusion support:

a. Analyze the details of Named Areas of Interest (NAI) and advanced persistent threats that impact the DODIN, track, correlate, harvest, trend, and report on the unique TTPs utilized.

b. Conduct incident handling/triage, network analysis and threat detection, trend analysis, metric development, and security vulnerability information dissemination.

c. Configure, maintain, and utilize USCYBERCOM and CC/S/A/FA capabilities in order to detect, monitor, track, and analyze malicious activity targeting the DODIN.

d. Consume, review, correlate, and report on high priority DOD, Intelligence, and US

Government operational reporting of threats and vulnerabilities to correlate similar incidents/events, malicious tradecraft, TTPs of malicious activity, and indicators utilized to impact or target the DODIN.

e. Develop consolidated notifications and updates to the USCYBERCOM JOC on threat and vulnerability activity.

f. Develop, obtain Government approval of, and release situational awareness reports/products, operational directives/orders/messages, and quarterly threat analysis reports/metrics.

g. Review, analyze, and maintain the content of a DOD indicator database to aid in the detection and mitigation of threat activity.

h. Update DOD shared situational awareness mechanisms, including USCYBERCOM websites, Wikipedia style solutions, and collaboration/chat mechanisms.

i. Develop and present cyber threat briefings, presentations, and papers to USCYBERCOM leadership to ensure situational awareness and status are conveyed related to the assigned project areas.

j. Assist the Government by operating as the DOD community leader for the discovery of threat activity and associated indicators.

k. Determine sophistication, priority, and threat level of identified malware and intrusion related TTPs.

l. Develop metrics and trending/analysis reports of malicious activity used to compromise the DODIN.

m. Develop, staff, and release analysis findings in technical analysis reports to DOD

Comm…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .