Attachment_A_-_USCYBERCOM_Requirements_Task_Areas_FINAL_6-17-15.docx
DOCX document 70 KB Posted
- Attached to
- United States Cyber Command (USCYBERCOM) Mission Support Services Federal contract opportunity
- Solicitation number
- GSC-QFOB-15-USCYBERCOM
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| USCYBERCOM-_RFI_Questions Answers.pdf | ||
| Attachment_E_-_Security_Requirements_FINAL_6-17-15.docx | DOCX document | |
| Attachment_C_-_Corporate_Capabilities_FINAL_6-17-15.docx | DOCX document | |
| Attachment_B_-_Questionnaire_FINAL_6-17-15.docx | DOCX document | |
| USCYBERCOM_RFI_Cover_Letter_FINAL_6-17-15.docx | DOCX document | |
| Attachment_D_-_Corporate_Experience_FINAL_6-17-15.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment A United States Cyber Command (USCYBERCOM) Requirements Document
The following Functional Alignment to Major Support Task Areas represent the scope of the USCYBERCOM Indefinite Delivery Indefinite Quantity (IDIQ). Task Orders under the IDIQ will utilize one or a combination of the Major Support Task Areas:
1. All-Source Intelligence
2. Business Administration
3. Capability Management and Development
4. Cyber Operations
5. Cyber Planning
6. Cyber Training & Exercises
7. Engagement Activities
8. Information Technology/Communications (IT/Comms)
9. Security
10. Strategy/Policy/Doctrine Development and Campaign Assessments Special Requirements:
1. Possess a TS with SCI eligibility with a Counter-Intelligence Polygraph (CI);
2. DoD 8570 certifications are applicable to Information Assurance positions;
3. Program Management Certifications as applicable; and
4. Non-Disclosure Agreements as applicable.
Major Support Task Area Descriptions
1. All-Source Intelligence
Intelligence is a joint function integral to all military operations. Joint Publication (JP) 2-01 defines combatant command (CCMD) roles in joint intelligence activities as “assisting the commander and staff in developing strategy, planning major operations and campaigns, coordinating the intelligence structure and architecture, recommending appropriate command relationships for intelligence, surveillance, and reconnaissance assets, and supervising the production and dissemination of appropriate intelligence products.” USCYBERCOM’s role in intelligence activities includes all-source intelligence support to the development of cyberspace operations capabilities planning, integration, coordination and execution. Intelligence activities assist operations and planning processes in the development of mission objectives.
Intelligence collection is conducted in response to specific needs expressed by policy makers and military commanders for information. Intelligence and operation activities collaborate to ensure all intelligence collection requirements are identified as early as possible.
1.1 Contractors shall provide intelligence analysis support for planning efforts, from Strategic to the Tactical level. Contractors shall conduct research and analysis, collection management, indications and warning, targeting, imagery analysis, signals intelligence analysis, joint intelligence preparation of the battlespace and crisis planning to standing and deployed cyberspace forces engaged in operations. Contractors shall screen all source intelligence reporting, access and summarize evaluated and previously unevaluated information, discriminate threat information from all source intelligence into actionable intelligence, and disseminate warning and threat analysis for real world contingencies. Contractors shall research all source reporting to produce predictive and current finished intelligence products and coordinate all analytical products and support national level organizations and theater staffs for dissemination across tactical, operational and strategic environments. Contractors shall communicate factual information clearly and concisely, both orally and in writing, often under pressure and tight deadlines.
1.2 Contractors shall support:
· Analyzing all source intelligence information to produce assessments, reports, articles, threat analyses, special studies etc., responsive to user needs; complying with suspense dates for draft and final products.
· Maintaining all source databases on area of responsibility; using multiple source intelligence tools to perform all source threat force analysis.
· Analyzing and fusing reports from multiple intelligence sources (HUMINT, SIGINT, IMINT, MASINT) to provide intelligence preparation of the battlespace, target development, and early warning of emerging threats.
· Screening and researching all source reporting, accessing and summarizing previously unevaluated information, discriminating threat information into actionable intelligence.
· Monitoring all sources of intelligence to ensure adequacy of coverage and timeliness of assessments; tasking incoming Requests for Information (RFIs) to appropriate cyberspace division.
· Identifying intelligence gaps and requesting solutions via collections process.
2. Business Administration
2.1 Administrative
Administrative support is critical to the effective and efficient operations of USCYBERCOM. Administrative support includes all aspects of administrative management: performing general office support; coordinating between organizations for day-to-day operations; scheduling and coordinating meetings, visits, conferences, and events; preparing, processing and tracking correspondence; preparing meeting minutes and meeting notes; preparing briefings; data collection and reporting; workflow/project tracking; and tracking action items. Specialized administrative support may be required in offices throughout the Command such as the Command Section, Public Affairs Office, Records Management Office, Publications Management Office, Knowledge Management Office, and the History Office.
Administrative support includes support to cyber exercise planning conferences including Joint Worldwide Planning Conference, Joint Event Life Cycle (JELC) planning conferences (Concept Development Conference, Initial Planning Conference, Main Planning Conference, Final Planning Conferences, and Master Scenario Events List (MSEL) Development Conference. Conference design, facilitation and analysis also fall under this task area.
2.1.1 Contractors shall provide routine administrative and clerical assistance, including receiving/screening telephone calls and visitors. Contractors shall respond to routine, non-technical requests for information; scheduling appointments, making arrangements for conferences, meetings and presentations, including location, schedule, agenda and coordinating all other arrangements with staff/participants. Contractors shall provide specialized administrative support to the Command Joint Directorates, organizations and special staff offices such as Legislative Affairs Office, Public Affairs Office, Command Secretariat, Command Engagements/Visits, Inspector General, and the Commander’s Action Group. Contractors shall assist with office procedures, command protocol, correspondence, messages, reports, forms, filing, mail, training, travel security, personnel procedures, and preparation for office moves. Contractors shall compose routine/non-technical correspondence and shall prepare reports, make suggestions/corrections to internal Command administrative/clerical correspondence including office tasks or other appropriate subjects. Contractors shall also provide support to initiate travel arrangements, travel orders, and prepare vouchers for Command leadership. Contractors shall have the ability to work within Government provided software packages with emphasis on the Defense Travel System, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, and Microsoft SharePoint 2013 and later upgrades. Contractors shall be required to prepare power point presentations in support of management briefings.
2.1.2 Contractors shall provide administrative and clerical expertise to support the achievement of operations and research objectives, information analysis, exercise and training development and implementation of training objectives. Contractors shall maintain Microsoft SharePoint and shared file locations for knowledge management of documentation and office related information. Contractors shall also provide administrative support for exercise and training design, planning, preparation, execution, analysis, evaluation, and reporting; Joint Training Plans and After-Actions Programs development; and individual, team and collective mission area training.
2.1.3 Contractors shall conduct administrative coordination activities for obtaining spaces to accommodate meetings, working groups, events, conferences, conference support, materials required to support such events, and the Information Technology (IT) and audio/visual/video teleconferencing (VTC) services and equipment that may be needed at the unclassified, secret, and top secret levels.
2.2 Knowledge management
The Chairman Joint Chief of Staff (CJCS) Instruction 5124.01, Charter of the Knowledge Management Cross-Functional Team, defines Knowledge Management as “the process of enabling knowledge flow to enhance a shared understanding, learning, and decision-making. Knowledge flow refers to the ease of movement of knowledge within and among organizations.” To manage, capture, store and reuse knowledge effectively, USCYBERCOM Instruction 5900-01, Knowledge Management (KM) Program, identifies four core areas of focus for the command’s KM Program:
· Strategy
· Processes
· Organization and Culture
· Technology
USCYBERCOM’s Chief Knowledge Officer (CKO) is responsible for managing the Knowledge Management program, which includes developing and executing a Knowledge Management strategic plan. The CKO collaborates with the Chief Information Officer (CIO) for the development of Knowledge Management software tools, as Knowledge Management is enabled through the use of key information systems such as online document collaboration. USCYBERCOM’s Knowledge Management Working Group (KMWG) is charged with amending or initiating policy for Knowledge Management processes, procedures, and technologies. The KMWG ensures that strategic initiatives are coordinated and managed across the Command. All Command personnel have a role in the Knowledge Management process from creation to consumption. The Knowledge Managers are charged with promoting the Knowledge Management best practices within their own organizations and serve as a resource for internal business process design and development. They promote and assist with the use of internal Knowledge Management tools. They should also meet the requirements identified in Joint Cyberspace Training and Certification Standards (JCT&CS) for knowledge managers.
2.2.1 Contractors shall provide technical expertise in Knowledge Management to support various directorates within USCYBERCOM and the CKO to formulate Knowledge Management strategies and policies to enable USCYBERCOM to create and maintain records in accordance with the Department of Defense (DoD) Knowledge Management Policy requirements to document the roles and responsibilities of the Command in the conduct of its mission.
2.2.2 Contractors shall provide technical and comprehensive Knowledge Management support to USCYBERCOM to plan, manage, and integrate the USCYBERCOM and Cyber National Mission Force (CNMF) joint exercise and training programs and after action processes to achieve and sustain USCYBERCOM mission essential task proficiency.
2.3 Records management
The Executive Office of the President Memorandum M-12-18, Managing Government Records Directive, 24 August 2012, creates the records management framework and provides for specific actions that will support agency records management programs. DoD 5015.02-STD and DoD 5015.2 STD (2007) define Records Management as "the planning, controlling, directing, organizing, training, promoting, and other managerial activities involving the life cycle of information, including creation, maintenance (use, storage, retrieval), and disposal, regardless of media." Simply stated it is the professional practice or discipline of controlling and governing what are considered to be the most important records of an organization throughout the records life-cycle, which includes from the time such records are conceived, implemented, revised and archived. This work includes identifying, classifying, prioritizing, storing, securing, preserving, retrieving, tracking and archiving of records. The National Archives and Records Administration is responsible for storing permanently valuable historical records.
2.3.1 Contractors shall provide technical expertise to support the formulation of Records Management strategies and policies to enable USCYBERCOM to create and maintain records in accordance with the DoD Record Management Policy requirements to document the roles and responsibilities of the Command in the conduct of its mission. Furthermore, contractors shall assist the Chief of the Command Secretariat, Command Publications Manager, and several directorates within the Command with the development and maintenance of a Command publications Library as appropriate on the three network domains.
2.4 Business Process Reengineering
Business process reengineering is the practice of rethinking and redesigning processes and workflows by which work is accomplished and products delivered to better support an organization's mission and increase efficiency. Reengineering starts with a high-level assessment of the organization's mission, strategic goals, and customer needs. Then current processes are identified along with areas where gaps may exist.
2.4.1 Contractors shall provide Enterprise Business Transformation expertise, including Lean Six Sigma and Process Change Management methodology to support the CKO in analyzing current USCYBERCOM workflows and processes to identify process inefficiencies and areas of improvement, reduce redundancy, and re-engineer applicable processes to increase efficiency.
2.4.2 Contractors shall develop approaches for improving organizational performance and the activities needed to implement new or revised business or functional processes arising from business process reengineering undertakings. Contractors shall identify the development and/or integration of information technology to enable the improvements in processes. Contractors shall provide technical expertise to ensure approved solutions to re-engineer processes are implemented and their effectiveness is measured against current processes. Contractors shall revise performance measures in alignment with new business processes.
2.5 Logistics
JP 1-02 defines logistics as “planning and executing the movement and support of forces.” It further defines logistics support as “support that encompasses the logistic services, materiel, and transportation required to support the continental U.S. based and worldwide deployed forces. JP 4.0 defines the core logistics functions “The core logistic functions are: deployment and distribution, supply, maintenance, logistic services, operational contract support, engineering, and health services.” The core logistic functions are considered during the employment of U.S. military forces in coordinated action toward a common objective and provide global force projection and sustainment.
2.5.1 Contractors shall provide logistics planning and management expertise for obtaining offsite facilities as needed for the conduct of crisis action planning, simultaneous planning events, cyber event management and planning for periods of non-disruption and continuity of operations.
2.5.2 Contractors shall provide management logistical oversight for facility management, asset management, and procurement support. Contractors shall manage the flow of resources between the point of origin, procurement, configuration management and through disposal, to include: purchasing, handling, controlling, and transportation of material and other property. Contractors shall maintain proper retention of logs, files, and supporting documentation for all movement of materials. Contractors shall communicate and coordinate with all parties involved in materials movements.
2.5.3 Contractors shall assist the Government in managing the development of upgrades and system improvements, tracking and reporting material, establishing and maintaining material handling procedures, asset management, configuration management and scheduling. Contractors shall develop and manage Power/Space/Cooling requests, and Baseline Exemption Requests (BERs). Logistics support shall adhere to and be provided in accordance with Federal and DoD policy.
2.6 Project Analysis
2.6.1 Contractors shall provide technical expertise to assist with the following project analysis functions to ensure proper and efficient execution and performance of programs, and that capabilities are successfully developed and acquired to meet USCYBERCOM's requirements:
· Track and analyze the status of programs fulfilling USCYBERCOM requirements for remaining within scope, within budget, and on schedule, while mitigating risks
· Maintain program information and status of ongoing program activities
· Analyze and refine initial user needs and assist in defining requirements
· Analyze validated and prioritized requirements to manage timelines and risks
· Assist with validating and prioritizing requirements
· Collaborate with teams managing related and dependent requirements to maintain status of collective progress
· Support execution and delivery of capabilities to end-users
· Provide lifecycle support to close out capability development and implementation
· Analyze project risks and develop risk mitigation plans
· Develop courses of action to fulfill gaps and requirements
· Conduct analysis of programs, manage deliverables, and prepare graphs, tables, diagrams, and presentations to present analysis conclusions and recommendations.
2.6.2 Contractors shall provide Project analysis support to assist USCYBERCOM with proper and efficient execution of programs, requirements identification and definition, and course of action development for the integration, management and sustainment of Offensive Cyber Operations (OCO) and Defensive Cyber Operations (DCO) capabilities, and efforts to secure, operate, and defend the DoD Information Network (DODIN).
2.6.3 Contractors shall provide support to prepare, review and update program documentation and status in support of milestone decisions, leadership and external reviews. Contractors shall assist with organizing and preparing for program meetings and conferences.
2.6.4 Contractors shall conduct project analysis, prepare papers, graphs, tables, diagrams, and briefings to present analysis conclusions and recommendations. The Contractor shall develop methods for tracking program performance, refine project analysis processes, methods, and tools. The Contractor shall maintain program plans and coordinate with the program managers to ensure programs fulfill requirements upon delivery. The contractor shall develop and maintain program files in accordance with records management processes.
2.7 Program Management
2.7.1 Contractors shall provide program management in order to assist in the management of program efforts to scope, schedule, budget and risk to ensure the accomplishment of program goals. Contractors shall develop program documentation, risk management documentation, plans, and program schedules. Contractors shall track program and budget status in agreed upon approved formats, evaluate operational and technical alternatives, and perform risk assessments. Contractors shall identify the program critical path and risk mitigation strategies.
2.7.2 Contractors shall develop work breakdown structures and integrated master schedules. Contractors shall prepare charts, tables, graphs and diagrams to assist in analyzing problems, program risks and issues, and prepare program management plans, program documentation and reports. Contractors shall coordinate schedules to facilitate completion of contract deliverables, briefings/presentations and program reviews, perform analysis, and develop and review program administrative operating procedures.
3. Capability Management and Development
Capability Management and Development includes development efforts for near term integration, science and technology (S&T) efforts to push technological limits to generate breakthroughs in engineering disciplines; and Research and Development (R&D) efforts which focuses on the development of new or improved capabilities of proven science and technology to the point they are appropriate for operational use. Test and evaluation is part of capability development and determines if a capability is appropriate for operational use. USCYBERCOM capability management and development efforts are conducted with the goal to fulfill tactical, operational, and strategic requirements, and to develop quick reaction cyberspace capabilities. USCYBERCOM provides the strategic vision and direction for R&D and S&T across the Services.
Capability Management and Development efforts are conducted by USCYBERCOM to advance concepts and technologies. USCYBERCOM works with the services, industry, academia, the IC and the DoD labs to bring new ideas and tools forward in support of the Cyber Mission Forces (CMF) in the shortest time possible. USCYBERCOM leverages this pool of expertise to build diverse capabilities to enable full-spectrum military operations. USCYBERCOM also enforces a process to ensure there is no redundancy of effort and that multiple DoD entities can use the same capabilities when possible to maximize returns on investment. The cyber forces train on, and integrate those capabilities in their tactical training exercises. Capability development for the national and CCMD cyber mission forces aligns with USCYBERCOM’s three mission areas of defending the nation; secure, operate, and defend the DODIN; and provide support to CCMDs.
3.1 Contractors shall provide technical assurance, engineering and architecture analysis and research for the creation and updating of system architectures initial capability documents, capability development documents, capability production documents, and engineering guidance documents (standards, specifications, technical architectures, systems). Contractors shall conduct test and evaluation to support the analysis and testing of cyber-related capabilities.
3.2 Contractors shall research, develop, demonstrate, integrate and test innovative technology in support of cyberspace threat defense and management in an effort to facilitate proactive development and test of cyberspace offensive and defensive capabilities. Contractors shall evaluate and validate sensor system performance capabilities and effectiveness, assess risk, and determine operational feasibility and benefits of the Command’s systems or technology prototypes, to include recommending assessments of system performance, identifying deficiencies, and investigation of physical science phenomena.
3.3 Contractors shall provide IT support and perform studies, analyses and experimentation in both laboratory and non-laboratory environments. Research & Development (R&D) tasks shall address any life cycle phase(s) and include science and technology efforts. Contractors shall evaluate unproven technology applications, identify potential risks, and document and submit results in support of evaluation findings. Contractors shall provide drawing support services. Contractors shall participate in technical reviews and meetings in support of capability management and development activities.
3.4 Contractors shall provide technical expertise and collaborate with USCYBERCOM and its partners to identify and capture capability development requirements. Contractors shall develop artifacts for capability development requirements, including white papers and CONOPS. Contractors shall provide technical expertise and participate in activities to identify courses of action for fulfilling capability development requirements, and collaborate with stakeholders to determine the best course of action. Contractors shall conduct requirements decomposition and requirements elicitation activities for capability development efforts. Contractors shall provide technical expertise during participation in program reviews to ensure the capability development program is fulfilling the requirement.
3.5 Contractors shall support the capability management and development process by coordinating with IC tool developers, CMF tool developers, and other weapon/tool/capability providers and submit data on cyber capabilities, review, analyze, and maintain data provided by end users and developers on operational cyber capabilities and associated data. Contractors shall conduct cyber capability analysis to pair operational requirements with cyber capabilities.
3.6 Contractors shall conduct critical and technical research and analysis to define Commander’s Critical Information Requirements (CCIR), Priority Intelligence Requirements (PIR), and Essential Elements of Friendly Information (EEFI) for reporting cybersecurity incidents.
4. Cyber Operations
JP 3-0, Joint Operations, provides that “USCYBERCOM is a sub-unified command subordinate to the U.S. Strategic Command (USSTRATCOM) and directs the operations and defense of specified DoD information networks. It is capable of conducting full-spectrum military cyberspace operations to enable U.S. freedom of action in cyberspace and enable actions in other domains and deny the same to our adversaries. Cyberspace operations is the employment of cyberspace capabilities primarily to achieve objectives in or through cyberspace.” JP 3-12, Cyberspace Operations defines a cyberspace capability as “a device, computer program, or technique, including any combination of software, firmware, or hardware, designed to create an effect in or through cyberspace.”
Section 18(d)(3) of the Unified Command Plan expands upon the above delegated USCYBERCOM responsibilities by also including the specific missions of providing shared situational awareness of cyberspace operations, including indications and warning; integration and synchronization of cyberspace operations with CCMDs and other appropriate U.S. Government agencies tasked with defending the nation’s interests in cyberspace; and providing support to civil authorities and international partners.
USCYBERCOM categorizes cyberspace operations into three areas: OCO, DCO, and DODIN Operations. JP 3-12 defines theses terms as:
Offensive Cyberspace Operations (OCO): “Cyberspace operations intended to project power by the application of force through cyberspace.”
Defensive Cyberspace Operations (DCO): “Passive and active cyberspace operations intended to preserve the ability to utilize friendly cyberspace capabilities and protect data, networks, net-centric capabilities, and other designated systems.”
DoD Information Network (DODIN) Operations: “Operations to design, build, configure, secure, operate, maintain, and sustain DoD networks to create and preserve information assurance on the DODIN.” Defending the DODIN includes ensuring the security objectives of confidentiality, integrity, and availability are maintained at a level commensurate with the criticality and sensitivity of the DODIN.
4.1 Contractors shall contribute technical expertise to develop Tactics, Techniques and Procedures (TTP) for conducting cyber operations, measures and countermeasures and support their implementation, develop and implement incidence reporting, event handling and secure configuration guidance to protect, mitigate, and remediate service outages and adversarial activities. Contractors shall provide technical input for the development of requirements and support the development of both offensive and defensive cyberspace capabilities to achieve USCYBERCOM goals, and for achieving situational awareness and a common operating picture of activities happening in cyberspace. Contractors shall support the government in providing situational awareness of cyber incidents, health, performance, availability and reliability of the DODIN.
4.2 Contractors shall provide technical expertise to assist in the planning, coordination, and synchronization of OCO, DCO, and operation of the DODIN.
4.3 Contractors shall contribute technical expertise during the conduct of assessments of cyberspace operations including the development and deliberate comparison of forecasted outcomes with actual events utilizing Measures of Effectiveness (MOE) and Measures of Performance (MOP) when determining progress toward desired end-states and satisfying objectives. Contractors shall participate and contribute to the development of the Joint Operations Center (JOC) Emergency Action Procedures in preparedness to defend the nation through inter-agency emergency cyber procedures.
4.4 Contractors shall assist in providing maneuver, fires and effects through the application of capabilities in and through the cyber domain. Contractors shall support the creation and dissemination of orders and directives to provide guidance to the DoD community.
4.5 Contractors shall support USCYBERCOM’s efforts in the DoD and whole of government by contributing to the development of policies, doctrine and processes, courses of action, input for the situational awareness report (SAR), and input for the National Defense Authorization Act (NDAA) 935 report.
4.6 Contractors shall provide technical expertise to assist in fulfilling USCYBERCOM’s responsibilities to the Joint Information Environment (JIE) initiative by identifying requirements and concepts of operation that focus on the execution of DODIN Operations and DCO Internal Defensive Measures (DCO-IDM). Contractors shall assist in the development, synchronization, integration and assessment of operational standards in support of achieving the JIE end-state.
5. Cyber Planning
Joint Planning consists of planning activities associated with joint military operations by combatant commanders and their subordinate joint force commanders in response to contingencies and crisis. It transforms national strategic objectives into activities by development of operational products. Joint plans and orders are developed with the strategic and military end states in mind. The commander and planners derive their understanding of those end states from strategic guidance. Specifically in this domain, commanders integrate cyberspace capabilities at all levels and in all military operations. Depending on the level of planning being conducted (Deliberate, Crisis Action, Future Operations (FuOps), Operations, and Execution), plans should address how to effectively integrate cyberspace capabilities, counter an adversary’s use of cyberspace, secure mission critical networks, operate in a degraded environment, efficiently use limited cyberspace assets, consolidate requirements for cyberspace capabilities, and assess the ability of the DoDIN to support offensive and defensive operations.
Planning translates strategic guidance and direction into campaign plans, level 1-4 plans, and operation orders. Joint operation planning may be based on defined tasks identified in the Global Employment of Forces (GEF) and the Joint Strategic Capabilities Plan (JSCP). Alternatively, joint operation planning may be based on the need for a military response to an unforeseen current event, emergency, or time-sensitive crisis. Joint operation planning encompasses a number of elements, including three broad operational activities, four planning functions, and a number of related products.
USCYBERCOM develops plans and orders through the application of operational art and operational design and by using the Joint Operation Planning Process (JOPP). Deliberate planning encompasses the preparation of plans that occur in non-crisis situations. It is used to develop campaign and contingency plans for a broad range of activities. Crisis Action Planning (CAP) is a process for getting vital decision–making information available up the chain of command to the President and Secretary of Defense. CAP encompasses the activities associated with the time-sensitive development of Operations Orders (OPORDs) for the deployment, employment, and sustainment of assigned, attached, and allocated forces and capabilities in response to a situation that may result in actual military operations.
USCYBERCOM employs each of the steps of deliberate planning and CAP through operational design and using JOPP for planning activities as a supported and supporting command through established Joint Planning Groups (JPGs), Operational Planning Groups (OPGs), and Operational Planning Teams (OPTs). Cyberspace operations planning activities are coordinated through the Integrated Joint Special Technical Operations (IJSTO) and Review and Approval Process for Cyberspace Operations (RAPCO) processes.
5.1 Contractors shall provide comprehensive strategic planning support to USCYBERCOM to plan, manage, and integrate the USCYBERCOM and CNMF joint exercise and training programs and after action processes to achieve and sustain USCYBERCOM mission essential task proficiency.
5.2 Contractors shall provide in-depth deliberate planning expertise for the development of policy, plans, processes, procedures, and governing directives for the operation, protection, and defense of the DODIN and provide input to address shortfalls, prioritize and validate requirements and be prepared to modify development planning efforts based on the changing cyberspace environment.
5.3 Deliberate Planning. Contractors shall assist with deliberate planning to include the management and implementation of the Adaptive Planning Process from strategic guidance to completion of USCYBERCOM level one through level four contingency plans, synchronization of the Command’s missions into plans through internal and external collaboration and coordination with all mission partners. Deliberate planning encompasses the preparation of plans that occur in non-crisis situations.
5.4 Crisis Action Planning. Contractors shall provide technical input and content recommendations to assist in short-term crisis action plans through internal and external collaboration and coordination with all mission partners. Contractors shall assist with Crisis Action Planning and the development of all orders and plans to meet time sensitive event horizons.
5.5 Future Operations Planning. Contractors shall provide technical input and content recommendations to assist in future operations plans through internal and external collaboration and coordination with all mission partners. Contractors shall assist with future operations Planning and the development of all orders and plans to meet mid-range time horizons.
5.6 Operational Planning. Contractors shall provide technical expertise to assist with the development of operational plans that contain a variety of viable cyberspace options, including mission analysis, courses of action (COA) development, COA analysis war gaming, COA comparison and approval, Commander’s estimates, and campaign plans, and order development, for the Commander to consider.
5.7 National Mission Team/Execution Planning. Contractors shall provide technical and joint planning expertise to assist with the development of tactical joint operational plans in coordination with higher headquarters, mission partners, and tactical teams. Contractors shall assist with future operations and mission planning for the development of tactical-level plans and execution of orders.
6. Cyber Training & Exercises
6.1 Cyber Training
USCYBERCOM is charged with the mission of achieving the most effective cyber force, one that is best postured to defend the nation and our national interests. The DoD Strategy for Operating in Cyberspace sets USCYBERCOM, along with its mission partners and allies, in motion toward building DoD trained and ready cyber forces. USCYBERCOM designs, plans, implements and coordinates cyber forces operational readiness objectives with CCMDs, Services, and Agencies (CC/S/A).
The work roles within the Cyber Mission Force (CMF) will have unique training requirements. Cyber teams will work together with regional and functional commanders according to a command and control construct that USCYBERCOM is working to develop, field, implement, and maintain. The teams will be trained to adhere to strict joint operating standards to ensure the teams can be on-line without jeopardizing vital military, diplomatic, or intelligence interests. These standards will also assure intelligence oversight while securing trust that military operations in cyberspace do not infringe on privacy and civil liberties of U.S. persons.
On behalf of the DoD (in accordance with CJCSI 3500.01G), USCYBERCOM establishes the joint standards for individual and collective training. These standards are contained in three foundational documents: the JCT&CS, and the Training and Readiness Manual (T&R Manual). The JCT&CS identifies the unique Knowledge, Skills and Abilities (KSAs) for each work role for all personnel.
The Exercise and Training Directorate (J7) implements the JCT&CS to include the development of Joint Mission Essential Tasks (JMETs), Joint Training Plan (JTP), training and exercise objectives, and assessment process for the Command. The individual training plans (ITP) outline an optimal path to achieving the required KSAs to satisfy the JCT&CS requirements. The T&R Manual provides the tasks, conditions and standards required to demonstrate individual and collective proficiency.
Realizing that individuals bring various skills and education backgrounds to USCYBERCOM, the Command conducts a training needs assessment on all personnel. The Individual Training Equivalency Board (ITEB) has been established to adjudicate the amount of credit individuals can receive for training that has already been completed, in-line with established equivalency standards. USCYBERCOM established and maintains Job Qualification Records for twenty (20) unique cyber work roles.
6.1.1 The Contractor shall provide technical expertise for the development of training programs that provide for, enhance the quality for, and enhance the quality of, the Cyber Forces in support of command mission objectives. The Contractor shall support the creation of sustainable, repeatable training programs to meet this demand.
6.1.2 Contractors shall provide comprehensive cyber training support for USCYBERCOM to plan, manage, conduct and integrate the cyber training program. Contractors shall assist in the analysis of training requirements in order to ensure that both individual members and cyber teams are adequately trained and prepared to maintain the requisite level of readiness standards as set forth by USCYBERCOM and/or the Services.
6.1.3 Contractors shall assist in the analysis of the training curriculum, performance objectives, training plans, certification standards, exercise objectives and evaluation standards. As part of the analysis, contractors shall project future performance objectives and assist with the development of training materials to support Joint Cyber Training objectives in order to ensure Command personnel possess the necessary skills required to accomplish their missions.
6.1.3.1 Contractors shall provide instructors for cyberspace curriculum developed by the Government. As part of the curriculum, contractors shall provide instructors that have the ability to follow curriculum plan, coordinate with Government guest speakers to ensure support to those modules of the curriculum and also ensure materials are prepared for the module block of instruction.
6.1.3.2 Contractors shall provide technical expertise and input to ensure the training curriculum provides an emphasis on the application of skill with opportunities for students to demonstrate the attainment of the learning objects is required.
6.1.3.3 Contractors shall develop updates to the curriculum, which will be incorporated periodically. Requirements for updates will come as a result of feedback from student evaluations as well as Government input. Recommended changes to the course, obtained from student feedback, Government direction, or contractor alterations.
6.1.3.4 Contractors shall prepare to support Mobile Training Teams (MTT) that will be utilized to instruct curriculum for a two week period in a Government facility. MTT support for each of these sites will be on a by request basis only.
6.1.4 Contractors shall assist with continuous performance improvement and standardization efforts based on future capabilities needs, alternate approaches, flexible applications, and adversary modifications. Contractors shall assist in maintaining training databases to ensure accuracy and timeliness of records. Contractors shall assist in the training waiver process through facilitation of the process and coordination with individuals for completeness of documentation. Contractors shall assist with maintaining training schedules, enrollments, and associated travel plans. Contractors shall assist with and conduct cyber training across USCYBERCOM to support the cyber training program.
6.2 Exercises
USCYBERCOM is an integrated part of the government process for national event responses. Therefore, to remain in a state of readiness, the Command participates in exercises that demonstrate coordination of response actions and coordination across government organizations, departments, and agencies in response to various cyber scenarios. USCYBERCOM plans and trains for major cyber incidents.
USCYBERCOM exercises put operating concepts to the test during the exercise continuum of Cyber Knight, Cyber Guard, and Cyber Flag. These exercises are designed to train and certify CMF teams and can consist of exercises, conventional maneuvers and kinetic fires in conjunction with cyber operations. Current Cyberspace related exercise (support required subject to change during the Period of Performance):
· Cyber Knight: Validates certification and proficiency standards against the CMF teams in accordance with the USCYBERCOM T&R Manual.
· Cyber Flag: Coupled with Joint Doctrine and the Force Model, includes all the Service Cyber components as well as inter-agency and international partners. Provides realistic training for the cyber components and government organizations in executing cyber defense and offense operations across the full spectrum of operations against simulated adversary forces. Provides the opportunity to apply new and developing tactics, techniques, and procedures for the cyber mission force and coalition teams.
· Cyber Guard: Coupled with Joint Doctrine, the Force Model is a whole-of-government event exercising state- and national-level responses to adversary actions against critical infrastructures in a virtual environment. This exercise promotes shared awareness and coordination to mitigate and recover from an attack while assessing potential federal cyber responses.
· Cyber Wargames apply modeling and simulation techniques to look five years into the future, and include expert participation from industry and academia. The objectives of wargames are to explore potential cyber environments and impacts on cyber operations, identify policy and coordination requirements needed to operate in the cyber realm, and identify cyber tools and capabilities necessary to conduct cyber operations from Intelligence, Surveillance, and Reconnaissance (ISR) through operations to Battle Damage Assessment (BDA) in the cyber environment. Wargames contribute to the development of exercise plans used in Cyber Flag.
· Table Top Exercises (TTXs) provide support for the planning and execution of exercises. TTXs validate requirements through each phase in order to validate that scenarios can be carried out and function as predicted in the planning process.
The Cyber exercises, war games, and TTXs that occur regularly throughout every fiscal year are anticipated as follows:
| Type of Event |
| Estimated Number of Events per year |
| Average # of Participants |
| Team Certification Events |
| 9 |
| 50-60 |
| CCMD Exercise Support |
| 10-15 |
| Cyber Knight or similar |
| 9 |
| 50-60 |
| Cyber Flag or similar |
| 3 (2 mini & 1 full) |
| Mini = 50-60/Full = 800 |
| Cyber Guard or similar |
| 5 (4 mini and 1 full) |
| Mini = 50-60/Full = 500 |
| Cyber Wargame |
| 3 |
| 150 |
| TTX |
| 25 |
| 15-30 |
6.2.1 Contractors shall analyze outputs stemming from USCYBERCOM exercises and support the development, architecture and infrastructure capabilities of persistent training and test environments. Contractors shall provide technical input for the development of requirements of training and test environments including the physical infrastructure and facilities.
6.2.2 Contractors shall collaborate with Command elements to implement objectives, priorities and plans for the USCYBERCOM joint exercise program. Contractors shall contribute to the development of exercises utilizing inputs from the cyberspace operations planning process, and to focus on JMETs for known and anticipated operational missions, capabilities, and improvement of Command processes through lessons learned. Exercises simulate alternative operational scenarios and provide insights into how issues may play out in the real world, the real cyber world.
6.2.3 Contractors shall provide research, analysis, and recommendations to conceive, develop, execute, and support Joint Event Lifecycle events including CCMD exercises, tabletop exercises, and scenario development/synchronization. Each year the Command will determine which CCMD exercises we will support.
6.2.4 Contractors shall provide technical expertise and participate in the lifecycle events of conducting an exercise:
· Incorporation of CCMD Training Objectives and/or Cyberspace Training Objectives to be included in the exercise, and if required participation in Concept development conference/meetings
· Initiation of exercise planning (objectives, storylines and themes, concepts of operations (CONOPs), development of exercise scenarios, MSEL, exercise design documents, exercise orders and directives, supporting plans, exercise schedule, exercise control plan
· Participation and/or refinement of materials that result from the initial planning, mid-planning, and final planning conferences
· Exercise build up/preparation
· Exercise hosting and system support
· Exercise execution (blue team/white cell participation)
· Exercise analysis, evaluation, review, assessment, after action reporting
6.2.5 Contractors shall provide comprehensive cyber exercise support to USCYBERCOM to plan, manage, and integrate the USCYBERCOM and CNMF joint exercise and training programs and after action processes to achieve and sustain USCYBERCOM mission essential task proficiency. Contractors shall contribute to the development of Certification and Proficiency Standards, which are required for each of the CMF teams.
6.2.6 Contractors shall conduct post-exercise lessons learned studies and incorporate these in future exercises. Contractors shall develop COAs in response to training objectives. Contractors shall identify, track, and resolve issues impacting training, exercises, and daily operations.
6.2.7 Contractors shall provide technical expertise for the continuous development and refinement of Exercises, Wargames, and TTXs design constructs and concepts in order to continuously identify future manpower, organizational, technical, policy and procedural requirements for the cyber environment.
7. Engagement Activities
Strategic engagements create opportunities for coordination and collaboration with partners across the U.S. Government, private sector, academia, and foreign allies to share information, promote responsible behavior, and defend U.S. interests in cyberspace. Engagements, whether through words, images, or actions, encourage the understanding of the scope and scale of threats and the risk and responsibilities stakeholders in cyberspace together share. Operationalized engagements strengthen collective cybersecurity with partners through the sharing of threat and vulnerability information, advancement of defensive capabilities, development of resiliency, and support of a deterrent posture.
USCYBERCOM cultivates partnerships across the U.S. Government to ensure DoD mission assurance, deter or defeat strategic threats to U.S. interests and infrastructure, and achieve Joint Force commander objectives. USCYBERCOM, together with the National Security Agency (NSA) and the Defense Information Systems Agency (DISA), maintains key partnerships across the DoD, Department of Homeland Security (DHS), and Department of Justice, Department of State, CCMDs, and other U.S. Departments and Agencies. These partnerships enable whole-of-government engagement and unified strategic communications to support U.S. deterrence strategy and policy in cyberspace.
USCYBERCOM engages with foreign allies and partners to deter shared threats and increase international security through our commitment to an open, secure, interoperable, and reliable Internet. UCYBERCOM collaborates and coordinates with foreign allies and partners to improve warning capabilities, collective defense, and capability and capacity building. Foreign partner engagements include training and exercises, planning and operations, and information sharing to deter and effectively respond to malicious cyberspace activity.
USCYBERCOM also engages with the private sector and academia to increase our collective knowledge and publicize malicious cyberspace activities. USCYBERCOM relies on the private sector and academia for technological and conceptual innovation, reliable and secure infrastructure, supporting services and expertise, and research and development to improve U.S. technical capabilities, ensure information assurance, and defend the nation’s vital interests in cyberspace.
7.1 Contractors shall conduct tasks associated with planning, coordinating, and preparing the Command for meetings/conferences/visits with Allies, Services, Agencies, Commands, and other parties, to include visit coordination, logistics, and Command information packages.
7.2 Contractors shall participate in activities to ensure USCYBERCOM remains in coordination with USSTRATCOM, and ensure collaboration with other CCMDs, and the Liaison Officers supporting the Lines of Operation (LOO) at various organizations.
7.3 Contractors shall provide technical expertise to USCYBERCOM activities with the Joint Staff to capture cyber requirements, cyber training requirements, and to implement and refine interim guidance on the command and control of cyber forces.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .