DRAFT Sample Task 01 PWS-Large.docx
DOCX document 38 KB Posted
- Attached to
- DTRA - Assessment, Exercise, and Modeling & Simulation Support Federal contract opportunity
- Solicitation number
- HDTRA120R0006
- Issued by
- Defense Threat Reduction Agency
About this file
This performance work statement outlines cyber assessment support services required by the Defense Threat Reduction Agency. The contractor shall provide personnel with expertise in areas such as cyber operations, cyber transport, and red teaming to conduct vulnerability assessments from mission assurance, balanced survivability, and adversarial perspectives. The assessments identify weaknesses in critical US and allied systems that could be exploited by state or non-state threats. The contractor must maintain readiness to support up to 61 assessments annually, providing teams of up to four personnel equipped to complete eight assessments over one to six weeks per mission. In addition to assessment activities, the contractor shall also manage equipment, provide program support, and coordinate travel as needed to execute the requirements of this performance work statement.
View the file
Other files for this federal contract opportunity
Show all 30
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Defense Threat Reduction Agency (DTRA)
Sample Task Order 01
Cyber Assessments Performance Work Statement (PWS)
31 July 2020
BACKGROUND/INTRODUCTION
The Defense Threat Reduction Agency (DTRA), Nuclear Enterprise Support Directorate (NE), Mission Assurance Department (MA) performs integrated, multidisciplinary mission assurance assessments that assess vulnerabilities of critical U.S. and allied national/theater mission systems, networks, architectures, infrastructures, and assets.
These assessments are generally requested by the DoD Chief Information Officer; Combatant Commands (CCMDs); Undersecretary of Defense Acquisition and Sustainment (USD(A&S)); Undersecretary of Defense Intelligence (USD(I)); Defense Information Systems Agency (DISA); and other Department of Defense (DoD) and Federal agencies, and are coordinated through the Joint Chiefs of Staff and DTRA.
APPLICABLE DOCUMENTS (and as amended)
2.1 DoDD 5105.62: Defense Threat Reduction Agency
2.2 DoDD O-5100.30: DoD Command and Control
2.3 DoDD O-5100.44: Defense and National Leadership Command Capability (DNLCC)
2.4 DoDD 3020.40, Mission Assurance
2.5 DoDD 3020.26, DoD Continuity Programs
2.6 DoDD 3020.44, DoD Policy & Responsibilities for Critical Infrastructure Protection
2.7 DoDD S-5210.81, US Nuclear Weapons Command and Control, Safety, and Security
2.8 DoDI 3000.08: Balanced Survivability Assessments (U/FOUO)
2.9 DoDI 2000.16, DoD Antiterrorism Standards
2.10 DoDI 6055.17, DoD Installation Emergency Management Program
2.11 DoDI 3020.52.17, DoD CBRNE Preparedness Standards
2.12 DoDI 2000.12, DoD Antiterrorism Program
2.13 DoDI 3020.39, Mission Assurance for DIE
2.14 DoDI 3020.45, Mission Assurance Construct
2.15 DoDI 5200.08, Security of DoD Installations and DoD Physical Security Review Board
2.16 DoDI 8500.01, Cybersecurity
2.17 DoDI 8510.01, Risk Management Framework for DoD Information Technology
2.18 DoD 5200.08-R, CH-1, Physical Security Program
2.19 CJCSI 5119.01B, Charter for Centralized Direction, Management, Operation, and Technical Support of the Nuclear C3 System
2.20 DTM 09-12, Interim Policy Guidance for DoD Physical Access Control
2.21 National Military Command System Concept of Operations
SCOPE
To ensure the continued support to the DTRA NE-MA Department’s customers and programs, it is imperative that the Department maintains a readiness posture to (1) conduct cyber assessments; (2) provide support to ensure the successful operation of the NE-MA Department’s operational programs; (3) conduct analysis in support of DoD and DTRA efforts. The size and skillsets of each team will vary and include those required to execute each mission. The resource needs of each mission and/or stakeholder request will be identified and managed by DTRA.
VULNERABILITY ASSESSMENTS
The NE-MA Department’s cyber component aims to identify vulnerability in critical systems, networks, and architecture that could be exploited well below the level of armed conflict by state or non-state actors, or that could be significantly impacted by natural or accidental hazards. This analysis is accomplished by assessing vulnerabilities through three distinctive lenses:
· Mission Assurance Assessments: The contractor team shall support the Government in identifying vulnerabilities affecting defense critical assets, task critical assets, and critical infrastructure that support defense critical missions. The assessment team work with installation and mission personnel to identify risks that may lead to mission loss or degradation, and provide recommendations for risk reduction based on DoD Mission Assurance Assessment benchmarks.
· Balanced Survivability Assessments: The contractor team shall provide a balanced look at the mission survivability of key DoD facilities and provide specific recommendations with supporting rationale to leadership. These assessments identify vulnerabilities within United States and Allied critical mission systems. The assessment team provides continuing support to infrastructure leadership to enable them to carry out a long-term investment strategy for risk management.
· Adversarial Assessments: The contractor team shall identify weaknesses that can be exploited. The contractor team shall perform assessments from an adversarial viewpoint and uses the full spectrum of identified adversarial capabilities, limited only by restrictions mandated by the customer and legal, safety, and security constraints, to test and evaluate protection strategies and demonstrate exploitation of identified vulnerabilities.
Components of these assessments include but are not limited to examining telecommunications (e.g., video, voice and data, commercial and military) and cyber space operations (e.g., computer networks, IA tools use, operations security). The NE-MA Department’s operational missions, by necessity, are fluid and requires adaptability to the operational need.
NE-MA Department’s cyber assessment teams may be deployed to high-threat but permissive environments anywhere in the world.
MISSION ASSURANCE DEPARTMENT SUPPORT
The Contractor shall provide adequate personnel with the requisite skills, certifications and/or licenses to fully support the NE-MA Department and the scope of work identified under Section 3 of this document. The Contractor shall provide adequate personnel to support up to 61 assessments/assignments, with a labor mix that is equally distributed across the labor categories (LCATs) specified in Section 4.1. Each team may consist of up to four (4) members. Each team can support up to eight (8) assessments. Assessments range from one (1) week to six (6) weeks in duration, from start to submission. DTRA may require a surge either in the number of LCATs or even require new capabilities as the assessment missions evolve. Assessment teams will comprise of a mix of contractor personnel and Government personnel. The Contractor is responsible for ensuring that its personnel are cleared at the TS/SCI level, ready to be in-processed, and ready to begin training/certification to be an assessor. The Government must be prepared to adapt to the changing needs of the environments and the threats to critical infrastructure.
All positions which provide subject matter expertise on an assessment team are deployable and must meet and maintain the following criteria.
· Adhere to CDC recommended immunizations for worldwide deployment.
· Be able to travel on short notice, work non-standard hours and take on-call duty.
· Obtain a Passport.
· Possess effective oral and written communication skills.
· Expert knowledge of Microsoft Office Suite. Ability to prepare written reports, white papers, and Power-Point presentations.
· Be capable of operating in all operational and physical environments and work collaboratively and professionally with USG military and/or civilian personnel.
The Contractor shall ensure that all on-site personnel assigned to this contract are ready to begin work within 45 days of contract award. The Contractor shall work cooperatively with other DTRA, NE-MA contractors performing other aspects of the NE-MA mission set. When tasked to by the DTRA PM or COR, the Contractor shall share information gathered in its assessments or otherwise work as part of an integrated DTRA team on assessments.
The Contractor shall also provide support to the NE-MA Department by attending and participating in relevant Department, Directorate, and Agency trainings, meetings, or other efforts to enable the Department, Directorate, and Agency to align its missions. The Contractor personnel must be ready to brief, present or collaborate on its area of expertise.
ASSESSMENT EXPERTISE
The Contractor shall provide personnel for the execution of each vulnerability assessment. The Contractor is responsible for providing its personnel all logistics and any ancillary support required to accomplish the mission. The size and make-up of each assessment team will be determined by the NE-MA Leadership. The NE-MA Department will require the following LCATs to successfully perform the assessments.
Cyber Space Operator shall perform vulnerability assessments on communications using computer networks, industrial control systems, radio, wireless, and other communication systems.
Senior Cyber Operators shall possess all the qualifications of a Cyber Space Operator noted in the preceding paragraph and shall also possess the following additional certifications:
· Possess IAT Level II and CSSP Auditor certifications as defined and described in Joint Publications 3-13 Information Operations and 3-12 Cyberspace Operations, DoDI 8500.1, DoD 8570.01 and 8570.01-M.
Cyber Transport Specialist shall identify all aspects of communications-related (i.e., DoD data voice networks, transmission systems, Defense Information Systems Network (DISN), and other DoD and Commercial terrestrial and satellite communications systems and networks) vulnerabilities, increase the customer’s awareness of potential vulnerabilities and impacts of communications on mission execution capability, and provide recommendations to mitigate or eliminate identified vulnerabilities.
Red Cyber Operator shall emulate a potential adversary’s cyber reconnaissance, exploitation techniques, and attack capabilities against a targeted mission, system, network, component, or capability.
Additional skills required for this position are as follows:
· Possess IAT Level III certification and CSSP Auditor certification as defined and described in Joint Publication 3-13 Information Operations and 3-12 Cyberspace Operations, DoDI 8500.1and DoD 8570.01 and 8570.01-M, and as amended.
IT SOFTWARE AND HARDWARE
DTRA, NE-MA requires expeditious procurements of IT software license, equipment, warranties, and maintenance support to sustain the Nuclear Enterprise Directorate (NE) and NE-MA Department mission essential needs. The Contractor shall be required to maintain an Equipment Procurement Plan (EPP) and the Master Government Property List (MGPL) in accordance with the contract data requirements list (CDRLs) referenced in Section 5 of this document. If software is procured by the Contractor, the Contractor shall track software licenses and notify the Government 60 days prior to any expiration of the licenses. The COR shall provide approvals of the license renewals in writing prior to the Contractor renewing the license(s).
PROGRAM MANAGEMENT
The Contractor shall actively manage this contract by coordinating closely with the DTRA COR and DTRA PMs. As part of the contracts management, the Contractor shall submit monthly reports in accordance with CDRL A001. The Contractor shall submit all reports on-time and with strict adherence to the instructions specified in each CDRL. At the COR’s request, the Contractor shall review statuses on any open task or assignment and travel reports with the COR.
Because of the multiple events and missions being executed simultaneously, the Contractor is required to provide mission coordination to assist the NE-MA assessment teams in executing all requirements seamlessly or near seamlessly. The Contractor is required to ascertain, and coordinate all site access requirements, liaise and coordinate with DTRA and other external stakeholders and end-users; and prepare each team for deployment and conclusion of each mission or event.
The Contractor shall also provide logistical coordination and ensure that the assessment teams are fully supported and resourced in a manner necessary to the conduct of assessments. The Contractor personnel shall travel both CONUS and OCONUS in support of the DTRA NE-MA mission and in execution of the requirements of this PWS. When traveling to locations designated by the Department of State as a danger/hazard pay post, the Contractor shall allocate the cost of the danger/hazard pay, consistent with the allowances provided by the Department of State, to the Travel CLIN on this contract.
· All travel must be compliant with the Joint Travel Regulations (JTR) unless otherwise specified by the COR. The Contractor shall follow CDRL A002 for submittal/approval of all proposed and actual travel.
· The Contractor shall at all times use reasonable efforts to pursue the most economical travel arrangements and minimize the cost of travel.
· The Contractor shall coordinate closely with the COR to arrange travel overseas, specifically when contractor personnel are to fall under a Status of Forces Agreement (SOFA) or other host nation agreements and/or when Synchronized Pre-deployment & Operational Tracker (SPOT) requirements are triggered. The Contractor shall comply with all requirements of the SPOT clauses included in the contract in a timely manner.
· The contractor employees shall comply with all DTRA mandatory travel reporting policies.
The Contractor shall also manage the all contractor acquired property and government furnished property. Contractor personnel performing work under this contract on-site will be provided with a Government workspace, a laptop, computer peripheries, Common Access Cards (CACs), DTRA e-mail accounts, access to Government file servers while off-site, and office supplies. However,
· The contractor personnel shall not use Government furnished equipment (GFE) for personal use. GFE may only be used by the Contractor for the execution of the tasks specified in this contract.
· The Contractor shall submit requests for replacement of GFE to the COR for processing. Lost or stolen GFE shall be verbally reported immediately, and followed up in writing within 24 hours of incident to the COR.
· The Contractor shall submit an EPP in accordance with CDRL A003 and the COR shall approve procurements of all items prior to the execution of any purchase totaling more than $5,000 under this contract.
· The Contractor shall submit a MGPL in accordance with CDRL A004 and the contract clauses.
Any accommodations not identified in this section are the responsibility of the contractor for their personnel.
PLACE OF PERFORMANCE
The Contractor is responsible for providing services to DTRA at the Fort Belvoir, VA and/or Crystal City, VA locations or other location as the mission requires. On Federal holidays or when DTRA is closed for business due to local or national emergencies, administrative closings, or similar Government directed closings, the Contractor is not expected to report to DTRA unless the mission requires performance. When DTRA is open for business but the DTRA facility is closed, the Contractor may conduct business offsite as directed by the DTRA COR. The Contractor must adhere to all building access requirements. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks identified within this PWS when the Government facility is not closed for one of the above reasons.
RECRUITMENT, RETENTION, REPLACEMENT, AND PERSONNEL PLAN
The Contractor shall notify the COR as soon as practicable of any departures or reassignments of personnel away from the performance of the tasks arising under this contract The Contractor shall propose a substitution as soon as practicable. No personnel substitutions or replacements shall be made by the Contractor without the prior written consent of the COR so that the COR can assess contractor qualifications meets the requirements stated herein and that the proposed candidate has the necessary qualifications to be cleared for access to the building and to work. The Government reserves the right to review qualifications of each substitution or replacement prior to consenting to the substitution or replacement.
When hiring personnel, the Contractor shall keep in mind that stability and continuity of the workforce are essential. The Contractor shall establish a transition plan for its personnel to ensure a seamless transition between in-coming and out-going contractor personnel. The Contractor shall also maintain a Personnel Recruitment, Retention, Replacement, and Surge Personnel plan to ensure that it remains agile and ready to meet the DoD Red Team mission requirements.
The Contractor shall replace lost personnel within 45 days.
SECURITY
The Contractor shall possess a DOD TOP SECRET clearance with an SCI caveat Facility Clearance. Contractor employees working on this program must be U.S. citizens and will require a DOD TOP SECRET clearance with an SCI caveat granted by the Defense Security Service (DSS). Clearances must be in place prior to contract award. A Visit Authorization Letter (VAL) must be provided for each contractor employee working on this contract who will require access to any DTRA site. The VALs for collateral security clearance shall be submitted in JPAS, contain the information specified in paragraphs 6-103, 6-104 and 6-105 of the National Industrial Security Program Operating Manual (NISPOM), and be submitted to the DTRA Security Support Branch (Visitor Control). The term of the VAL shall be for the term of the contract. The Contractor shall provide proof of U.S. citizenship for all contracted employees prior to entering the DTRC. The contractor shall comply with all terms of the DD 254, the NISPOM, the DoD 5220.22-M, NATIONAL INDUSTRIAL SECURITY PROGRAM, and any revisions to that manual. The contractor shall provide all forms and information, apply for clearances, and be responsible for any expense incurred in obtaining TOP SECRET/SCI security clearances for the contractor employees.
The contractor will produce some SECRET and/or TOP SECRET documents. The Contactor shall comply with all DoD requirements for marking, handling, storing and transporting classified documents, working papers, notes, media, etc. (herein referred to as documents) while in the possession of the contractor. This includes any document the contractor may generate in performance of this contract.
The contractor shall demonstrate sound and proven OPSEC practices, ensuring unclassified/sensitive information will be properly protected at all times, and abide by all DTRA OPSEC policies.
The Contractor shall adhere to all facility access control policies and procedures. Contractor personnel shall wear security identification badges at all times while in DTRA facilities, as access cards and Identification Cards (IDs) are presented upon request at all entry control points. Lost or stolen IDs or badges shall be verbally reported immediately and followed up in writing within 24 hours of incident to the DTRA COR.
The contractor must be responsible for safeguarding all Government property provided for contractor use. At the end of each work period, all Government property, equipment, and materials must be secured.
6. PERFORMANCE REQUIREMENTS SUMMARY
The contractor service requirements specified above are summarized into performance objectives that relate directly to mission essential items. The performance threshold briefly describes the minimum acceptable levels of service required for each requirement. These thresholds are critical to mission success. Contractor service requirements, performance metrics, and remediation plans are provided below.
PWS
Section
| Performance Objective |
| Performance Threshold |
| Method of Surveillance |
| Incentive/Disincentive |
| Section 4 |
| Perform all tasks specified in Section 4 without interruption and in accordance with DoD Issuances and DTRA NE-MA Department Guidelines and SOPs. |
| Tasks and deliverables are completed and submitted in accordance with DTRA NE-MA SOPs & CDRLS 100% of the time with accurate and complete information. |
| 100% review and inspection of documents submitted, and daily surveillance of performance. |
If Contractor meets or exceeds the performance threshold, it will:
(i) Contribute to a positive Schedule rating in CPARS.
(ii) Increase likelihood of option exercise.
If Contractor does not meet contract performance, remedies at FAR Clause 52.246-4 will be pursued, and/or likelihood of option exercise will be decreased.
| Section 5 |
| Provide sufficient personnel to perform all tasks specified in Section 4 without interruption. |
| Replace any departing personnel within 45 days. |
| Onsite surveillance. |
| Section 5 |
| The Contractor shall keep current all required certifications to perform the duties/roles of the appropriate LCAT. |
| At all times, the Contractor shall ensure its on-site personnel maintain and keep current all certifications. |
| Review of Progress Reports. |
File details come from the government source that posted it. Updated .