REES PERFORMANCE WORK STATEMEN.pdf

PDF 232 KB Posted

Attached to
REES Temperature System Server Migration Services Federal contract opportunity
Solicitation number
HT941025N0084
Issued by
Defense Health Agency

About this file

This Performance Work Statement (PWS) details a non-personal services contract for REES Temperature System Server Migration at Naval Medical Center San Diego. The contract will run from May 30, 2025 to May 29, 2026, with the contractor responsible for providing all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and services necessary to perform the server migration. Key objectives include updating the Rees Server in accordance with IMD regulations to better service the temperature system for optimal operation.

The contractor will perform work at Naval Medical Center San Diego, operating Monday through Friday except federal holidays. Specific cybersecurity and technical requirements include maintaining a test/laboratory environment, conducting monthly vulnerability scans, implementing security patches, ensuring IPv6 capability, and supporting continuous monitoring and risk management. The contractor must also comply with extensive Department of Defense information technology security protocols, including obtaining necessary access credentials, maintaining system authorization, and adhering to cybersecurity assessment and reporting requirements.

View the file

Other files for this federal contract opportunity

Other files attached to REES Temperature System Server Migration Services, newest first.
File Type Posted
Notice of Intent.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DHA PWS Template V13

November 16, 2021

PART 1

1.0 GENERAL INFORMATION

1.1 This is a non-personal services contract to provide Installation for REES Temperature

System Server Migration.

1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform [Server Migration] as defined in this Performance

Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.

1.3 Background: Services provided for Rees Server to up to date in accordance IMD regulations.

1.4 Objectives: Updates are required for IMD to better service the temperature system for optimal operation.

1.5 Scope: Services include: to install REES Temperature System Server Migration

1.6 Period of Performance (PoP): May 30, 2025 to May 29, 2026

1.7 Administrative specifications

1.7.1 Place of performance: The work shall be performed at Naval Medical Center San Diego.

1.7.2 Recognized Federal holidays: N/A.

New Year’s Day Labor Day

Martin Luther King Jr.’s Birthday Columbus Day

President’s Day Veteran’s Day

Memorial Day Thanksgiving Day

Juneteenth Day Christmas Day

Independence Day

1.7.3 Hours of operation: The contractor is responsible for conducting business Monday thru

Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.

November 16, 2021

1.11 Contractor personnel

1.11.1 CAC requirements: For all contractors who will work in Government facilities, the

Facilities Security Officer (FSO)/Company's Security point of contact (POC) will provide the

Government all the required information per the DHA CAC request process current version 2.1, January 2018, or more recent when updated. See process attached at Part 7 Section 7.1.1 of the

PWS. A CAC is the standard identification for eligible DoD contractor personnel.

1.11.1.1 The contractor shall return all CACs to the COR upon the departure of the contractor(s).

1.11.2 Contractor onboarding and training. The contractor shall complete all requirements, training, and forms as prescribed in the following requirements:

1.11.2.1 The DHA’s “Onboarding Checklist for Contractor Employees” is located at the DHA

Onboarding and Offboarding Portal at https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx

1.11.2.2 The DHA’s contractor training instructions embedded at Part 7 Section 7.1.2.

1.11.2.3 The contractor shall comply with onboarding requirements of the DHA for contractors needing to be issued CAC identification, including DoD- and DHA-directed training and forms submission, prior to network access, as displayed in the In/Out-Processing Portal at:

https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx (note: Public Key Infrastructure

(PKI)-restricted, printed versions available).

1.11.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.

1.11.4 Key control: The contractor shall establish and implement methods of making sure all keys/key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the contractor by the Government shall be duplicated. The contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas.

The contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the CO.

1.12 Key personnel (Contractor): The contractor shall provide a contract manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the CO.

The contract manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contract manager or alternate shall be https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx

November 16, 2021 available between 8:00 a.m. to 4:30 p.m., Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons.

1.14 Reporting

1.14.1 Contractor Manpower Reporting (CMR): RESERVED.

1.15 Contractor Identification

1.15.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy

Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel.

Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.

1.15.2 Contractor personnel will be required to attend meetings or otherwise communicate with

Government and/or other contract representatives to meet the requirements of this order.

Contractor personnel shall make their contractor status known during introductions.

1.15.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.

1.16 Contractor Access to Health Affairs (HA)/DHA Network(s)

1.16.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's

Personnel Security Office for a background investigation.

1.16.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the

DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.

1.17 Personnel Security

November 16, 2021

1.17.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce

Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated

March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance

Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care

Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA

Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM

5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:

1.17.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security

Office can be reached at (703) 275-6038.

1.17.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).

1.17.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.

PART 2

2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE

PUBLICATIONS/INSTRUCTIONS

2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D-

Services)

2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R-

Services)

2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.

2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to

November 16, 2021 the supervision and control usually prevailing in relationships between the Government and its employees.

2.2 Acronyms: IT, IS, and HMS

AIS Automated Information System

APL Approved Products List APL

AQL Acceptable Quality Level

ARRT Acquisition Requirements Roadmap Tool

ATO Authority to Operate

B2B Business-2-Business

CAC Common Access Card

CAP Cloud Access Point

CCEVS Common Criteria Cybersecurity Evaluation and Validation Scheme

CDI Covered Defense Information

CE Computer Environment

CDRL Contract Data Requirement List

CIO Chief Information Officer

CJCSM Chairman of the Joint Chiefs of Staff Manual

CMMC Cybersecurity Maturity Model Certification

CMR Contractor Manpower Reporting

CNSSI Committee on National Security Systems Instruction

CO Contracting Officer(s)

CONUS Continental United States (excludes Alaska and Hawaii)

COR Contracting Officer Representative

COTR Contracting Officer's Technical Representative

CSP Cloud Service Provider

CSSP Cyber Security Service Provider

CUI Controlled Unclassified Information

DAD-A Deputy Assistant Director for Acquisition

DC3 DoD Cyber Crime Center

DD Form 254 Department of Defense Contract Security Requirement List (if applicable)

DB Design-Build

DBB Design-Bid-Build

DFARS Defense Federal Acquisition Regulation Supplement

DHA Defense Health Agency

DISA Defense Information System Agency

DoD Department of Defense

DoDD Department of Defense Directive

DoDI Department of Defense Instruction

DSAs Data Sharing Agreements

DSAA Data Sharing Agreement Application

DMZ Demilitarized Zone

DoDM Department of Defense Manual

DPCLO DHA Privacy and Civil Liberties Office

DUA Data Use Agreement

November 16, 2021 eMSM Enhanced Multi-Service Markets

EULA End User License Agreement

EVM Earned Value Management

FAR Federal Acquisition Regulation

FCI Federal contract information

FE Facilities Enterprise

FedRAMP Federal Risk Authorization and Management Program

FISMA Federal Information Security Modernization Act

FRCS Facility Related Control Systems

FSO Facilities Security Officer

HA Health Affairs

HIPAA Health Insurance Portability and Accountability Act

HCA Head of the Contracting Activity

HIT Health Information Technology

IGCE Independent Government Cost Estimate

IA Information Assurance

IO Initial Outfitting

I/O In/Out Processing Portal

IPv Internet Protocol Version

IS Information System

ISP Internet Service Provider

IT Information Technology

ISCM Information Security Continuous Monitoring

IV&V Independent Verification & Validation

MedCOI Medical Community of Interest

MHS Military Health System

MIL-STD Military Standard

MTFs Military Treatment Facilities

NCR National Capitol Region

NDA Non-Disclosure Agreement

NIAP National Information Assurance Partnership

NIST National Institute of Standards and Technology

OCONUS Outside Continental United States (includes Alaska and Hawaii)

ODC Other Direct Costs

OPM Office of Personal Management

OSD Office of the Secretary of Defense

P-ATO Personal Authorization to Operate

P&R Personnel and Readiness

PGI Procedures, Guidance and Information

PDT Project Delivery Team

PHI Protected Health Information

PII Personally Identifiable Information

PIT Platform Information Technology

PK Public Key

PKI Public Key Infrastructure

POA&M Plan of Action and Milestones

November 16, 2021

POC Point of Contact

PMO Program Management Office

PoP Period of Performance

PP Personal Property

PPSM Ports, Protocols, and Services Management

PRS Performance Requirements Summary

PSP Personnel Security Program

PWS Performance Work Statement

QA Quality Assurance

QAP Quality Assurance Program

QASP Quality Assurance Surveillance Plan

QC Quality Control

QCP Quality Control Plan

RFP Request for Proposal

RFQ Request for Quotation

RMF Risk Management Framework

SP Special Publication

SPRS Supplier Performance Risk System

SRM Sustainment, Restoration and Modernization

SRG Security Requirements Guides

STIG Security Technical Implementation Guides

TOS Terms of Service

US United States

UFC Unified Facilities Criteria

VPN Virtual Private Network

XML Extensible Markup Language

PART 3

3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:

3.1 Services: The Government:

☒ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Government Furnished Services required in support of this contract/task orders. These Services are described below.

3.2 Facilities: The Government:

☐ Will NOT provide Facilities in support of this contract/task order. As a result, this paragraph is Not Applicable.

☒ WILL provide Facilities in support of this contract/task orders. The Government provided

Facilities are described below:

Government will only provide IT support all equiment will provided through the Rees Scientific

Corporation.

3.3 Utilities: The Government:

☒ Will NOT provide Utilities in support of this contract/task order. As a result, this paragraph is

Not Applicable.

☐ WILL provide Utilities in support of this contract/task orders. The Government provided

Utilities are described below:

3.4 Equipment: The Government:

☒ Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Equipment in support of this contract/task orders. The Government provided

Equipment is described below:

Contracting Office Responsibilities:

The Contracting Office shall ensure close coordination and validation of the GFP items with the

COR and DHA Accountable Property Officer prior to uploading the GFP Attachment into the

PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Contracting Office’s responsibility to prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The CO and COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.

The contracting office will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the

Contracting Office, and requested within the PIEE/GFP Module system.

Contractor Responsibilities:

November 16, 2021

A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a timely, complete and accurate accounting of the GFP applicable to the contract/task order. Contractors are required to report the receipt of any GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their contract. Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.

3.5 Materials: The Government:

☒ Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ IS providing Materials in support of this contract/task orders. The Government-provided

Materials are described below:

PART 4

4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES

4.1 Services: The Contractor:

☐ Will NOT provide Contractor Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.

☒ WILL provide Contractor Furnished Services required in support of this contract/task orders.

PART 5

5.0 SPECIFIC TASKS

5.1 Task Headings: Rees Server Migration: The contractor shall provide new server and assistance with the installion of the updated server.

5.1.1 Subtask heading:

5.2 Special Qualifications: No Special Qualifiactions required.

5.2.1 When using education/certification in conjunction with labor categories, the COR in coordination with the CO must establish a review process of contractor personnel to ensure labor category requirements are met.

PART 6

6.0 INFORMATION TECHNOLOGY & SECURITY

6.1 All work under this contract is [ Unclassified].

6.2.1 TIER II: Non-critical sensitive position.

6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements:

6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes

PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office

(DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into

DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect

MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data.

After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.

6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.

6.4 Training

6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements:

6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity

Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoD 8570.01-M. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.

6.4.1.2 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoD

8570.01–M, IA Workforce Improvement Program. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-2001, including:

6.4.1.2.1 DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01–M; and

6.4.1.2.2 Appropriate operating system certification for IA technical positions as required by

DoD 8570.01–M.

November 16, 2021

6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.

6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.

6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.

6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS:

6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication

(SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information

Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-

171), in accordance with DFARS clause 252.204-7012.

6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800-

171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment

Methodology requirement flows down to subcontractors.

6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier

Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/)

6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD

Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order.

See Attachment 2, Deliverable Schedule Table.

6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.

6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.

6.5.4 Cybersecurity Maturity Model Certification (CMMC) (When applicable): The CMMC

(DFARS clause 252.204-7021) builds upon the NIST SP 800-171 DoD Assessment

Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract https://www.sprs.csd.disa.mil/

November 16, 2021 information (FCI) and DoD Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk. The CMMC requirement flows down to subcontractors.

6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization

(3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.

6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.

6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.

6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management

Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.

6.5.8 Cyber Incident Reporting Requirement

6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:

6.5.8.1.1 Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other IS on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and https://www.cmmcab.org/ https://www.fedramp.gov/

November 16, 2021

6.5.8.1.2 In accordance with DFARS clause 252.204-7012, rapidly report (within 72 hours) cyber incidents involving DoD CUI to DoD Cyber Crime Center (DC3) via https://dibnet.dod.mil/portal/intranet/. In the event of a cybersecurity incident involving a CUI-

Specific breach (i.e., PII/PHI), the contractor, in addition to reporting to the DC3, shall follow the incident reporting guidance prescribed in the TRICARE Operations Manual, Chapter 1, Section 5, “Compliance with Federal Statutes” at https://manuals.health.mil/

6.5.8.2 Cyber incident report: The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements as prescribed at the https://dibnet.dod.mil/portal/intranet/.

6.5.8.3 Medium assurance certificate requirement: In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a

DoD-approved medium assurance certificate, see https://public.cyber.mil/

6.5.9 Malicious software: When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DC3 in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.

6.5.10 Media preservation and protection: When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected IS and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

6.5.11 Access to additional information or equipment necessary for forensic analysis: Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.

6.5.12 Cyber incident damage assessment activities: If DoD elects to conduct a damage assessment, the CO will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of DFARS clause 252.204-7012.

6.5.13 Apply other IS security measures when the contractor reasonably determines that IS security measures may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., HIPAA) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.

6.5.14 The contractor shall maintain within the US or US territories all Government data that is not physically located on DoD premises, unless the contractor receives written notification from the CO to use another location, in accordance with DFARS 239.7602-2(a).

6.5.15. The contractor shall mitigate supply chain risk to the government by complying with

DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN https://dibnet.dod.mil/portal/intranet/ https://manuals.health.mil/ https://public.cyber.mil/

November 16, 2021

Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).

6.6 Risk Management Framework (RMF) for DoD IT: All IS, Platform Information

Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data must be accredited in accordance with DoDI

8510.01, Risk Management Framework (RMF) for DoD IT and comply with annual Federal

Information Security Modernization Act (FISMA) security control testing. IS and PIT systems must be categorized in accordance with Committee on National Security Systems Instruction

(CNSSI) 1253, implement a corresponding set of security controls from the NIST SP 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.

6.6.1 All systems subject to RMF must present evidence of authorization in the System Security

Plan, Security Assessment Report) a Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD RMF or equivalent DoD Component PIT system accreditation decision that is current within 3 years within 5 business days of CO request.

Evidence of FISMA compliance must be presented in the form of a POA&M. Systems must have and maintain an Authority to Operate (ATO) or Authority to Operate with Conditions

(ATO-C) by contract award.

6.6.2 The contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37 Risk Management Framework

(RMF) and DoDI 8510.01, Risk Management Framework (RMF).

6.6.3 The contractor shall configure the information system in accordance with Defense

Information Agency (DISA) Security Requirements Guides (SRGs) and security technical implementation guides (STIGs).

6.6.4 The contractor shall ensure that the information system conforms to the requirements of

DoDI 8551.01 “Ports, Protocols, and Services Management (PPSM)”.

6.6.5 The contractor shall ensure that the information system shall authenticate all entities as specified in DoDI 8520.03 “Identity Authentication for Information Systems” prior to granting access.

6.6.6 The contractor shall Public Key (PK) enable the information system, implementing digital signature and encryption requirements specified in DoDI 8520.02, “Public Key Infrastructure

(PKI) and Public Key (PK) Enabling”.

6.6.7 The contractor will be responsible for compliance with the Joint Force Head Quarters –

Department of Defense Information Network issuances and IA Vulnerability Management

(IAVM) issuances by ensuring that the issuances are assessed, implemented and maintained throughout development and sustainment in accordance with specified timelines.

https://aplits.disa.mil/processAPList

November 16, 2021

6.6.8 The contractor shall support reciprocity, by providing all directed information in NIST security documents to the government.

6.6.9 The contractor shall implement system level protection and detection capabilities that are consistent with their contract for NIST Security requirements that meet DoD and DHA

Cybersecurity Architectures.

6.6.10 Cyber Incident Reporting Requirement: The contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.

6.6.11 Information security continuous monitoring (ISCM): ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur. The Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all ARRT and PIT systems under this requirement in accordance with NIST SP

800-137.

6.6.12 The contractor shall mitigate supply chain risk to the government by complying with

DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN

Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).

6.7. Facility Related Control Systems: (Applicable if Facility Related Control Systems

(FRCS) is utilized. If not replace section 6.7-6.7.10.14 and attachments three (3) through five

(5) with 6.7 FRCS: Reserved). The DHA’s Facilities Enterprise (FE) Program Management

Office (PMO) establishes the processes for acquisition, installation and sustainment of FRCS in

DHA Facilities. Requirements for cybersecurity of FRCS are developed and specified by the

FHA FE FRCS PMO. The scope of PIT and Control Systems within the DoD includes building control systems such as Heating Ventilation and Air Conditioning, Utility Management Control

System, Electronic Security Systems, Fire Alarm Systems, and other assets. The application of

IT cybersecurity strategies is migrating into PIT and Control Systems in response to emerging threats. The requirements within this scope apply to all versions of Design-Build (DB); Design-

Bid-Build (DBB); and facilities Sustainment, Restoration and Modernization (SRM) projects as well as Initial Outfitting (IO) requirements activities.

6.7.1 Applicability: Contractors shall agree to the DHA Cybersecurity requirements as outlined for those project-specific FRCS Systems selected from Military Standard (MIL-STD) 1691, (https://home.facilities.health.mil/military-standard-milstd-1691-equipment) and identified in the

DBB design process, D-B RFP development, SRM procurement documentation, or IO requirements unless an exception has been granted for a system by the Government prior to project award or procurement order issuance.

https://aplits.disa.mil/processAPList https://home.facilities.health.mil/military-standard-milstd-1691-equipment

November 16, 2021

6.7.2 Cybersecurity Design: Failure to meet the design requirements may result in Government non-acceptance of submittals or termination of the procurement delivery order for cause, in accordance with project documentation and FAR 52.212-4(m).

6.7.2.1 The contractor shall comply with Unified Facilities Criteria (UFC) 4-010-06

Cybersecurity of Facility-Related Control Systems, UFGS 25-05-11 Cyber Security for Facility-

Related Control Systems, and referenced standards to develop a Cybersecurity program for their

FRCS products to be installed in DoD facilities. The UFC system is prescribed by MIL-STD

3007 and provides planning, design, construction, sustainment, restoration, and modernization criteria, and applies to the Military Departments, the Defense Agencies, and the DoD Field

Activities in accordance with Under Secretary of Defense Acquisition, Technologies, and

Logistics Memorandum dated 29 May 2002. UFC will be used for all DoD projects and work for other customers where appropriate.

6.7.2.2 Contractors shall comply with the National Information Assurance Partnership (NIAP)

Common Criteria Cybersecurity Evaluation and Validation Scheme (CCEVS) evaluation

(https://www.niap-ccevs.org) which is published on the NIAP-CCEVS Products Compliance

List. The NIAP-certified products have been assessed from a security perspective, helping to reduce the existence of potential vulnerabilities. Contractors are required to continually maintain their products, mitigate vulnerabilities, and distribute fixes to licensed users.

6.7.2.3 The contractor agrees to comply with security regulations and guidance listed in

Attachment 3, Cybersecurity Regulations and Guidance, and all RMF requirements. The contractor shall establish appropriate administrative and technical safeguards to ensure the confidentiality, integrity, and availability of Government data under their control.

6.7.3 Funding of FRCS System/Device Requirements: Projects requiring new or replacement

FRCS, or upgrade/extension of existing devices/systems, employ either SRM, DB, or DBB acquisition strategies. Many FRCS are categorized as Real Property and are project funded.

Others are categorized through Military Standard 1691 as Personal Property (PP) requiring IO funding. The IO effort should preferably, and where feasible, be embedded in the SRM, DBB or

DB contract through Contract Line Items or another vehicle. This will optimize coordination of project-funded infrastructure design/construction with FRCS device/system design, installation, testing and commissioning. Where the project delivery team (PDT) determines that acquisition of PP devices/systems will be through IO action entirely separate to the SRM, DBB, or DB contract, the same RMF-related activities are required. These activities shall be fully integrated into the project master schedule.

6.7.3.1 Pricing for Cybersecurity: If there are any additional costs associated with any element of the Cybersecurity lifecycle including a test/laboratory environment, the Contractor shall provide those costs as follows:

6.7.3.1.1 All costs to assist the Government to achieve a new ATO and maintain it during the equipment’s warranty shall be included in the initial quote/offer price for SRM, and in the proposal for DB/DBB projects.

https://www.niap-ccevs.org/

November 16, 2021

6.7.4 FRCS Cybersecurity Requirements: The contractor shall provide a POC responsible for the cybersecurity of the contractor device or system, throughout the lifecycle of the product. The contractor shall provide Subject Matter Experts to support all assessments of contracted products and materials.

6.7.4.1 The contractor shall establish and utilize a test/laboratory environment that duplicates all contractor fielded equipment/product that falls within the FRCS system/device authorization boundary. The contractor shall ensure that all fielded equipment/product is maintained during the construction/installation period of performance, and for fifteen (15) years post acceptance or as long as the contractor commercially supports the equipment/product, whichever is longer.

6.7.4.2 The contractor’s test/laboratory environment shall be used to submit to the Government, either through the RFP response, procurement order offer/quote, or construction submittal process, with all sections of the FRCS Risk Assessment Questionnaire and a Nessus vulnerability assessment report.

6.7.4.3 Contractors must provide a fully credentialed Nessus scan of the laboratory environment utilizing the DoD policy template with the submission. In addition, Nessus scans shall be provided within ten (10) days of a request from the Government POC to ensure a continuous monitoring program. Nessus scanner must be procured by the contractor, at their own cost, in order to comply with RMF requirements. The contractor shall request the latest versions through the CO.

6.7.4.4 Contractors shall notify the assigned Government POC FRCS analyst of any updates/changes to the system and attain Government approval from the Military Treatment

Facilities (MTFs) Change Control Board prior to installation. This should include operating system updates/patches; contractor application and database upgrades, updates, and patches;

other software/firmware updates/patches; and addition/removal of components.

6.7.4.5 The contractor shall comply with DoDI 8500.01 Cybersecurity, Enclosure 3, paragraph

9.b.(11), requiring all cybersecurity products and IA-enabled products that require use of the product’s cybersecurity capabilities will comply with the evaluation and validation requirements of Committee on National Security Systems Policy 11, National Policy Governing the

Acquisition of IA and IA-Enabled Information Technology Products, June 2013, as amended.

6.7.4.6 The contractor shall comply with DoDI 8510.01, Enclosure 6, para 2.f(6)(a), ensuring systems must be reassessed for reauthorization prior to the Authorization Termination Date.

Government Program Offices or appropriate facilities organizations plan for this activity. The results of an annual cybersecurity review or a negative change to the system or environment at any time (i.e., a change increasing the residual risk) may result in a need for reauthorization prior to the regular three-year reauthorization.

6.7.4.7 If the FRCS is Internet Protocol capable, the proposed system shall be Internet Protocol

Version 6 (IPv6) capable or the contractor shall provide a detailed project, migration or planning documentation to show when the proposed system shall be IPv6 capable. The contractor shall be able to demonstrate or provide documentation to prove that their product is IPv6 capable.

6.7.4.7.1 Minimum IPv6 capabilities include:

(a) Conformant with the IPv6 standards profile contained in the DoD IT Standards Registry

(DISR);

(b) Maintaining interoperability in heterogeneous environments with IPv4;

(c) Commitment to upgrade as the IPv6 standard evolves;

(d) Availability of contractor IPv6 technical support.

6.7.4.8 The contractor shall notify the Government POC and CO POCs in writing with any inabilities to comply with DoD security requirements. The contractor will provide anticipated costs and timelines required to address any vulnerabilities in question.

6.7.5 Post Award Requirements: Contractor provided network infrastructure components (e.g.

switches, routers, etc.) shall be standardized to the existing MTF network infrastructure where possible and shall be listed on the DoD Information Network Approved Products List (APL)

(https://aplits.disa.mil). Operating systems and firmware shall be the most current government approved version approved for infrastructure components, workstations, and servers.

6.7.5.1 As technology requirements change and compliance requirements transition, the contractor shall maintain their solution and incorporate new system/device capabilities and requirements into their proposed design. Contractors should at a minimum provide documentation that details what changes/requirements cannot apply to the current version and provide a schedule when the capabilities will be incorporated into future versions to ensure continued compliance and functionality.

6.7.5.2 The contractor’s installed device or system shall pass pre-validation technical screening including fully-credentialed vulnerability scans utilizing Nessus, Security Content Automation

Protocol scans, and STIGs checklists within 6 months of construction submittal acceptance, or procurement contract award, and prior to related commissioning activity or acceptance testing.

All resulting documentation will be provided by the contractor to the Government POC for review. The contractor shall mitigate or remediate all Very High, High, and Moderate severity vulnerabilities discovered during the RMF Assessment process according to the associated

POA&M.

6.7.5.2.1 Successful pre-validation technical screening must meet the Cybersecurity criteria listed below:

(a) No unmitigated Very High or High severity, vulnerabilities as described in the appropriate

DISA STIGs located on https://public.cyber.mil/stigs/.

(b) No unmitigated Moderate severity, vulnerabilities described in the appropriate DISA STIGs located on https://public.cyber.mil/stigs/.

(c) No unmitigated Very High or High severity vulnerabilities from Nessus vulnerability scans.

(d) No unmitigated Moderate severity vulnerabilities from Nessus vulnerability scans.

6.7.5.2.2 The contractor will provide the following documentation on their system/device:

https://aplits.disa.mil/ https://public.cyber.mil/stigs/ https://public.cyber.mil/stigs/

November 16, 2021

(a) Manufacturer name/model, version, and functionality description

(b) Product specifications

(c) Technology Architecture Diagram (System topology)

(d) Provide Hardware, Software, and Firmware Inventory

(e) Provide Ports Protocols and Services that are required for System functionality

(f) Provide a data flow diagram with detailed topology (include any required interfaces to other

Systems)

(g) Complete a DD Form 2930, Privacy Impact Assessment

6.7.5.3 In DBB and DB contracts, the contractor shall submit requests for the templates and any additional technical documentation through the standard RFI process. Completed documents shall be provided to the Government though the standard Submittal process for Government

Approval. For SRM projects and IO requirements, the contractor shall submit a request for the templates and any technical documentation within twenty (20) days of contract award. The required schedule for requests and responses is identified in the timeframes below for each acquisition strategy. Attachment 4, FRCS Responsibility Matrix, provides a Responsibility

Matrix overview of the project roles and responsibilities.

6.7.5.4 For all devices/systems requiring an ATO:

(a) For SRM projects and IO requirements, the contractor shall not make any delivery and shall not receive payment for the until the Government POC has approved the self-assessment of the test/laboratory environment. The contractor must receive written confirmation from the CO that the system/device has successfully completed a self-assessment and that the contractor may proceed with delivery. Delivery may take place prior to this milestone only if written permission is provided by the CO.

(b) For DBB and DB MILCON-funded FRCS, the contractor proceeds at his own risk if the contractor has not received Government approval that the system/device has successfully completed a self-assessment. Once the system/device has been installed, commissioning or acceptance testing shall not proceed until the Government POC, with contractor support and mitigation, has completed a successful self-assessment of the installation, and the Independent Verification & Validation (IV&V) has been scheduled (if required).

An IV&V cannot be scheduled until all documentation requirements and technical requirements have been completed to the Government POC’s satisfaction. Additionally, all required POA&Ms must have been identified, and been appropriately mitigated to reduce the risk to the Government network and PHI/PII/For Official Use Only data housed within the system.

6.7.5.5 A contractor’s technical solution that requires an Assessment and Authorization shall be able obtains a recommendation of ATO from a Government-appointed third-party validator within twelve (12) months of the successful installation self-assessment.

6.7.6 Cybersecurity Assessment: The contractor’s solutions shall be configured to allow

Endpoint protection, allow unattended credentialed scans, and allow patching without contractor intervention.

November 16, 2021

6.7.6.1 The contractor solution shall comply with DoD Instruction 8582.01, “Security of Non-

DoD Information Systems Processing Unclassified NonPublic DoD Information. Devices and systems must be configured in such a way that allows the updating of malware definition signatures on a scheduled basis. Scanning shall encompass the entire system (file system, operating system, and real-time processes) by default. In cases where scanning of the entire system may negatively affect its operation, the contractor shall provide a detailed list of exclusions with justifications. The contractor shall provide technical specifications that clearly demonstrate whether the proposed solution can integrate and support either the full security suite or the individual components (e.g. Data Loss Prevention, Intrusion Prevention System, Antivirus, etc.) without performance degradation of the contractor device or system.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .