Atch_2_-_PWS.pdf

PDF 196 KB Posted

Attached to
AMC Phased Array Federal contract opportunity
Solicitation number
HTC711-15-Q-D059
Issued by
Department of Defense United States Transportation Command

About this file

Attachment 2 PWS

View the file

Other files for this federal contract opportunity

Other files attached to AMC Phased Array, newest first.
File Type Posted
Phased_Array_Q A's.pdf PDF
Atch_2_-_PWS_Amendment_01.pdf PDF
Phased_Array_Q A's.pdf PDF
Phased_Array_Q A's.pdf PDF
Combined_Synopis-Solicitation_Notice_Final.pdf PDF
Atch_6_-_Past_Performance_Questionnaire.pdf PDF
Atch_3_-_Provisions_and_Clauses.pdf PDF
Atch_4_-_DD254.pdf PDF
Atch_1_-_Info_Sheet.pdf PDF
Atch_7_-_PP_Log.pdf PDF
Atch_5_-_PP_Reference_Submission_Sheet.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 2

AIR MOBILITY COMMAND (AMC) PHASED ARRAY PASSIVE RADIO FREQUENCY

IDENTIFICATION (pRFID) INSTALLATION PROJECT

PERFORMANCE WORK STATEMENT (PWS)

8 April 2015

1. DESCRIPTION OF SERVICES

1.1. Background

As the lead DOD proponent for radio frequency identification (RFID), USTRANSCOM is focused on implementing AIT throughout the supply chain to maximize the effectiveness of the deployment and distribution decisions. Effective use of AIT will streamline DOD logistics business processes and enhance its warfighting capabilities. USTRANSCOM will continue to assess technology, examine warfighter AIT needs and update policies to provide the military forces with integrated AIT solutions.

As a primary conduit to the broader deployment and distribution enterprise, AIT plays a key role in providing decision makers with the ability to shape and respond to ever changing force requirements and closure profiles. The United States Air Force (USAF) Air Mobility Command (AMC) has determined that passive RFID (pRFID) may prove beneficial to the aerial port special handling sections to track cargo and hazardous material. This technology will be used to automatically capture data from International Organization for Standardization (ISO) tags attached to inbound cargo. The tag would be processed to verify availability of cargo Advance Transportation Movement and Control Document (ATCMD) data and provide automatic inventory management by keeping bay location inventory and maintain segregation of hazardous material while keeping a record of arrival and departure times.

1.2. Scope

The contractor shall be responsible for conducting a technical site survey to facilitate the design and installation of a Phased Array technical solution to enhance aerial port business processes. The contractor shall be responsible to install the approved technical solution using non-proprietary hardware and software. The contractor will procure and install all hardware and software in the designated aerial port area. The contractor will provide training on the installed Phased Array system to a limited number of government personnel.

The contractor shall be responsible for ensuring the accuracy, timeliness, and completion of all requirements stated in this PWS. The contractor shall comply with all DOD pRFID standardized protocols and network security requirements. The contractor shall follow all Defense Information Initiative (DII) Common Operating Environment (COE) procedures and requirements, where applicable.

The specific task areas are:

Task 1: Project Management Task 2: Site Survey Task 3: Purchase of Equipment Task 4: LAN and Power Task 5: Installation and Testing of Phased Array System Task 6: Training

1.3. Specific Tasks

1.3.1. Task 1: Project Management

Project management shall be event oriented with scheduled reviews and risk management. The contractor shall use proven analysis and business practices to reduce the time, cost, and schedule.

The contractor shall provide a Project Manager (PM) to facilitate Government-Contractor communications. The PM shall be the primary technical and managerial interface between the contractor and the Contracting Officer and the COR. Written notification of the name, address, and telephone number of the PM, and his or her alternate, shall be provided to the Contracting Officer and COR the first day of contract performance and thereafter as changes occurs. The PM or in their absence, the designated alternate, shall have full authority to act for the contractor on all matters relating to daily operations of the contract. The Project Manager responsibilities include, but are not limited to, interfacing with Government management personnel, staffing of all tasks, formulating and enforcing work standards, assigning schedules, reviewing work discrepancies, and communicating policies, purposes, and goals of the organization to subordinates. The PM or in their absence, the designated alternate, must be available during normal duty hours and be able to meet with Government personnel within one (1) business day to discuss problems. The PM shall meet with the Contracting Officer and COR as necessary to maintain satisfactory performance and to resolve other issues pertaining to Government/Contractor procedures.

1.3.1.1. Subtask 1: Project Management Plan

The development of an accurate Project Management Plan (PMP) provides the framework from which to integrate the project schedule and technical performance data. The contractor shall develop and maintain a PMP. A draft PMP shall be delivered five (5) business days after the contract start date. The Government will review and provide comments. A final shall be delivered five (5) business days after receipt of Government comments. The contractor shall update its Plan, as necessary, and provide updated versions as part of the weekly status meeting.

1.3.1.2. Subtask 2: Kick-Off Meeting

The contractor shall initiate work on this contract by meeting with the key Government representatives (Contracting Officer, Contracting Officer Representative (COR)/Project Manager) to ensure a common understanding of the requirements, expectations, and ultimate end products. The contractor shall conduct this meeting by teleconference with the key Government representatives NLT 1 week after award. The contractor shall discuss the overall understanding of the project and review the background information and data provided by the Government. Discussions shall also include the scope of work, deliverables to be produced, how the efforts will be organized and the project conducted, assumptions made/expected and results. Nothing discussed in this or any subsequent meetings or discussions between the Government and contractor shall be construed as adding, deleting, or modifying any contract requirements, including deliverable specifications and due dates. The contractor shall prepare and distribute, via e-mail, the meeting minutes within three (3) business days after the meeting.

1.3.1.3. Subtask 3: Weekly Status Meeting

The contractor shall conduct a weekly status meeting with the COR via teleconference. The contractor shall develop a meeting agenda and minutes template which includes issue/action item tracking and funds status. Following the weekly status meeting, the contractor shall produce and distribute status meeting minutes within one (1) business day after the meeting.

1.3.2. Task 2: Site Survey

The contractor shall conduct a site survey at Travis AFB, CA aerial port Special Handling/Security Cage area, to evaluate infrastructure requirements, to validate cargo functional processing requirements, and to identify port facility construction characteristics affecting efficiencies and effectiveness of using a Phased Array system. The contractor shall be responsible for evaluating infrastructure requirements to identify the necessary support equipment, software, network communications, and facility support required. At the completion of the site survey, the contractor shall recommend pRFID equipment and software for best data capture based on cargo requirements (IE Security Cage cargo, Explosives, Hazardous materials) at the location. The contractor shall brief the Government and designated personnel at the aerial port on the project. The site survey and report will be complete within 30 calendar days after contract award. The contractor shall determine the type and location of hardware to provide a Phased Array interrogation of pRFID tags on cargo arriving and presiding in the Special Handling/Security Cage area. Interrogations of pRFID tags should be done on arrival and at specified inventory times on each shift. The contractor shall provide drawings/photographs showing the proposed positions of the hardware. The contractor shall determine LAN and power requirements to support the required hardware installation. The contractor shall coordinate all installation plans and requirements with the host base support services offices (e.g., Civil Engineering, Safety, Fire Department, and Communications, etc.).

Within five (5) business days of the site survey completion, the contractor shall deliver to the COR a detailed Site Survey Report that identifies the location of all recommended equipment, software applications, and supporting infrastructure (e.g., LAN drops, facility electrical power, etc.) . During the site survey, the contractor shall, to the maximum extent possible, ensure that recommendations comply with the following Air Force security publications (current version):

AFI33-129 WEB Management and Internet Use AFI33-201 Communications Security (COMSEC) AFI33-219 Telecommunications Monitoring and Assessment Program (TMAP)

1.3.3. Task 3: Purchase Equipment

The Contractor shall purchase the pRFID phased array equipment, as identified in the pRFID Site Survey, once approved by the Government. Hardware delivered under this contract, as appropriate, shall include all antennas, interrogators, controllers, connectors, cables, adaptors, and other associated hardware required for operations, as provided by the Original Equipment Manufacturer (OEM). The contractor shall be responsible for purchasing the recommended equipment (interrogation equipment, related equipment controller software, and infrastructure support (e.g., electrical power, Local Area Network cabling, etc.)) for the location to support the desired interrogation operations once approved by the Government. The contractor shall confirm the software to be used is listed on the Air Force Evaluated/Approved Products List (AF E/APL). The contractor shall provide an initial set of 1000 pRFID tags. All hardware/equipment and software shall be delivered to the aerial port address that will be provided to the contractor by the Government. All hardware/equipment and software must be ordered no later than five (5) business days after Government approval. Any software applications delivered under this contract shall include any required sub- applications for use with the pRFID readers and the already installed aerial port RFID Edge- Servers as identified in the aerial port Site Survey Report. The contractor shall provide the COR a finalized inventory and description listing of all pRFID equipment and software applications purchased under this contract after the site survey is completed, but no later than 30 calendar days after contract award.

1.3.4. Task 4: LAN and Power

Once site surveys are complete, and if required, the contractor shall coordinate with the base for designation of a local contractor to install LAN and power at Travis AFB, CA. Government personnel will ensure completion of LAN and power installation and provide confirmation to the contractor.

The Government and contractor shall determine a mutually agreed upon date of LAN power depending on contract award.

1.3.5. Task 5: Installation and Testing of Phased Array system

The contractor shall install the approved Phased Array system at Travis AFB, CA aerial port Special Handling/Security Cage area that was approved by the Government. Testing will require 100% accountability of each bay location while being able to identify cargo that is placed in the wrong bay.

Software should be able to identify incompatibility of hazardous materials. Software will need a way to associate pRFID tags to cargo that arrives without a pRFID tag. The pRFID system needs to provide special handling area zonal coverage and the ability to isolate individual shipments within a particular zone. The contractor shall provide a way to print Military Shipping Labels (MSL) with passive RFID labels for cargo that arrives without a pRFID tag attached. The contractor shall ensure the software and hardware selected is compatible with and would have the ability to transmit data to Global Air Transportation Execution System (GATES).

Specific Requirements.

• Passive RFID system installed must be compatible around munitions and hazardous materials.

• Project must be able to accurately gather passive RFID tag read data tags in special handling bays / Enclosed Security Cage.

• The passive RFID hardware footprint must be kept to a minimum while providing adequate coverage at the site.

• The passive RFID hardware should be installed to allow for 100 percent tag reads for all bays.

• The passive RFID readers must be located in an area that does not interfere with business operations or cause a local frequency conflict.

• The ability of the technology to provide zonal coverage and isolate individual shipments within a particular zone is paramount.

• Once passive RFID tag reads are captured, the system should be able to store, transmit and record the data so that users can compare with data in GATES (Global Air Transportation & Execution System).

• Meet information assurance requirements including providing documentation or information necessary to obtain or maintain approval to allow the passive RFID infrastructure to be connected to Service network.

• Passive RFID system must have the ability to back up data in the event the primary system fails.

• Implement a standalone solution with plans for passive RFID system to integrate inventory data with GATES if data from the test proves to be beneficial.

• Training on-site government personnel of the passive RFID system is needed.

• Print current inventory anytime while always providing current up to date inventory.

1.3.6. Task 6: Training

The contractor shall provide training on the Phased Array System to designated government aerial port personnel, not to exceed 5 personnel. Training will take place after installation, testing and acceptance.

1.4. DELIVERABLES

All deliverables shall meet professional standards and meet the requirements set forth in contractual documentation. The contractor shall provide all deliverables electronically, and other than software, in Microsoft Office (Word, Excel, PowerPoint, Project, etc.) formats pursuant to the following schedule. The deliverables are not separately priced, but are included in the firm-fixed price. All technical data delivered under this task order are developed exclusively at the Government’s expense, and in accordance with Department of Defense Federal Acquisition Regulation Supplement (DFARS) 252.227-7015, the Government has unlimited rights in these deliverables.

PWS Para Deliverable Title Delivery Schedule

1.3.1.1. Project Management Plan Draft – five (5) business days after the contract start date Final – five (5) business days after receipt of Government comments Update – as necessary, as part of the weekly status meeting

1.3.1.2. Kick-Off Meeting Minutes Within three (3) business day after the kick-off meeting

1.3.1.3. Weekly Status Meeting Minutes Within one (1) business day after the weekly status meeting

1.3.2. Travis Aerial Port pRFID Site Survey

Report

Within five (5) business days of the site survey completion, all site surveys must be complete within thirty (30) calendar days of contract award

1.3.3. Hardware/Equipment and Software

ordered

No later than five (5) business days after Government approval for purchase

1.3.3. Hardware/Equipment and Software

Purchase Inventory List

After site survey is completed but no later than 30 calendar days after contract award

1.3.4. LAN and Power install Mutually agreed upon date

1.3.6. Provide user training Provide User training after installation, testing and acceptance.

2. SERVICE DELIVERY SUMMARY

The Services Delivery Summary (SDS) represents the most important task order objectives that, when met, will ensure task order performance is satisfactory. Although not all PWS requirements are listed in the SDS, the contractor is fully expected to comply with all requirements in the PWS.

PWS Para Performance Objective Performance Threshold

1.3.1.3. Weekly Status Meeting Minutes 90% of the time minutes are received within one (1) business day after the weekly status meeting

1.3.2. Travis Aerial Port pRFID Site Survey

Report

Report is delivered within five (5) business days of the site survey completion and contains location and type/quantity of equipment to be purchased and installed. All site surveys were completed within 30 calendar days of contract award

1.3.3 Hardware/Equipment and Software

order

Hardware/Equipment and software was ordered NLT five (5) business days after Government approval to purchase

1.3.3. Hardware/Equipment and Software

Purchase Inventory List

Report is delivered after each site survey is completed but no later than 30 calendar days after contract award and contains, where applicable, equipment descriptions, part numbers, serial numbers, version numbers, etc…

1.3.4 LAN and Power install Mutually agreed upon date

1.3.5. Testing of Phased Array System 100% of the time, 100% of the tags are read and shown in proper location.

3. GOVERNMENT FURNISHED RESOURCES

The Government will provide necessary and reasonable access to buildings, system equipment, hardware and software required, personnel, and will provide appropriate working space for contractor personnel as required. The Government will work with the designated base POCs to arrange base access for the contractor or employees of the contractor. The contractor shall provide the Government a listing of personnel needing access. The Government will support the survey team by providing knowledgeable cargo process functional representatives to identify the cargo flow in and out of the aerial port while the survey team is on site. The Government will provide authorization to use a digital camera for photographs of the choke points to use in the site survey, and to use a Spectrum Analyzer to identify possible interference areas. The Government will provide background information on the direction of pRFID use within AMC. The RFID Edge-Server equipment will be furnished by the Government.

4. GENERAL INFORMATION

4.1. Place of Performance

The contractor shall conduct project management, telephonic meetings, any necessary interface software development, and documentation development activities at their facilities. The contractor shall conduct a pRFID technical site survey at Travis AFB, CA.

4.2. Period of Performance

The period of performance for this effort shall commence at date of award and must be completed no later than 15 Sept 2015. Normal duty hours at each location are between 7:30 AM and 5:00 PM local time.

4.3. Travel

Performance under this contract will require contractor travel within the Continental United States. The Government will reimburse the contractor for travel expenses subject to the Federal Acquisition Regulation (FAR) and the Joint Travel Regulation (JTR). All contractor travel shall be coordinated with and validated by the primary or alternate COR prior to incurring any travel expenses. The contractor shall identify personnel who will be traveling in sufficient time to obtain the lowest possible rates for airfare, rental car and lodging. For long distance travel, a minimum of five (5) business days advance notice from the travel commencement date is required. The travel request shall be in writing and contain the dates, location, and estimated travel costs. Contractor invoices (along with associated receipts) shall support all travel reimbursement requests.

Task Number of Trips Number of Days

Number of People

1.3.2 Travis AFB, CA Site

Survey

1 4 2

1.3.5 Travis AFB

Installation / Testing

1 5 3

4.4. Other Direct Costs (ODCs)

The Government will reimburse materials and fees incurred in the performance of the PWS based on prior coordination with the COR. The contractor shall request authorization from the COR to procure items or services that will be billed under the ODC Contract Line Item Number (CLIN), and shall obtain written authorization from the COR prior to purchasing or incurring any expenses. Any unforeseen requirements must be coordinated with the Government prior to incurring any expenses.

4.5. Software and Hardware Purchases

The contractor, at the Government’s request, shall support the procurement of software licenses, maintenance agreements, and hardware necessary for the completion of work under this requirement.

Prior to the purchase of the software/hardware, the contractor shall provide the COR with estimated costs of the items and await authorization to purchase from the COR.

Any software licenses acquired that will become part of the pRFID Phased Array System installation shall be transferrable to the Government upon the request of the Contracting Officer, or upon contract completion. The Government will provide the contractor with the necessary Government information, to include but not limited to, points of contact, to be included on the transferable software license and hardware maintenance agreements where applicable. It is the contractor’s responsibility to ensure that all such licenses fully comply and are consistent with applicable Federal law and regulations. In order to assure compliance, prior to the contractor’s purchase of any software license, the contractor shall forward the proposed vendor software license to the Contracting Officer for review and comments. The Government shall complete its review and provide comments on license deficiencies to the contractor within ten (10) business days after receipt of the software license.

Upon receipt of the Government’s comments, the contractor shall negotiate with the vendor to resolve all the Government’s comments. If the contractor determines resolution is not possible, the contractor shall recommend to the Government a different software product with license terms consistent with Federal law.

4.6. Contractor Furnished Equipment and Services

Except for those items or services specifically stated in paragraph 3, the contractor shall furnish everything needed to perform this contract.

4.7. Contractor Employee Qualifications/Certifications

The contractor shall be responsible for managing and overseeing the activities of all contractor personnel, as well as sub-contractor efforts used in performance of this effort. The contractor’s management responsibilities shall include all activities necessary to ensure the accomplishment of timely and effective support, performed in accordance with the requirements contained in the performance work statement.

The contractor shall ensure that all personnel employed to perform services under this contract are qualified, trained, certified, and licensed, in accordance with applicable laws and regulations.

4.8. Inspection, Acceptance and Quality Assurance

Reports and other deliverables will be reviewed and accepted at the place of delivery by the COR. The following general quality measures will be applied to each deliverable received from the contractor:

Accuracy, deliverables shall be accurate in presentation, technical content, and adherence to accepted elements of style; Clarity, deliverables shall be clear and concise and all diagrams shall be easy to understand and be relevant to the supporting narrative; Consistency to Requirements, deliverables shall satisfy the requirements of the PWS; File Editing, all text and diagrammatic files shall be editable by the

Government; Format, deliverables shall be submitted in electronic and non-proprietary format; and Timeliness, deliverables shall be submitted on or before the due date specified in the PWS.

The COR will review, for completeness, preliminary or draft documentation that the contractor submits, and may return it to the contractor for correction. Absence of any comments by the COR shall not relieve the contractor of the responsibility for complying with the requirements of the PWS. Final approval and acceptance of documentation required herein shall be by letter of approval and acceptance by the COR.

The contractor shall not construe any letter of acknowledgement of receipt as a waiver of review, or as an acknowledgement that the material is in conformance with this PWS. Any approval given during preparation of the documentation, or approval for shipment shall not guarantee the final acceptance of the completed documentation.

4.9. Correspondence

To promote timely and effective administration, correspondence shall be subject to the following procedures: Technical correspondence (where technical issues relating to compliance with the requirements herein) shall be addressed to the COR, with an informational copy to the Contracting Officer; and all other correspondence ( that which proposed or otherwise involves waivers, deviations, or modifications to the requirements, terms or conditions of this contract) shall be addressed to the Contracting Officer, with an informational copy to the COR.

4.10. Non-Disclosure Agreement (NDA) for Contractor Employees

Information made available to the contractor by the Government, for the performance or administration of this effort, shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer. The contractor agrees to assume responsibility for protecting the confidentiality of Government records which are not public information. Each contractor or employee of the Contractor to whom information may be made available or disclosed shall be notified in writing by the contractor that such information may be disclosed only for a purpose and to the extent authorized herein.

Performance of this effort may require the contractor to access and use data and information proprietary to a Government agency or Government Contractor which is of such a nature that its dissemination or use, other than in performance of this effort, would be adverse to the interests of the Government and/or others.

Contractor and/or contractor personnel shall not divulge or release data or information developed or obtained in performance of this effort, until made public by the Government, except to authorize Government personnel or upon written approval of the Contracting Officer. The contractor shall not use, disclose, or reproduce proprietary data that bears a restrictive legend, other than as required in the performance of this effort. Nothing herein shall preclude the use of any data independently acquired by the contractor without such limitations or prohibit an agreement at no cost to the Government between the contractor and the data owner which provides for greater rights to the contractor.

Completion of non-disclosure statements will be required by contractor personnel to ensure information that is considered sensitive or proprietary is not compromised. All contractor personnel will be required to sign a NDA. The Government will retain these documents. See Appendix 3, Non-Disclosure Agreement.

The contractor may also be required to sign a non-disclosure agreement in accordance with DFARS 227.7103-7 if access to required technical data or computer software that was delivered to the Government with restrictions as described in DFARS 227.7103-7. Before obtaining access to another contractor’s proprietary information, in accordance with FAR 9.505-4, the contractor must agree with the other company to protect the information and complete necessary agreements and furnish such agreements to the Contracting Officer.

4.11. Packaging, Packing and Shipping Instructions

The contractor shall provide all deliverables and other project related products, reports, etc., as an electronic file e-mail attachment whenever possible. The contractor shall generate all document deliverables in standard office automation software products, i.e. standard Microsoft Office products. If the contractor determines that it would be more beneficial to use non-standard office automation software to generate any of the required deliverables, the contractor must notify and receive approval from the COR prior to generation of those deliverables. In the event deliverables cannot be delivered via e-mail they shall be delivered on Compact Disc (CD). Multiple deliverables may be combined on a CD.

4.12. Payment for Unauthorized Work

No payments will be made for any unauthorized supplies and/or services or for any unauthorized changes to the work specified herein. This includes any services performed by the contractor on their own volition or at the request of an individual other than a duly appointed Contracting Officer. Only a duly appointed Contracting Officer is authorized to change the specifications, terms, or conditions under this effort.

4.13. Section 508 Compliance Requirements

Any/all electronic and information technology (EIT) procured through this effort must meet the applicable accessibility standards at 36 CDR 1194. 36 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at http://www.section508.gov.

5. CYBER SECURITY

5.1. Handling of Non-Public Information

In performance of this contract, the contractor may have access to Department of Defense (DOD) information . The contractor agrees (a) to use and protect such information from unauthorized disclosure IAW DOD Instruction 8582.0 I : Security of Unclassified DOD Information on Non-DOD Information Systems; (b) to use and disclose such information only for the purpose of performing this contract and to not use or disclose such information for any personal or commercial purpose;

(c) to comply with other current Federal and DOD information protection and reporting requirements for specified categories of information (e.g., medical, proprietary , critical program information (CPI), personally identifiable infomation , export controlled); (d) to obtain permission of the Government Requiring Activity before disclosing/discussing such information with a third party; (e) to return and/or electronically purge, upon Government request, any DOD information no longer required for contractor performance; and (f) to advise the Contracting Officer (CO) and/or Contracting Officer's Representative (COR) of any unauthorized release of such information.

5.2. Periodic Government Inspections

The contractor (and its subscontractors) shall authorize Government inspections and reviews of its unclassified IT environment where DOD information is resident or transiting to assure compliance with DOD cyber security requirements throughout the contract performance period. The contractor shall be responsible for taking corrective action based upon the impact and severity of identified weaknesses. The Government will limit inspections to a maximum of one per year. The contractor shall a llow follow-on visits, if requested, to confirm resolut ion of any s ignificant weaknesses identified during the inspections.

5.3. Remote Access

Contractor Furnished Equipment (CFE) employed for remote access to a Government network must meet or exceed equivalent Government Furnished Equipment (GFE) cyber security computing requirements.

The contractor shall ensure that a ll CFE (hardware and software) employed to access these environments meet the following minimum Government cyber security requirements and provide periodic certification of compliance as a pre-requis ite to being granted network access.

http://www.section508.gov/

(a) Use of persona lly owned systems is prohibited;

(b) Operating systems and applications must be configured for compliance with the applicable

Security Technical Implementation Guides (STIGs);

(c) DOD approved anti-virus and anti-spyware software must be installed and signatures must be configured to automatically update on a daily basis;

(d) DOD approved host-level firewall must be utilized and configured to permit traffic by exception only, dropping all other traffic. If the host-level firewall provides intrusion detection or prevention, the signatures or rules must be updated at the same intervals as the anti-virus software.

(e) Computers must be Information Assurance Vulnerability Management (IAVM) compliant;

(f) Computers must be scanned with the currently approved DOD scanner solution at a minimum of every 30 days. All vulnerabilities must be remediated and reported to the cognizant Information Assurance Manager;

(g) Contractor employees must possess a current Government issued Common Access Card (CAC) and install Government certified CAC readers; and

(h) Verification of compliance with these requirements must be provided to an appointed government representative on a monthly basis.

5.4 Incident Handling

5.4.1. Reporting Requirements

The contractor shall provide an initial incident report to the Defense Cyber Crime Center (DC3) as soon as possible upon discovery of any suspected cyber intrusion events on the contractor's (or its subcontractors') unclassified information system(s) or network(s) where DOD information is resident or transiting. The initial incident report shall be provided even if some details are not yet avai lable, with follow-on detailed reporting to DC3 within 24 hours. Reportable cyber intrusion events include the following:

(a) A cyber intrus ion event involving possible data exfiltration, manipulation or unauthorized disclosure of any DOD information resident on or transiting the contractor's (or its subcontractors') unclassifi ed information systems or networks;

(b) Intrusion activities that allow unauthorized access to the contractor's unclassified information system(s) or networks(s) on which DOD information is resident or trans iting.

5.4.2. Incident Report Content

The incident report shall include, at a minimum, the following information:

(a) Data Universal Numbering System (DUNS).

(b) Contract numbers affected unless all contracts by the company are affected.

(c) Facility CAGE code ifthe location of the event is different than the prime Contractor location.

(d) Point of contact if different than the POC recorded in the System for Award Management

(address, position, telephone, email).

(e) Contracting Officer point of contact (address, position, telephone, ema il).

(t) Contract clearance level.

(g) Name of subcontractor and CAGE code if this was an inc ident on a subcontractor network.

(h) DOD programs, platforms or systems involved.

( i) Location(s) of compromise.

U) Date incident discovered.

(k) Type of compromise (e.g., unauthorized access, inadvertent release, other).

(1) Description of technical information compromised.

(m) Any additional information relevant to the information compromise.

5.4.3. Incident Report Submission

The contractor will submit unclassified incident reports to DC3 via the Defense Industrial Base Network

(DIBNet) Portal (http://dibnet.dod.mil).

5.4.4. Incident Response Coordination

In the event of an intrusion or potential intrusion, the contractor agrees to a llow fo llow-on actions by the Government to further characterize and evaluate the suspect activity. The contractor acknowledges that damage assessments might be necessary to ascerta in intruder methodology and identify systems compromised as a result of the intrusion. Contractor acknowledges that in certa in cases a complete forens ic analysis might be necessary to ascertain intruder methodology and identify systems compromised as a result of the intrus ion. Once an intrusion is identified, the contractor agrees to take all reasonable and appropriate steps to preserve any and all evidence, infonnation, data, logs, e lectronic files and similar type information (refe rence NIST Special Publication 800-61 : Computer Security Incident Handling Guide, (current vers ion)) re lated to the intrusion for subsequent forensic analysis so that an accurate and complete damage assessment can be accomplished by the Government. The contractor is not required to maintain an organic fo rensic capability, but must ensure data is preserved (e.g. removing an affected system, while still powered on, from the network meets the intent of this requirement) and all actions documented until fo rens ic analysis can be performed by the Government or mutually agreed upon th ird party (e.g. Federally Funded Research and Development Center (FFRDC), commercial security contractor, etc.). Any follow-on actions shall be coordinated with the contractor via the COR.

5.4.5. Information Sharing

The Government may use and disclose reported information (e.g., information regarding threats, vulnerabilities, incidents, or best practices) that does not include contractor attribution information at its discretion to assist entities in protecting information or information systems (e.g. threat information products, threat assessment reports); provided that such use or disclosure is otherwise authorized in accordance with applicable statutes, regulations, and policies.

5.4.6. Confidentiality and Non-Attribution Statement

The Government shall take reasonable steps, by controlled access and need-to-know procedures, to protect against public release of attribution information of the cqntractor. The Government may use and disclose reported informat ion that includes attribution information only on a need-to-know basis to authorized persons for cyber security and related purposes (e.g., in support of forensic analysis, incident response, compromise or damage assessments, law enforcement, counter intelligence, threat reporting, and trend analysis). The Government may disclose attribution information to support contractors that are supporting the Government's cyber security and related activities if the support contractor is subject to legal confident ia lity requirements that prevent any further use or disc losure of the attribution in fonnation.

The Government agrees to consider avai lable exemptions of the Freedom of Information Act to protect against disclosure of attribution information of the contractor to unauthorized persons. Within a reasonable period necessary to perform an analys is after completion of the assessment, all contractor proprietary information or third party proprietary in fonnation in the possession of the Government as a result of the assessment will be destroyed unless other disposition is agreed upon in writing by the Parties or is required by law, Executive Order or regulation.

5.4.7. Law Enforcement/Counterintelligence

In the event of a known or potential intrusion, the contractor shall consent to responding counterintelligence or law enforcement investigative agency requests to apply forensic analysis tools to contractor information systems affected by the intrusion, including monitoring tools, imaging tools, and any other techniques that the agency seeks to apply to effectively analyze the intrusion . The contractor shall allow the responding counterintelligence and/or law enforcement investigative agency to image affected systems, including systems containing proprietary information. Nothing in this contract shall limit the ability to conduct law enforcement or counterintelligence activities, or other activities in the interest of the Government.

http://dibnet.dod.mil/

5.5. Security Training

Contractor employees assigned to USTRANSCOM and utilizing its enterprise networks shall attend/complete security training as prescribed by DOD and USTRANSCOM instructions. At a minimum this includes: Employee Initial Security Training, Annual Security Awareness Training, Operations Security (OPSEC), DOD Antiterrorism Level 1 Training, Active Shooter Training, Personally Identifiable Information (Pll) Training, Emergency Operations and any Security Stand Down Day Training scheduled by the Commander. Contract employees assigned elsewhere shall attend security training established by their respective government security offices and/or installations.

6. Security (Physical, Personnel, Information, Antiterrorism/Force Protection and Industrial).

6.1. General Security Information.

The majority of daily work associated with this PWS is at the unclassified level, but contractor personnel may be required to access SECRET information during performance of this task order. There will be compliance with U.S.military activity responsible for security administration at location where performance of the contract will be carried out.

6.2. Citizenship and Clearance Requirements.

The contractor’s, subcontractors, and/or partner’s personnel performing services under this task order shall be citizens of the United States of America. Overall, all contractor personnel shall possess the appropriate personnel security investigation for the position(s) occupied. Contractor personnel shall be required to have a background investigation that corresponds with the sensitivity level of the tasks to be performed.

6.3. Clearance Requirements and Position Sensitivity.

Contractor personnel with IA administrative privileges and/or who will monitor DOD IT systems or software as designated by DOD 8500.1/5200.2-R may be rated at the various levels listed below. The stipulation of the numbers and what IT/Automated Data Processing (ADP) levels the contractors will have is approved by the COR or the CO before the start of the task order. The contractor shall comply with all appropriate provisions of applicable security regulations while assigned to this task order for DOD and USTRANSCOM. The following guidance will be followed when determining background investigation and clearance levels for this task order depending on requirements:

POSITION LEVEL:

Information Technology (IT)-II Automated Data Processing (ADP)-II Or Non-Critical Sensitive Positions (SECRET):

IT/ADP-II and Non-Critical Sensitive Positions are those positions that: have access to Secret or Confidential information; Security police/provost marshal-type duties involving the enforcement of law and security duties involving the protection and safeguarding of DOD personnel and property; category II automated data processing positions; duties involving education and orientation of DOD personnel; duties involving the design, operation, or maintenance of intrusion detection systems deployed to safeguard DOD personnel and property; responsible for the direction, planning, design, operation, or maintenance of a computer system, and whose work is technically reviewed by a higher authority of the ADP-I category to ensure the integrity of the system; and any other position so designated by the head of the Component or designee.

BACKGROUND INVESTIGATION REQUIREMENTS:

(IT-II/ADP-II/Non-Critical Sensitive) Requirements for SECRET:

Positions designated by the Government at the Non-Critical Sensitive/ADP-II/IT-II rating require a National Agency Check with Local Credit (NACLC) (or acceptable periodic reinvestigation) favorably adjudicated (a favorable adjudication grants eligibility at the SECRET level as prescribed by DOD 5200.2-R). The IT-

II/ADP-II requirement mandates the contractor have a minimum FCL at the SECRET (or higher) level due to investigation submissions as directed in DOD 5220.22-M, DOD 5200.01 and JPAS.

POSITION LEVEL:

Information Technology (IT)-III Automated Data Processing (ADP)-III Or Non-Sensitive Positions (Position of Trust Determination) (No Classified Access) All other positions involved in computer activities and Common Access Card. No clearance is granted for classified access and only a Position of Trust (PoT) is awarded and posted in JPAS.

BACKGROUND INVESTIGATION REQUIREMENTS:

(IT-III/ADP-III/Non-Sensitive) Requirements for Position of Trust Determinations (No Classified Access):

Positions designated by the Government at the Non-Sensitive/ADP-III/IT-III rating require a National Agency Check with Inquiries (NACI) (or acceptable investigation/reinvestigation) favorably adjudicated (a favorable adjudication issues a Position of Trust determination as prescribed by DOD 5200.2-R and DOD DTM 08-003 (Dated Dec 08). Favorable NACI or equivalent investigation results must be posted in JPAS before a CAC or NIPRNET access will be granted. To obtain interim CAC/NIPRNET access, NACI investigations will be opened with fingerprint, name and criminal records checks returned favorably before the credentials (CAC and NIPRNET) are issued. NACI submissions will be completed on the Standard Form (SF) 85 and submitted with fingerprint cards (FP 258) to USTRANSCOM Force Protection, Security Services Center (SSC) for processing. No classified access will be granted based on the NACI investigation.

NOTE: The above requirements for IT-III/ADP-III/Non-Sensitive Positions are for access to unclassified systems only. Contractors who require access to classified systems or areas must have interim or final adjudication of background investigations at the Critical or Non-Critical Sensitive levels.

USTRANSCOM will only process NACI/Position of Trust investigations and will not complete any personnel security investigations for classified access. It is incumbent upon the contractor to have the appropriate investigations completed upon start of the task order. Personnel who do not have the proper investigation will be denied the ability and access to USTRANSCOM facilities until investigations have been favorably adjudicated.

6.4. Security Clearance and Special Access Requirements.

All positions on this task order require a minimum of a SECRET clearance as granted by the Personnel Security Management Office-Industry (PSMO-I).

6.5. Facilities Clearance (FCL)

The contractor must have a valid FCL at the SECRET level. Interim FCLs are acceptable provided they are not expired. FCL procedures and security guidelines for adjudicative requirements are outlined in DOD 5220.22-M FCLs and Interim FCLs must be awarded by the Defense Security Service (DSS) Facility Clearance Branch.

6.6. Derogatory Information.

If the Government notifies the contractor that the employment or the continued employment of any contractor personnel is prejudicial to the interests or endangers the security of the United States of America, that employee shall be removed and barred from the worksite. This includes security deviations/incidents and credible derogatory information on contractor personnel during the course of the task order’s period of performance as noted in JPAS. Personnel who have incident reports posted in JPAS will be denied the ability to support the task order until the issues have been resolved and the incident has been removed in JPAS. The contractor shall make any changes necessary in the appointment(s), at no additional cost to the Government.

Security Regulation Guidance:

Department of Defense (DOD):

2000.16 (DODI Antiterrorism (AT) Standards)

5200.01 (DODM Information Security Program volumes 1-4) 5200.2-R (DOD Personnel Security Program) 5200.08-R (DOD Physical Security Program) 5220.22-M (National Industrial Security Program Operating Manual-NISPOM)

8500.1 (DTIC Cyber-Security)

2000.12 (DODI Antiterrorism (AT) Program) 4500.9-R, Part 2, Appendix E, Defense Transportation Regulations – Movement) DISA 300.115.3 Circular: (SIPRNeT Security Classification Guide)

DOD regulations are found at: http://www.dtic.mil/whs/directives/corres/pub1.html

USTRANSCOM:

USTRANSCOM Instruction 31-02 (USTRANSCOM Security Classification Guide) USTRANSCOM Instruction 31-12 (Operations Security - OPSEC)

Scott Air Force Base:

SAFB Instruction 31-101 (Installation Security Instruction)

USTRANSCOM Force Protection (Industrial Security) Points of Contact:

USTRANSCOM

Attn: TCJ3-FP (Steve Strait or Steve Stegen) 508 Scott Drive Scott AFB IL 62225 Commercial: 618-220-6531/220-7892 (respectively) Email at steven.g.stegen.civ@mail.mil or steven.m.strait@mail.mil USTCJ3-FP Approval: Steven G. Stegen, USTRANSCOM SSC, 618-220-7892 USTCJ3- FP Tracking #: USTRANSCOM-FP-0013-15

APPENDICES:

1. ACRONYMS

2. APPLICABLE DOCUMENTS

3. NON-DISCLOSURE AGREEMENT

Appendix 1

ACRONYMS

Acronym Definition AFB Air Force Base AF E/APL Air Force Evaluated/Approved Products List AFI Air Force Instruction AMC Air Mobility Command pRFID Passive Radio Frequency Identification ATCMD Advance Transportation Movement and Control Document CA California CD Compact Disc CLIN Contract Line Item Number COE Common Operating Environment COMSEC Communications Security CONUS Continental United States COR Contracting Officer’s Representative DFARS Department of Defense Federal Acquisition Regulation Supplement DII Defense Information Initiative DLA Defense Logistics Agency DOD Department of Defense DTM Directive-Type Memorandum EIT Electronic and Information Technology FAR Federal Acquisition Regulation FOUO For Official Use Only GATES Global Air Transportation Execution System GSA General Services Administration IAW In Accordance With ID Identification IPR In-Process Review ISO International Organization of Standardization JTR Joint Travel Regulation LAN Local Area Network NDA Non-Disclosure Agreement ODC Other Direct Cost OEM Original Equipment Manufacturer OSD/SCI Office of the Under Secretary of Defense for Supply Chain Integration PM Project Manager PM J-AIT Army Product Manager for Joint Automatic Identification Technology PMP Project Management Plan POC Point of Contact PWS Performance Work Statement RFID Radio Frequency Identification

Acronym Definition SDS Service Delivery Summary TMAP Telecommunications Monitoring and Assessment Program USAF United Stated Air Force USTRANSCOM United States Transportation Command

Appendix 2

APPLICABLE DOCUMENTS

Federal and DOD Documents

AFI 33-129, Air Force Instruction on WEB Management and Internet Use http://www.e-publishing.af.mil/shared/media/epubs/AFI33-129.pdf

AFI 33-201, Air Force Instruction on Communications Security (COMSEC) The documents will be provided by the Government upon request to the COR. There is no public access available.

AFI 33-219, Air Force Instruction on Telecommunications Monitoring and Assessment Program (TMAP) http://www.e-publishing.af.mil/shared/media/epubs/AFI33-200.pdf

DODD 4500.56, DOD Policy on the Use of Government Aircraft and Air Travel http://www.dtic.mil/whs/directives/corres/pdf/450056p.pdf http://www.e-publishing.af.mil/shared/media/epubs/AFI33-129.pdf http://www.e-publishing.af.mil/shared/media/epubs/AFI33-200.pdf http://www.dtic.mil/whs/directives/corres/pdf/450056p.pdf

Appendix 3

NONDISCLOSURE AGREEMENT AND AGREEMENT TO DISCLOSE POTENTIAL

CONFLICTS OF INTEREST

FOR CONTRACTOR EMPLOYEES ON USTRANSCOM CONTRACTS

NOTE: This Agreement is a standard agreement designed for use by contractor (including sub-contractor) employees assigned to work on USTRANSCOM contracts.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .