ID09190059_RFP_Attachment_3_-_Task_Order_001_PWS.docx
DOCX document 66 KB Posted
- Attached to
- Virtual Desktop Infrastructure (VDI) Support Services Federal contract opportunity
- Solicitation number
- ID09190059
- Issued by
- GSA Federal Acquisition Service
About this file
This performance work statement outlines requirements for Virtual Desktop Infrastructure and SecureView engineering, analysis, and installation support services for the U.S. Pacific Air Forces. Services include senior program management, engineering, SecureView support, certification and accreditation, site surveys and project agreements, deployment, and training. Performance will take place across the PACAF area of responsibility. The contractor shall provide servers, firewalls, switches, thin clients, laptops, monitors, and allied equipment support. The period of performance is one year from award with a potential for additional task orders over five years. Proposals are due by noon on August 19, 2019 in response to solicitation ID09190059, a small business set-aside released by the GSA Federal Acquisition Service for Region 9.
Solicitation Attachment 3 - Task Order 001 PWS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| ID09190059_-_Amendment_1,_Attachment_1,__PACAF_EVDI_-_Industry_Questions.xlsx | XLSX spreadsheet | |
| ID09190059_-_SF30_Amendment_01.pdf | ||
| ID09190059_Request_For_Proposals_Amendment_1.pdf | ||
| ID09190059_RFP_Attachment_2_-_Contract_Performance_Work_Statement_(PWS).doc | DOC document | |
| ID09190059_RFP_Attachment_1_-_Past_Performance_Reference_Information_Sheet.docx | DOCX document | |
| ID09190059_Request_For_Proposals.pdf | ||
| ID09190059_RFP_Exhibit_A_-_Price_Workbook.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ID09190059
Task Order 001 – Diego Garcia SecureView
PERFORMANCE WORK STATEMENT (PWS)
1. Contracting Officer’s Representative (COR). COR details will be provided upon award.
2. Project Title. Pacific Air Force (PACAF) SecureView Diego
3. Background. Traditional methods of providing encrypted data access and information sharing strategies within the Department of Defense (DoD) must be affordable, without compromising data security and operational efficiencies. The USAF and PACAF cannot continue to deploy secure networks by using traditional TYPE 1 encryption to every user or installing Protected Distribution Systems (PDS) that require significant O&M manpower. Furthermore, requirements to operate in a Mission Partner Environment (MPE) is rapidly escalating complexity requiring operators and commanders to have multiple platforms, and networks available for every operator position. The hardware requirement at the desktop alone is quickly becoming untenable. The O&M, sustainment, technical requirements and cost to support multiple standalone networks cannot continue. The implementation of SecureView builds on Joint Information Environment (JIE), Data Center Virtualization, and PACAF SIPRNet EVDI initiatives.
US Air Force Research Laboratory (AFRL) led the way in developing a data access and information sharing solution. AFRL engaged in a technical collaboration with Intel and Citrix, resulting in SecureView, a government solution that expands on commercial off-the-shelf (COTS) capabilities.
SecureView has been deployed at more than one dozen federal agencies and has saved the government millions of dollars in development and Total Cost of Ownership (TCO) expenses. This solution is less vulnerable to cyber hacking, modification or corruption than traditional software-based security solutions and provides excellent performance for mission-critical collaboration and media-intensive use cases over alternate hardware configurations.
SecureView is a hardened, client-hosted virtualization (CHV) solution, enabling independent, concurrent access to multiple domains. It provides performance that is independent of network bandwidth and server contention issues, providing consistent responsiveness for visually intensive analysis and collaboration. SecureView is NIST 800-53 certified as High in both confidentiality and integrity, and Medium in availability, and is supported on several reliable desktop platforms along with numerous laptop and tablet models. SecureView’s advanced isolation provides the ability to run multiple securely isolated environments on a single PC. It includes a hardware-assisted, trusted boot that verifies the integrity of the virtual desktop at launch, as well as hardware-assisted, accelerated disk encryption.
SecureView is cost effective in that it reduces the traditional need for each user to have separate workstations for each isolated domain. As a CHV solution, it does not require the network and back-end build-out often necessary with server-hosted virtualization (SHV) approaches running on thin-clients. SecureView utilizes Suite B cryptography. Suite B eliminates the need for separate encryption devices or PDS.
With existing missions changing to incorporate new technology, and new missions being on-boarded which demand quick mobility of users. Also, secure collaboration with US and coalition partners, and ability to push mission data in real-time to places not possible before, a transformation has to occur. The requirement is to change each base from a silo of great information to a seamless access point meshed with other data centers to provide seamless and consistent EUC experiences. Mobile devices are becoming a more prevalent part of DoD business, cloud-based services are bringing realities of highly available and resilient data service offering, and more mobility while still being efficient and productive, are just some of the challenges the Air Force, and other services, is faced with while making a transformation strategy to a incorporate a new generation of computing, while securely managing data across a broad array of computing platforms. The technical and program management skills required to accomplish those tasks is not inherently available or part of the duty description for military or government personnel necessitating contract support to fill the void.
4. Objectives. PACAF A36C requires a contractor to provide the required technologies to implement and deploy SecureView utilizing the NSA Commercial Solutions for Classified Mobile Access Capability (CSfC MACP) throughout the PACAF Theater. This includes coordinating with AFRL, the NSA, AF Designated Approval Authority (AF DAA), the AF Cross Domain Office, Defense Information Assurance Security Accreditation Working Group (DSAWG), to design, engineer, architect, implement and perform ALL necessary & required Certification and Accreditation actions to deploy a SecureView Secret and Below (SABI) solution for NIPRNet/SIPRNet (Non Secure/Secure Internet Protocol Router) across the Pacific..
These are specific implementation-based tasks and not an augmentation of existing roles and responsibilities within the staff. Contractor resources will have years of experience and the skills required to execute the unprecedented merger of servers, storage, networking, data centers, DoD component commands, and end-user devices into a virtual environment that allows users access from anywhere and any device. These contractor resources will be experienced in deploying technologies in PACAFs unique environment.
5. Scope. Contractor shall provide the required technologies to deploy and implement SecureView Secret and Below (SABI) utilizing NSA’s CSfC MACP for transport. This includes designing, engineering, architecting and implementing to include coordination and performing associated allied support for this project.
Project materials shall be vetted against the NSA CSfC MACP Approved Products List (APL). The government reserves the option to approve the recommended vendor solution prior to the contractor ordering equipment from the NSA CSfC APL.
Contractor shall coordinate and develop project support agreements that addresses reserving rack/floor space, power, and connectivity for both SIPRNet and NIPRNet. The contractor shall provide necessary Allied Support for a complete turnkey implementation including installation of racks, power, UPS, all patch cables for connectivity where necessary. Coordination with each base can be done via telecom if the respective base agrees. If the base does not agree and asks for PSA site surveys, the contractor shall be responsible for site surveys if requested by the base or MAJCOM. Regardless of the method the contractor receives information for Allied Support, the contractor is ultimately responsible for ensuring a turnkey installation even if information provided by the Govt is inaccurate or incomplete. The scope of allied support does not include significant upgrades or new power panels, facility UPS’s or facility HVAC systems. If any of these issues are encountered the MAJCOM reserves the right to move the schedule for up to 90 days at no cost to the government to resolve these issues. The government also reserves the option to de-scope or remove a base from the schedule if any of these issues are encountered.
Contractor shall perform all necessary Certification and Accreditation that includes developing all necessary artifacts, submission and coordination with the AF Designated Approving Authority (AFDAA), AF Cross Domain Review Board, the Defense Information Assurance Security Accreditation Working Group (DSAWG), the NSA Secure Solutions for Classified Mobility Capability Package and the NSA Data at Rest Capability Package.
Contractor shall provide client/End User Device (EUD’S) hardware that shall be the latest approved on the NSA CSfC and AFRL hardware compatibility list at the time the contractor is deploying EUD’s. PACAF reserves the option to modify/change the mix of desktops, laptops and approved tablets prior to the contractor purchasing EUD’s.
This effort involves:
| • | Task Area 1 – Senior Program Management |
| • | Task Area 2 – Engineering |
| • | Task Area 3 – SecureView |
| • | Task Area 4 – Certification and Accreditation |
| • | Task Area 5 – Site Survey and Project Support Agreements (PSA’s) |
| • | Task Area 6 – Deployment |
| • | Task Area 7 – Training |
6. Performance Requirements. Contractor shall provide the required technologies to upgrade/enhance the End-User Computing (EUC) environment through the implementation of CSfC and SecureView in the PACAF SIPRNet Enterprise. This includes designing, engineering, architecting and implementing a SecureView, multi-level client architecture utilizing the NSA’s CSfC Mobile Access Capability Package (MACP) across the PACAF.
6.1 Task 1 – Senior Program Manager. Experienced in managing High Level Engineers and Associate Program Managers in the deployment of complex theater-wide joint enterprise projects on a virtualized platform. The Senior Program Manager will have demonstrated experience:
6.1.1 Subtask 1: Manage the life cycle of a project from architectural design services to hand-off to customer support using the standards of Project Management Model (PM2). Experienced in determining organizational and unit needs and developing technical solutions and Project Support Agreements (PSA) in support of critical cyber requirements.
6.1.2 Subtask 2: De-conflict the simultaneous projects to include the demonstrated skill of management and tracking of equipment shipping, licenses, personnel travel, scheduling, cost analysis, budget analysis to ensure a turn-key solution under-budget and on-time.
6.1.3 Subtask 3: Manage and Prepare System, Hardware, and Software Accreditation Packages to include eMASS, and EITDR inputs. Coordinating with Base Information Assurance Managers (IAMs) and PACAF Cyber Surety to ensure systems and applications are approved for connection to the AF and DISA Networks and inclusion in the base enclaves.
6.1.4 Subtask 4: Develop and implement a VDI Operational Test/Checklist and VDI System Test Plan to include SecureView, System Stability Test, Zero Client Power Test, Functionality of Email, SharePoint, Task Management Tool, and Server Power Test.
6.1.5 Subtask 5: Provide direct customer support and troubleshooting for SecureView and VDI client hardware and software and coordinate with Government Network Operations Centers and Higher Headquarters.
6.1.6 Subtask 6: Develop VDI Joint Information Environment (JIE) Metrics for Joint and Higher AF Headquarters.
6.1.7 Subtask 7: Lead a team in the deployment of virtual capabilities in an austere, and disconnected, disadvantaged and intermittent location where bandwidth and access creates unique challenges. This includes areas that are disconnected and separated from major DoD installations.
6.1.8 Subtask 8: Lead a team of engineers and project managers for on-site multi-datacenter installations in a large overseas theater to include scheduling projects and migrations, coordinating equipment shipments, scheduling travel, coordinating with overseas bases for access, and coordinating installation times with base personnel.
6.1.9 Subtask 9: Lead an engineering team in the design, deployment, and management of Virtual Servers, Networks, Storage Arrays, Virtual Desktops on a secure/non-secure network throughout a large DoD overseas environment. Experience should include provisioning of these devices for Unified Computing (i.e. virtual call managers), Thin/Zero Client deployments to include SecureView, and SharePoint deployments.
6.1.10 Subtask 10: Lead an architecture and engineering team in the deployment of Virtualized Multi-Tenant Data Center and various secure hybrid Cloud Computing solutions. Demonstrated experience in leading the deployment of virtualization and virtual desktops in the Pacific Theater or other theater-wide DoD deployments to include server-accelerating RAM-based VDI data storage, with server RAM as the primary storage tier and virtualized server acceleration. Experience guiding the development of Hyper-Converged and Converged Infrastructure technologies whether in a lab or real-world deployment.
6.1.11 Subtask 11: Demonstrate experience in leading a team in the deployment of network, server, and storage on SIPRNet to include configuration of said equipment to Air Force specifications. Experience should include leading a team in the seamless connection to a Virtual Desktop Environment.
6.1.12 Subtask 12: Expertise with training of AF personnel in virtual desktop site surveys, network and encryption devices requirements, equipment procurement (i.e. Zero/Thin Clients) and installation, and desktop configurations to include SecureView.
6.1.13 Subtask 13: Must be familiar with host nation sensitivities and be able to work well within the constraints of host nation military and business environment.
Deliverables: Monthly Status Report Daily Status Report Project Plan Project Milestones Operational Checklist Test Plan
6.2 Task 2 - Engineering: Contractor shall provide a Network Engineer that possess the requisite certifications (CCIE – Cisco Certified Internetwork Engineer) in routing and switching and network virtualization to include but not limited to Cisco Nexus platform devices, Brocade and Juniper switches and routers with experience deploying these devices throughout a large DoD environment.
6.2.1 Subtask 1: Engineer shall architect and engineer Commercial Solutions for Classified in a complex Base Area Network. Design and configure CSfC Inner and Outer VPN Concentrators to ensure the architecture is compatible with the NSA MACP package. The network engineer must have experience with deploying SecureView and the NSA CSfC MACP architecture. Understand the NSA CSfC MACP approved products list and how configure and set up an operational single vendor system.
6.2.2 Subtask 2: Design and configure CSfC MACP firewall’s and Intrusion Detection Devices (IDS) to ensure architecture is compatible with the NSA MACP package.
6.2.3 Subtask 3: Design and configure Inner and Outer VPN concentrators to ensure architecture is compatible with the NSA MACP package.
6.2.4 Subtask 4: Develop and execute test plans necessary for NSA MACP CSfC approval.
6.2.5 Subtask 5: Provide direct customer support and troubleshooting for SecureView client hardware and software and coordinating with Government Network Operations Centers and Higher Headquarters.
6.2.6 Subtask 6: Advise and work with base personnel on any network configurations and changes necessary for an operational system.
6.2.7 Subtask 7: Coordinate with the respective base for IP addressing and subnets as necessary.
6.2.8 Subtask 8: Conduct all testing necessary for all C&A approval to obtain an ATO
6.2.9 Subtask 9: Configure and implement DNS entries as necessary for an operational system Deliverables: Detailed Engineered Solutions Architectural Diagrams Operational Checklist Test Plan Training Plan
6.3 Task 3: SecureView Engineer: Contractor shall provide a SecureView Engineer that has experience with the deployment of SecureView architecture and clients. SecureView Engineer will be experienced in working with DoD/AF personnel in the Pacific Theater in architecting and deploying solutions in the Pacific Theater. SecureView Engineer will:
6.3.1 Subtask 1: Install and configure servers necessary to for a SecureView deployment, these include but not limited to; inner and outer VPN management server, SecureView Management servers, Certificate Servers.
6.3.2 Subtask 2: Provision clients with SecureView including any and all software and hardware configuration necessary for an approved working client; which includes but not limited to, a SIPR Thin VM, NIPR Thin/Thick VM, Inner VPN Appliance (StrongSwan), Outer VPN Appliance (AnyConnect), and Network Driver Appliance.
6.3.3 Subtask 3: Provide technical details and configuration specifics to support all C&A work.
6.3.4 Subtask 4: Perform all testing necessary for AF Cross Domain and NSA MACP CSfC approvals.
6.3.5 Subtask 5: Provide direct customer support and troubleshooting for SecureView client hardware and software and coordinating with Government Network Operations Centers and Higher Headquarters.
6.3.6 Subtask 6: Conduct all testing necessary for all C&A approval to obtain an ATO.
Deliverables: Detailed Engineered Solutions Architectural Diagrams Operational Checklist Test Plan Training Plan
6.4 Task 4: Certification and Accreditation: Contractor shall perform all Certification and Accreditation steps necessary to obtain an Approval to Operate from the AF, NSA, DoD and any other agency that must be coordinated with to have fully operational system. This includes but not limited to:
6.4.1 Subtask 1: Develop all paperwork, test plans, drawings & artifacts necessary to obtain AF DAA approval for SecureView.
6.4.2 Subtask 2: Develop all paperwork, test plans, drawings & artifacts necessary to obtain AF Cross Domain access approval for SecureView.
6.4.3 Subtask 3: Develop all paperwork, test plans, drawings & artifacts necessary for the DSAWG approval for SecureView.
6.4.4 Subtask 4: Develop all paperwork, test plans, drawings & artifacts necessary for the NSA CSFC MACP approval.
6.4.5 Subtask 5: Develop all paperwork, test plans, drawings & artifacts necessary for the NSA CSFC Data at Rest Program.
6.4.6 Subtask 6: The ATO/IATT process must be complete and all approvals obtained prior to any connections to the AFNET, NIPRNet and SIPRNet.
Deliverables: Monthly Status Reports Detailed Engineered Solutions Architectural Diagrams Operational Checklist Test Plan
6.5 Task 5: Site Survey and Project Support Agreements (PSA’s): Contractor shall at their discretion gather site survey information via telecons, remotely, and/or via physical site surveys, however, the contractor is responsible for the accuracy of the information. The Govt shall not be responsible for any inaccurate information if the contractor chooses telecon and/or remote assessment instead of physical site survey.
6.5.1 Subtask 1: Contractor shall develop a PSA if required by a base, PSA shall clearly show:
a. Space required in existing racks
b. Ports required for connectivity
c. IP addresses/subnets needed
d. Space required for new racks
e. Power required and/or circuit breakers required if new power is necessary
f. Identification of users for client deployments
6.5.2 Subtask 2: Contractor shall be responsible for providing and installing allied support necessary for an operational system:
a. Any necessary power if not available at the cabinet location coordinated and approved
b. UPS if necessary
c. Patch cables necessary for an operational system
d. New Communication Cabinet if necessary that has similar features to the existing communication cabinets in the Data Center
6.5.3 Subtask 3: If facility UPS, facility HVAC or extensive power upgrades i.e. new power panels, are identified the contractor shall notify the PACAF lead project engineer immediately. The Govt shall have 45 days to remedy the situation or provide an alternative plan at no cost to the Govt. The Government also reserves the option to descope the project should this situation arise.
Deliverables: PSA Architectural Diagrams Test Plan
6.6 Task 6: Deployment: Contractor shall ship all necessary equipment and hardware to the respective base.
6.6.1 Subtask 1: Contractor shall install and configure all servers, VPN concentrators, firewalls, IDS and all necessary supporting HW for an operational system.
6.6.2 Subtask 2: Contractor shall install 25% of the clients designated by base personnel.
6.6.3 Subtask 3: Contractor shall provide all necessary hardware, cables, adapters, token readers necessary for an operational client. The contractor shall not rely on the host base to provide any supporting hardware with the exception of monitors. The contractor shall ensure they provide appropriate connecting cables for existing monitors.
6.6.4 Subtask 4: Contractor shall Coordinate with government for the exact types of clients on the SecureView APL prior to any client purchase including the number of laptops/tablets required.
Deliverables: Daily Status Report Operational Checklist Test Plan
6.7 Task 7 – Training: Contractor shall conduct a 1 week classroom training session for each base on the system configuration, CSfC, and the SecureView client configuration.
6.7.1 Subtask 1: Contractor shall provide “over the shoulder” training to base personnel during the project implementation.
Deliverables: Training Plan
7. Performance Standards.
| Performance Standard |
| Acceptable Quality Level (AQL) |
| Method of Calculation |
| 6.1. Senior Program Manager |
| Task must be 100% accurate |
Minimum Acceptable: Tasks shall be 90% accurate
Deliverable shall meet the target criteria of 100% within one instance of rework.
| 6.2. Engineering |
| Task must be 100% accurate |
Minimum Acceptable: Tasks shall be 90% accurate
Deliverable shall meet the target criteria of 100% within one instance of rework.
| 6.3. SecureView |
| Task must be 100% accurate |
Minimum Acceptable: Tasks shall be 90% accurate
Deliverable shall meet the target criteria of 100% within one instance of rework.
| 6.4. Certification and Accreditation |
| Task must be 100% accurate |
Minimum Acceptable: Tasks shall be 90% accurate
Deliverable shall meet the target criteria of 100% within one instance of rework.
| 6.5. Site Survey and PSA |
| Task must be 100% accurate |
Minimum Acceptable: Tasks shall be 90% accurate
Deliverable shall meet the target criteria of 100% within one instance of rework.
| 6.6. Deployment |
| Task must be 100% accurate |
Minimum Acceptable: Tasks shall be 90% accurate
Deliverable shall meet the target criteria of 100% within one instance of rework.
| 6.7. Training |
| Task must be 100% accurate |
Minimum Acceptable: Tasks shall be 90% accurate
Deliverable shall meet the target criteria of 100% within one instance of rework.
8. Incentives. NA
9. Place of Performance. Work will be performed at a Government site within the Pacific AOR regardless of Service component. Travel in and around the primary place of performance may be required throughout the period of performance to include any location or Service Component facility across the Pacific. Additional travel within CONUS and OCONUS will be required to support the requirements of this PWS.
Diego Garcia
Alternate Place of Performance - Contingency Only. As determined by the Contracting Officer’s Representative (COR), contractor employees may be required to work at an alternate place of performance (e.g., home, the contractor's facility, or another approved activity within the local travel area) in cases of unforeseen conditions or contingencies (e.g., pandemic conditions, exercises, government closure due to inclement weather, etc.). Non-emergency/non-essential contractors should not report to a closed government facility. Contractor shall prepare all deliverables and other contract documentation utilizing contractor resources. To the extent possible, the contractor shall use best efforts to provide the same level of support as stated in the PWS. In the event the services are impacted, reduced, compromised, etc., the Contracting Officer or the contractor may request an equitable adjustment pursuant to the Changes clause of the contract.
Contractors are required to periodically work flexible hours to facility interaction with DoD engineers from Europe, West PAC, and Eastern U.S. specifically during project migrations or installs.
10. Period of Performance. One year after date of award
As directed by the COR, the contractor shall continue performance in emergency or mission essential conditions. Additionally, the contractor may be required to account for the whereabouts of their personnel should this information be requested by the COR. In the event of a Government shutdown, and as directed by the COR, the contractor shall continue performance in emergency or mission essential conditions.
11. Delivery Schedule.
| PWS Task# |
| Deliverable Title |
| Format |
| Due Date |
| Distribution/Copies |
| Frequency and Remarks |
6.1, 6.4
| Monthly Status Report |
| Word/Excel/ |
PowerPoint Government-Provided Format
| 30 days |
| Email to COR, Project Manager, and Branch Chief |
| Monthly |
6.1, 6.6
| Daily Status Report |
| Word/Excel/ |
PowerPoint Government-Provided Format
| Close of Business Each Day |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
6.1
| Project Plan |
| Word/Excel/ |
PowerPoint Government-Provided Format
| 30 Days Prior to start of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
| 6.1 |
| Project Milestones |
| Excel |
Government-Provided Format
| 30 Days Prior to start of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
| 6.2-6.4 |
| Detailed Engineer Solution |
| Word/Excel/ |
PowerPoint Government-Provided Format
| 60 Days Prior to start of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
| 6.2-6.5 |
| Architectural Diagrams |
| Word/Excel/ |
PowerPoint Government-Provided Format
| 60 Days Prior to start of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
| 6.1-6.4, 6.6 |
| Operational Checklist |
| Word/Excel/ |
Government-Provided Format
| 30 Days Prior to start of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
| 6.1-6.6 |
| Test Plan |
| Word/Excel/ |
Government-Provided Format
| 60 Days Prior to start of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
| 6.5 |
| PSA |
| Word/Excel/ |
PowerPoint Government-Provided Format
| 30 Days Prior to deployment of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
| 6.2, 6.3, 6.7 |
| Training Plan |
| Word/Excel/ |
PowerPoint Government-Provided Format
| 90 Days Prior to end of project |
| Email to COR, Project Manager, and Branch Chief |
| During operations/ deployments |
12. Security Requirements. This section shall be considered a supplement to Block 13 of the Government provided DD Form 254, Contract Classification Specification. The following security requirements shall apply to this effort.
References:
a. DISAI 240-110-8, Information Security
b. DISAI 240-110-36, Personnel Security
c. DISA Instruction 630-230-19, Cybersecurity
d. DoDM 5200.01, Vol 1-4 Information Security Program, 24 February 2012
e. DOD 5200.2-R, DoD Personnel Security Program
f. DOD 5220.22-M, National Industrial Security Program Operating Manual, February 2006 Incorporating Change 02 May 2016
12.1 Facility Security Clearance. The work to be performed under this contract/order is up to the Secret level. Therefore, the company must have an interim or final Secret Facility Clearance from the Defense Security Service Facility Clearance Branch.
12.2 Security Clearance and Information Technology (IT) Level. All personnel performing on or supporting a DISA contract/order in any way will be U.S. citizens. The personnel security requirements for this contract/order cover the individuals supporting the Task Areas delineated in the table below. Contractor personnel must possess the interim or final security clearance and interim or final IT-level eligibility delineated in the table below when performance starts.
| PWS Task / Subtask |
| Clearance Level |
| IT Level Access |
| Level of Classified Access |
| Justification for Access to Classified |
| 6.1. Senior Program Manager |
| Secret |
| IT-II |
| Secret |
| PACAF Theater level support provided requires project management, implementation, execution, troubleshooting, information exchange across the theater involving Secret level material related to networks and capabilities of SIPRNet and NIPRNet. |
| 6.2. Engineers |
| Secret |
| IT-II |
| Secret |
| PACAF Theater level support provided requires project management, implementation, execution, troubleshooting, information exchange across the theater involving Secret level material related to networks and capabilities of SIPRNet and NIPRNet. |
| 6.3. SecureView SME’s |
| Secret |
| IT-II |
| Secret |
| PACAF Theater level support provided requires engineering, troubleshooting, information exchange, configuration, integration, execution of data center services for both SIPRNet and NIPRNet. |
| 6.4. Certification and Accreditation Specialist |
| Secret |
| IT-II |
| Secret |
| PACAF Theater level support provided requires engineering, troubleshooting, information exchange, configuration, integration, execution of data center services for both SIPRNet and NIPRNet. |
12.2.1 The following types of positions require a minimum interim Secret security clearance and interim IT-II eligibility when performance starts:
- Program Managers
- Engineers
- SecureView SME’s
- Certification and Accreditation Specialist
12.2.2 All personnel requiring Secret under this contract must undergo a favorably adjudicated National Agency Check, Local Agency Check and Credit Check (NACLC) as a minimum investigation. The NACLC will be maintained current within 10-years and requests for Secret Periodic Reviews (SPRs) will be initiated 90 days prior to the 10-year anniversary date of the previous NACLC or SPR.
12.3 Investigation Requirements. All personnel requiring IT-I access under this contract/order shall undergo a favorably adjudicated Tier 3 investigation (formerly known as a Single Scope Background Investigation (SSBI)) as a minimum requirement. The Tier 3 will be maintained current within 10-years and requests for Tier 3 reinvestigation (formerly known as Single Scope Background Period Reinvestigation (SBPR) or Phased Periodic Reinvestigation (PPR)) will be initiated prior to the 10-year anniversary date of the previous Tier 3.
12.3.1 All personnel requiring Secret access under this contract/order shall undergo a favorably adjudicated Tier 3 (T3) Investigation formerly known as a National Agency Check, Local Agency Check and Credit Check or Access National Agency Check and Inquiries as a minimum investigation. The Tier 3 Investigation will be maintained current within 10-years and requests for Secret Periodic Reinvestigations will be initiated by submitting a Tier 3R investigation prior to the 10-year anniversary date of the previous Tier 3 Investigation.
12.3.2 Contract employees that are not immediately eligible for at least interim IT-1 systems access will be permitted to begin work with interim IT-II systems access at the discretion of the Government, pending eligibility for IT-1. Before being permitted to begin work under this arrangement the individual contractor employee must be submitted by the company for an SSBI (investigation) that is reflected in the DoD JPAS database and granted interim IT-II systems access approval by local security representatives. The employee will not be granted any privileged access until interim or final IT-1 systems access is granted internal security processing completed by local security personnel. The Contractor must submit the request for SSBI as soon as a job offer is tendered to an employee. Advance NAC results will be requested by the Contractor to facilitate expeditious consideration for interim IT-1 systems access by local security personnel. Advance NAC results or a previous DoD investigation are required for interim IT-1 consideration. If the employee is not able to obtain an interim IT-1 clearance or interim IT-II clearance within 90 days, they will not be eligible to provide service on this contract.
12.4 Adjudication for Secret IT-I access. Favorable Adjudication of any previous T5, T5R, SSBI, SBPR or PPR by any of the DoD Central Adjudication Facility or other federal adjudications facilities within a five year period will be automatically accepted for final Secret IT-I access.
12.4.1 Prior to granting interim Secret IT-I authorization, the supporting security manager will forward a written request for interim Secret IT-I authorization to DISA PSO for approval. The request for SSBI (e-QIP, FBI name and fingerprint check) must be submitted by DISA PSO to the OPM.
12.5 Visit Authorization Letters (VAL). Visit requests shall be processed and verified through the Joint Personnel Adjudication System (JPAS) with required information forwarded to appropriate Security Office for authorization. SMO codes will be provided to vendor prior to submission of personnel requiring access. JPAS visits for contracts/orders are identified as “Other” or “TAD/TDY” and will include the Contract/Order Number and ADP/IT-Access level of the contract/order in the Additional Information section. Contractors that do not have access to JPAS may submit visit authorizations by e-mail in a password protected .pdf to the Contracting Officer Representative (COR) or Alternate COR specified in PWS Section 1.0.
If JPAS is not available, the VAL must contain the following information on company letterhead
· Company name, address, telephone number, assigned CAGE Code, facility security clearance
· CAGE CODE
· Contract/Order Number
· Name, SSN, date and place of birth, and citizenship of the employee intending to visit
· Certification of personnel security clearance and any special access authorizations required for the visit (type of investigation & date, adjudication date & agency, and IT access level)
· Name of COR/Alt COR
· Dates or period the VAL is to be valid
12.6 Security Contacts. Security Personnel contacts will be provided upon award, or may be requested with if necessary.
12.7 Information Security and other miscellaneous requirements.
12.7.1 Contractor personnel shall comply with all local security requirements including entry and exit control for personnel and property at the government facility.
12.7.2 Contractor employees shall be required to comply with all Government security regulations and requirements. Initial and periodic safety and security training and briefings will be provided by Government security personnel. Failure to comply with Government security regulations and requirements shall require the company to provide the Government with a written remediation/corrective action plan; furthermore, failure to comply with such requirements can be cause for removal and the contractor will not be able to provide service on this contract/order.
12.7.3. Contractor employees with an incident report in JPAS who have had their access to classified suspended will not be permitted to provide and fill positions requiring access to classified information on a DISA contract/order.
12.7.4 The Contractor shall not divulge any information, classified or unclassified, about DoD files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the DoD facility. Identification shall be worn and displayed as required.
12.7.5 DISA retains the right to request removal of contractor personnel regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, clearly conflict with the interest of the Government.
12.7.6 Contractor personnel will generate or handle documents that contain For Official Use Only information at the Government facility. Contractor shall have access to generate and handle classified material only at the location(s) listed in the place of performance section of this document. All contractor deliverables shall be marked in accordance with DoDM 5200.1, Vol. 3, Vol. 4, Information Security, DoD 5400.7-R, Freedom of Information Act Program, unless otherwise directed by the Government. The contractor shall comply with the provisions of the DoD Industrial Security Manual for handling classified material and producing deliverables. The contractor shall comply with DISA Instruction 630-230-19.
12.7.7 The Contractor shall afford the Government access to the contractor’s facilities, installations, operations, documentation, databases and personnel used in performance of the contract/order. Access shall be provided to the extent required to carry out a program of IT inspection (to include vulnerability testing), investigation and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of data or to the function of information technology systems operated on behalf of DISA or DoD, and to preserve evidence of computer crime.
13. Government Furnished Property (GFP)/Government-Furnished Equipment (GFE)/Government-Furnished Information (GFI). N/A
14. Other Pertinent Information or Special Considerations.
14.1 Contractor with necessary access to facilities to perform specific tasks outlined in this document to include base network control centers and operations centers.
14.2 Flexible work hours to accommodate base time zones and operational schedules. PACAFs AF efforts require direct and continuous collaboration with engineers/PMs from Europe, East Coast, and West Pacific which are all on different time zones.
14.3 Collaborative open environment workspace to facilitate brain-storming and collective engineering efforts. PMs and Engineers require daily, unscheduled, access to each other to architect, engineer, deploy and manage AF initiatives and respond to on-going and future projects.
14.4 Access to non-secure environment and open internet access to allow engineers and project managers to access OEM (Original Equipment Manufacturer – i.e. Cisco, EMC, Microsoft) websites and databases and to utilize vendor-provided laptops and connectivity devices (mobile hotspots/Wifi).
14.5 Individual work spaces to augment the collective open environment allow required personal space. It’s acceptable for the Government to provide a single location that allows for collaboration, access to non-secure sites and internet access, while also providing personal space.
14.6 Letters of Identification (LOIs)/Letters of Authorization (LOAs) for Contactors working on these contracts, whichever is applicable.
14.7 Contractor badges or Common Access Cards (CACs) for base access.
14.8 Any communications and information systems support documentation (plans, programs, base comprehensive blueprints, applicable regulations, specifications, standards, technical manuals, as-installed drawings, and other documentation as required in the performance outlined responsibilities) available to support the requirement.
14.9 Area Clearance Messages as required.
14.10 Visitor Group Security Agreements (VGSAs) as required.
14.11 Sponsorship or status under any Status of Forces Agreement (SOFA) as required.
14.12 DD254 as required.
14.13 Escorts as required.
14.14 The Government project manager shall provide the contractor with necessary access of facilities.
a. Identification of Possible Follow-on Work. N/A
b. Identification of Potential Conflicts of Interest (COI). N/A
c. Identification of Non-Disclosure Requirements. Contractors must execute a non-disclosure agreement as they will work with sensitive and/or proprietary information.
Deliverables:
Include status in Monthly Status Report (The contractor is responsible for identifying that all personnel, to include any new personnel on the contract, have executed the provided NDA and the NDA is current as of the date of the monthly status report. The NDA shall be sent to the COR for records filing.)
d. Packaging, Packing and Shipping Instructions. N/A
e. Inspection and Acceptance Criteria. N/A
f. Property Accountability. N/A
g. Supply Chain Risk Management (SCRM). N/A
h. Training: Contractor employees will be required to take Annual IA Cyber Awareness – Required for network access. Contactor employees may be required to take periodic mandatory training courses provided through the agency and other training required by statute, regulation, DoD, AF or DISA policy. No other training of contractor personnel shall be provided by the Government unless authorized by the Contracting Officer.
i. Products Developed. All products developed during the course of this effort become the property of the United States Air Force and/or the service component specified in this PWS.
15. Section 508 Accessibility Standards. The following Section 508 Accessibility Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) to this acquisition.
Technical Standards |X| 1194.21 - Software Applications and Operating Systems |_| 1194.22 - Web Based Intranet and Internet Information and Applications |_| 1194.23 - Telecommunications Products |_| 1194.24 - Video and Multimedia Products |_| 1194.25 - Self-Contained, Closed Products |X| 1194.26 - Desktop and Portable Computers |_| 1194.41 - Information, Documentation and Support
The Technical Standards above facilitate the assurance that the maximum technical standards are provided to the Offerors. Functional Performance Criteria is the minimally acceptable standards to ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic and information technology (E&IT) products are proposed.
Functional Performance Criteria |_| 1194.31 - Functional Performance Criteria
ANNEX 1:
SAMPLE EQUIPMENT LISTING.
The following listing reflects anticipated quantities and types of equipment needed to fulfill the requirement at this location for the vendor’s awareness. This is not a brand name requirement. The vendor shall propose an equivalent or better solution to the following:
| Part Number |
| Description |
| Qty |
Secure View Servers
| Dell PE R640 |
| SecureView Management Server (CPU: 2 x Intel Xeon Silver 4114, RAM: 32-GB, HDD: 5 x 2-TB) |
| 2 |
| Dell PE R640 |
| Gray CA Server (CA Standard: Dell PE R640 (CPU: 1 x Intel Xeon Silver 4114, RAM: 32-GB, HDD: 4 x 1-TB)) |
| 2 |
| Dell PE R640 |
| Red CA Server (CA Standard: Dell PE R640 (CPU: 1 x Intel Xeon Silver 4114, RAM: 32-GB, HDD: 4 x 1-TB) |
| 2 |
Secure View EUC
| Z240 |
| Desktop (SFF) (16G RAM) |
| 160 |
| Elitebook 850 G4 |
| Laptop (16G RAM) |
| 180 |
| Wyse 7040 |
| Thin Client (16G RAM) |
| 235 |
| 20" LCD Monitors |
| 400 |
Mobile Access CP SCFC Firewalls/IDS
| FPR2110-NGFW-K9 |
| Firewall (Black Grey) Redundant Cisco Firepower 2110 NGFW Appliance |
| 8 |
| FPR2110-NGFW-K9 |
| Red Firewall w/ IPS/IDS - Redundant Cisco Firepower 2110 |
| 4 |
| L-FPR2110T-T-1Y |
| Software/License |
| 4 |
| FPR2110-ASA-K9 |
| Outer VPN Gateway - Redundant Cisco Firepower 2110 ASA Appliance, 1U |
| 4 |
| L-AC-APX-1Y-S2 |
| Software/License |
Cisco AnyConnect Apex Term License 1-Yr 100-249 Users
| C9300-24T-E |
| Switches (CSFC Transport) - Redundant Cisco Catalyst 9300 Switch, 24 port RJ45 |
| 12 |
| C9300-DNA-E-24-3Y |
| Cisco Catalyst 9300 Switch, DNA Essentials, 24-Port, 3 Year Term License |
| 12 |
| WS-C2960X-24TS-L |
| Switches (Management/Provisioning)Cisco Catalyst 2960-X Switch, 24 port RJ45, 4 port SFP, Feature Set: LAN Base - Layer 2 |
| 6 |
| JELA |
| Support |
| 34 |
| GLC-SX-MMD= |
| Cisco 1000BASE-SX/LC SFP Transceiver Module |
| 36 |
Mobile Access CP Inner VPN Aruba
| 7010-USF1/JW703A |
| Inner VPN Gateway - Redundant Aruba 7010 Mobility Controller |
| 4 |
| SN1-7010-USF1/H3AX3E |
| ArubaCare 9 x 5 x NBD for Aruba 7010-US |
| 4 |
| LIC-7010-PEFV/JW496AAE |
| PEFV License for Aruba 7010 Mobility Controller for VIA/VPN Users |
| 4 |
| SN1-LIC-7010-PEFV/H2VS3E |
| PEFV License for Aruba 7010 Mobility Controller for VIA/VPN Users - 1 Year Support |
| 4 |
LIC-AP LIC-PEF LIC-RFP and LIC-AW
LIC-ENT/JW471AAE
| Aruba LIC-ENT Enterprise (License Bundle E-LTU) |
| 4 |
| SN1-LIC-ENT/H2XW3E |
| Aruba 1Y FC 24x7 License Control Bundle SVC |
| 4 |
| LIC-ACR-128/JW541AAE |
| Advanced Cryptography - 128 Sessions |
| 8 |
| SN1-LIC-ACR-128/H2YM3E |
| Advanced Cryptography - 128 Sessions - 1 Year Support |
| 8 |
Mobile Management CP Misc
| EliteBook 850 G3 Notebook |
| HP EliteBook 850 G3 Notebook (CPU: Intel Core i7-6600U, RAM: 16-GB, SSD: 256-GB) |
| 3 |
Allied Support
| AP7811B |
| Rack PDU, Metered, 2U, 30A, 208V, (12) C13s & (4) C19 |
| 22 |
| GLC-T= |
| CORE CISCO 1000BASE-T SFP |
| 64 |
| SFP-10G-SR= |
| CISCO 10GBASE-SR SFP MOD |
| 38 |
| SFP-H10GB-CU1M= |
| 1M 10GBASE-CU SFP+ CBL |
| 28 |
| SFP-H10GB-CU3M= |
| 3M 10GBASE-CU SFP CBL. |
| 20 |
| SFP-H10GB-CU5M= |
| 5M CBL 10GBASE-CU SFP+ 1000BASE-X - SFP |
| 16 |
| SFP-H10GB-ACU10M= |
| ACTIVE TWINAX CBL ASSY 10M |
| 20 |
| QSFP-H40G-CU1M= |
| 1M CBL PASSIVE COP 40GBASE-CR4 |
| 13 |
| QSFP-H40G-CU3M= |
| 3M CBL PASSIVE COP 40GBASE-CR4 |
| 13 |
| QSFP-H40G-ACU10M= |
| 40GBASE-CR4 ACTIVE COPPER CBL 10M |
| 12 |
| LCLC10GA-2M-AX |
| 2M CBL LC/LC MMF DUPLX 10G 50/125 |
| 36 |
| LCLC10GA-9M-AX |
| 9M MMF CBL LC/LC 10G DUPLX OM3 50/125 |
| 39 |
| C6AMB-R15-AX |
| 15FT CAT6A PATCH CBL MOLDED BOOT RED |
| 44 |
| C6AMB-R1-AX |
| 1FT CAT6A PATCH CBL MOLDED BOOT RED |
| 51 |
| C6AMB-R7-AX |
| 7FT CAT6A PATCH CBL MOLDED BOOT RED |
| 44 |
| SH |
| SHIPPING |
| 2 |
Enclosure 4a, PWS Page 1 of 11 Pages 2015/Version 9
Attachment 3, Task Order 001 PWS Page 1 of 14 Pages
File details come from the government source that posted it. Updated .