ISSO_PWS.pdf
PDF 681 KB Posted
- Attached to
- Information System Security Officer (ISSO) Training Federal contract opportunity
- Solicitation number
- FA860123Q0111
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
for
Special Access Program (SAP)
Information System Security Officer (ISSO) Training in support of
Headquarters Air Force Materiel Command
09 Jun 2023
Performance Work Statement
For
AFMC Special Access Program (SAP) Information System Security Officer (ISSO) Training
1.0 Scope. This document outlines the requirements for Special Access Program (SAP) Information System Security Officer (ISSO) Training requested by the Headquarters Air Force Materiel Command (HQ AFMC) Special Access Program Management Office (SAPMO).
2.0 Introduction. AFMC training for SAP ISSOs to enable protection information and information systems, at multiple classification and SAP program levels, used to plan, develop, deploy, sustain, and decommission cutting-edge technologies, systems, and platforms developed by AFMC SAPs supporting land, sea, air, space, and cyberspace dominance over adversary nations. Training must be specifically tailored to cover specific protection requirements for SAP information and systems specified in the DoD Joint SAP Implementation Guide (JSIG), 11 April 2016. SAP ISSOs are essential to ensure the cybersecurity posture of AFMC's various SAP systems. However, analysis undertaken in recent years has revealed a troubling trend in which field units consistently fail cybersecurity inspections. It is imperative that AFMC train its SAP ISSOs and ensure they comprehend DoD, DAF, and AFMC regulations, policies, guidelines, methodologies, strategies, processes, templates, tools, and system hardening requirements.
Failure to provide this training could lead to the corruption, denial, exposure, or compromise of critical AFMC SAP information, potentially resulting in loss of life or limb, loss of technical advantage over adversary nations, loss of air/space craft, loss of other significant DoD, DAF, and AFMC financial resources and investments, and failure to comply with federal laws and DoD, DAF, and AFMC regulations, policies, and guidelines.
3.0 Description of Services.
3.1 Course Length. The Contractor shall provide a course length of 32 hours of instruction, not to exceed a four-day period. The Contractor should plan for a 60–90-minute lunch based on the availability of meal services at the course location. The Contractor shall provide necessary breaks during instruction not to exceed 15 minutes per one (1) hour of instruction.
3.2 Target Audiences. In general, the primary target audience are AFMC SAP cybersecurity personnel with limited experience with, and formal training on, documenting and protecting SAP information and information systems in accordance with the JSIG. The secondary audience are AFMC SAP cybersecurity personnel responsible for overseeing and managing SAP cybersecurity programs at the program level and higher. The Contractor shall consider the fact that the target audiences are Adult Learners.
3.3 Course Content. The Contractor shall provide quality course content and shall work with the Government to ensure the course is appropriately tailored to meet the needs of the target the audience (see para 3.2), while addressing the spirit and intent described in 2.0, Introduction.
Successful delivery of this course is important to national security as it will facilitate the protection of Classified National Security Information (CNSI), SAP, and Sensitive Compartmented Information (SCI), as well as the systems used to process, store, and transmit this information, against unauthorized access and disclosure; unauthorized modification, removal, or destruction; and denial of authorized access or service. The Contractor should incorporate Adult Learning principles for their curriculum development (Visual, Auditory, Kinesthetic) to ensure effective transfer of knowledge and skills.
3.3.1 The Contractor shall state how they will incorporate Principles of Adult Learning into their instructional systems design. The Contractor shall ensure that no less than 10% of the course curriculum incorporates Kinesthetic, or hands-on, learning. The Contractor should incorporate a robust number of visual displays to support their curriculum.
3.3.2 The Contractor is encouraged to consult with subject matter experts (SMEs) from various functional backgrounds to support well-balanced course content (e.g., experienced SAP Information System Security Managers (ISSMs); experienced SAP ISSOs; SAP Authorizing Officials (AOs), SAP Security Controls Assessors (SCAs), etc.). The Contractor should be able to state how they will incorporate various SME-perspectives and insights into their instructional systems design/course.
3.3.3 The Contractor shall ensure the course content is set up in a logical fashion to support understandings of the information, from broad concepts to the necessary details.
3.3.4 The Contractor shall incorporate all applicable aspects of SAP information and information system documentation and protection, to include associated system accreditation paperwork, process, and requirements.
3.3.4.1 The Contractor shall instruct on purpose and scope of standard JSIG and RMF information system accreditation artifacts (e.g., Authorization to Operate (ATO); Denial of Authorization to Operate (DATO); Interim Authorization to Test (IATT); Interconnection Security Agreement (ISA); System Security Plan (SSP); System Topology; Hardware/Software Lists; Security Technical Implementation Guide (STIG) Applicability List; Ports, Protocols, and Services (PPS) Matrix; Vulnerability Scans; STIG Compliance Scans; Risk Assessment Report (RAR); Security Assessment Report (SAR); Plan of Actions & Milestones (POA&Ms), etc.).
3.3.4.2 The Contractor shall provide robust visual information on planning, designing, and implementing documentation and protection of SAP information and information systems, including implementing security controls, safeguards, and equipment (e.g., Identification, Authentication, Authorization, and Auditing (IAAA); Intrusion Detection/Protection Systems (IDS/IPS); Firewalls; etc.). The Contractor should incorporate aspects of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations, and other NIST SP 800 series publications, to support depth of instruction.
3.3.4.3 The Contractor shall provide instruction on underlying concepts associated with successfully completion of required JSIG RMF artifacts. This includes but is not limited to the RMF Process, Business Impact Analysis (BIA), Risk and Threat Analysis, Risk Management Strategies, System Development Life Cycle (SDLC), Information System Boundaries, Control Selection, and Defense-in-Depth.
3.3.5 The Contractor shall provide a copy of course materials to the Government at least 30 calendar days prior to the first course offering. Any major modifications to course content shall be submitted to the Government for review no less than 10 calendar days prior to implementation. The Government reserves the right to request the Contractor to make reasonable course content adjustments prior to course execution.
3.3.6 In support of quality assurance (4.2), the Government will collect student feedback to evaluate and monitor Contractor performance on course content.
3.4 Student Course Materials.
3.4.1 The Contractor shall provide hard-copy training materials (e.g., notetakers, handouts) for each student. Printouts should be easily readable, to include graphics, with font size 11 or greater, and shall follow the flow of any slides presented.
3.4.2 The Contractor shall provide laptop computers, for the duration of the course, for use by students in hands-on course exercises/labs. Laptop computers provided by the Contractor will be returned to the Contractor at the end of the course.
3.4.3 In support of quality assurance (4.2), the Government will collect student feedback to evaluate and monitor Contractor performance for the quality and delivery of course materials.
3.5 Course Delivery, Instruction, & Feedback.
3.5.1 The Contractor shall host in-person courses unless otherwise agreed to by the Government. Course location will be hosted per (4.4) Place of Performance.
3.5.2 The Contractor shall provide quality instruction to meet requirements of this PWS.
3.5.2.1 The Contractor shall provide at least one knowledgeable and experienced primary instructor for the duration of each course offering. All instructors shall have subject matter expertise in areas relevant to the course (e.g., SAP RMF accreditation, SAP ISSM/ISSO duties, computing in multi-classification level environments, secure communications, etc.). Evidence of this requirement shall be provided with the initial bid (it can be as basic as a resume or written paragraph on the instructors’ backgrounds), and 30 calendar days prior to course start upon change of primary instructor(s). All instructors are expected to actively participate and instruct during the training.
3.5.2.2 The Contractor is encouraged to seek and provide experienced instructors or subject matter experts from various functional backgrounds to support well-balanced course delivery and instruction (e.g., experienced SAP Information System Security Managers (ISSMs); experienced SAP ISSOs; SAP Authorizing Officials (AOs), SAP Security Controls Assessors (SCAs), etc.).
3.5.3 The Contractor shall take daily attendance by having students sign-in at the beginning of each day and after lunch. The Contractor shall collect emergency contact information of course attendees at the start of course. The Contractor shall notify the Government POC if a course attendee is unaccounted after 2 hours from daily course starts and lunch break return. The Contractor should ensure they provide an administrative overview at the start of the course to cover such things as restroom locations, emergency exits, inclement weather, and food services. When the Government provides the training location (e.g., building, conference room, etc.), the Contractor will coordinate with the Government POC to obtain the required administrative information.
3.5.4 The Contractor shall issue professional certificates for each student successfully completing the course. Issued certificates may be hard-copy or digital. The Contractor must provide the Government POC with the digital certificates or copies of the hard-copy certificates within 3 business days of course conclusion. All provided certificates must be individual PDFs and include the students’ names in the title.
3.5.5 The Contractor should provide the student with opportunities to provide course feedback. The Government will not require copies of the Contractor’s feedback forms.
3.5.6 In support of quality assurance (4.2), the Government will collect student feedback to evaluate and monitor Contractor performance for course delivery and instruction.
3.6 Communications and scheduling
3.6.1 Following contract award, the Contractor shall provide updates to the Government as requested. Turnaround time for communications should be within 3 business days.
3.6.2 The Contractor shall work with the Government Program Management Office’s designated Government POC to schedule training as needed following contract award.
3.7 Government Program Management. The Government personnel responsible for individual sites will provide access to all technical data required to perform approved taskings.
Only the Government Program Manager(s) have authority to review and approve contract deliverables in coordination with the Government Contracting Officer.
3.7.1 The overall program management responsibilities for this effort resides with the following office:
HQ AFMC/A5/8Z
4375 Chidlaw Rd, Area A, Bldg 262, Suite S-010 Wright-Patterson AFB, OH 45433-7142
3.7.2 The Contractor will be notified at time of award of the primary Quality Assurance Program Coordinator assigned to this effort.
3.8 Government Contract Management. Responsibility for contracting activities rests solely with the Government Contracting Officer. No conversation, recommendations, or direction, whether given directly by, or implied by Government personnel, affecting scope, schedule, or price of the program covered by this PWS, shall be acted upon by the Contractor unless specifically approved by the Government Contracting Officer located at the below address:
4.0 Contractual Requirements.
4.1 Pricing. The Contractor initial bid shall provide a clear cost structure outlining the cost per course. The cost structure shall be valid for the duration of the contract. Course materials shall be included in the overall cost structure.
4.2 Quality Assurance. The Government reserves the right to review services being provided.
The Government will collect student feedback to evaluate and monitor Contractor performance.
The Government will also investigate complaints received from customers. The Contractor shall be responsible for initially validating customer complaints; however, the Government Representative shall make final determination of the validity of customer complaint(s) in cases of disagreement with customer(s).
4.3 Quality Control. The Contractor is solely responsible for the quality of services provided.
The Contractor is also liable for the Contractor employee negligence, and any fraud, waste, or abuse. Re-performance of any work for failure to perform in accordance with the specified requirement shall be completed at the Contractor’s own expense and at no additional cost to the Government.
4.4 Place of Performance. Courses are projected to take place on/or around Wright-Patterson Air Force Base (AFB), which serves as the Government’s primary location.
4.5 Government Furnished Equipment/Information (GFE/GFI). The Government may provide unclassified information in support of this contract upon request by the Contractor (e.g., policies, references). The Government may host courses and provide access/use of Government facilities and/or equipment for use by the Contractor upon mutual agreement. The Contractor shall coordinate with the applicable Government POCs for access/use of GFE/GFI. The Contractor shall be responsible for safeguarding GFE issued outside Government controls for Contractor use in support of this contract. At the end of each work period, all Government facilities, equipment, and materials shall be secured.
4.6 Contractor Identification. Contractor personnel should distinguish themselves from Government employees (course attendees) during execution of courses through distinct badges or attire. When conversing with Government personnel during training sessions, electronic mail, or telephone, the Contractor shall ensure they clearly identify themselves as such (i.e., Contractor and company affiliation), to avoid situations arising where sensitive topics might be better discussed solely between Government employees.
4.7 Security Requirements. The Government will not release any Classified or Unclassified Covered Defense Information to the Contractor in support of this contract. The Contractor shall not release outside their controls any information provided by the Government, unless required in the performance of the Contract. The Contractor shall follow all applicable security protocols and rules for Military Installation access when applicable. The Government will direct the Contractor of any necessary avenues required to obtain any applicable identification badges, entry control cards, and vehicle passes. The Contractor shall return issued badges, cards, and passes to the Government at the conclusion of each training session.
5.0 Deliverables. Below are deliverables that shall be required for the tasks outlined in this
PWS.
5.1 All deliverables must meet and comply with the requirements set forth in this PWS.
6.0 Services Summary.
SERVICES SUMMARY (SS)
PERFORMANCE OBJECTIVES, PERFORMANCE THRESHOLDS,
METHODS OF SURVEILLANCE AND REMEDIES
Performance Objective
PWS
para.
Performance Threshold
Provide Quality Course Content
3.3 Provide quality course content covering aspects of the PWS. The Government will collect student feedback and overall rating of Contractor provided course content 0-10. The Contractor shall maintain an average quality rating of 6 or higher to obtain future scheduling.
Provide Student Course Materials
3.4 Provide 100% of students with hard-copy training materials that is easily readable, to include graphics, with font size 11 or greater, and fully functioning laptop computers for hands-on computer labs/exercises. The Government will collect student feedback on whether or not they received readable course materials and fully functioning laptop computers 0-10. The Contractor shall maintain an average quality rating of 6 or higher to obtain future scheduling.
Provide quality Course Delivery, Instruction, & Feedback
3.5 The Contractor shall provide quality course delivery and
instruction to meet requirements of this PWS. The Government will collect student feedback rating Contractor method of delivery and instruction 0-10. The Contractor shall maintain an average quality rating of 6 or higher to obtain future scheduling.
Student Accountability and Attendance
3.5.3 Record student attendance for each day of the course via a sign in roster. Provide the Government with a copy of the sign-in rosters within 3 business days of the conclusion of the course.
Certificates 3.5.4 Provide the students and Government with a certificate of completion within 3 business days of the conclusion of the course.
Instructor SMEs 3.5.2 The Government shall be provided documentation of primary instructors’ background/subject matter expertise showing how the PWS standard is met. Any new instructors to be added following award shall be similarly vetted and approved no later than 30 calendar days prior to their first course of instruction.
Presentation Materials
3.3 Final training material shall be provided to the Government at least 30 calendar days prior to the first course offering. Any updates made to the training material thereafter shall be provided to the Government ASAP, but no later than 10 business days prior to the start of the next course.
7.0 Voluntary Protection Program.
Applicability: This section of the PWS applies to “Applicable Contractors” as defined below.
Definitions:
Applicable Contractor. A Contractor whose employees worked at least 1,000 hours at the site in any calendar quarter within the last 12 months and is NOT directly supervised by the applicant (installation).
Days Away, Restricted, and or Transfer Case Incident Rate (DART). The number of recordable injuries and illness cases per 100 full-time employees resulting in days away from work, restricted work activity, and/or job transfer that a site has experienced in a given time frame.
Total Case Incidence Rate (TCIR). Total number of recordable injuries and illness cases per 100 full-time employees that a site has experienced in a given time frame.
Voluntary Protection Programs. The Voluntary Protection Program (VPP) promotes effective worksite-based safety and health. In the VPP, management, labor, and OSHA establish cooperative relationships at workplaces that have implemented a comprehensive safety and health management system. Approval into VPP is OSHA’s official recognition of the outstanding efforts of employers and employees who have achieved exemplary occupational safety and health.
Requirements. Wright-Patterson AFB is in the process of pursuing VPP recognition or has already been recognized under the OSHA Voluntary Protection Program (VPP). VPP impacts all “applicable contractors” operating on Air Force Installations. The Contractor shall be responsible for ensuring their employees and managers have a comprehensive understanding of VPP as well as full compliance with OSHA requirements. The Contractor shall follow the safety and health rules of the installation or VPP site. Detailed information on VPP is available on the OSHA website at http://www/osha.gov/dcsp/vpp/index.html
The Contractor shall submit a Safety and Health Plan and corresponding site safety checklist to the Contracting Officer not later than 10 calendar days after contract award. The Contractor’s plan shall include appropriate measures to ensure the Contractor reacts promptly to investigate, correct, and track alleged safety and health violations and/or uncontrolled hazards in contractor work areas. The plan shall:
Demonstrate a management commitment to employee safety and health;
Identify the application of the safety and health plan to subcontractors;
Identify the roles and responsibilities of the following individuals with respect to safety and VPP: Management, Supervisors, Employees, and Safety Coordinator;
Identify applicable safety rules and regulations;
Include a worksite hazard analysis to include base-line hazard identification and required control measures;
Include a job site analysis to include hazards of tasks required to control measures;
Identify employee safety and health training requirements and the documentation process;
Include a workplace inspection frequency, to include identifying the individual conducting the inspections;
Include employee hazard reporting procedures;
Identify individual(s) responsible for corrective action of hazards;
Identify first aid/injury procedures;
Identify procedures for accident investigation and reporting;
Identify emergency response procedures; and Identify the process for tracking controlled hazards in contractor work areas.
The Contractor shall submit their Total Case Incidence Rate (TCIR) and Days Away, Restricted, and or Transfer Case Incident Rate (DART) rates and OSHA Form 300A annually to the contracting office for consolidation and submission as part of the installation’s annual VPP Safety and Health Management report. TCIR and DART rates are due by the 15th of January of each year.
The contractor’s Quality Control Plan shall identify the processes and procedures the Contractor will use to track compliance with the Safety and Health Plan, and the process and procedures that will be used to correct violations.
The Contractor shall establish these VPP requirements for all subcontractors who qualify as applicable contractors under the resulting contract.
8.0 Contractor Manpower Reporting Language for Contract Performance Work Statements.
The Contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the Air Force via a secure data collection site.
The Contractor is required to completely fill in all required data fields using the following Air Force link web address: http://www.ecmra.mil/
Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30.
While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year.
Reporting Period: Contractors are required to input data by 31 October of each year. Uses and Safeguarding of Information: Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the Contractor name and contract number associated with the data.
User Manuals: Data for Air Force service requirements must be input at the Air Force CMRA link. However, user manuals for government personnel and contractors are available at the Army CMRA link at http://www.ecmra.mil <http://www.ecmra.mil> .
Contractors may direct questions to the help desk at: http://www.ecmra.mil/.
9.0 Combating Trafficking in Persons
Combating Trafficking in Persons (CTIP) is a worldwide problem posing a transnational threat involving violations of basic human rights. The DoD has a zero tolerance policy for TIP. As part of the 2013 National Defense Authorization Act, the Pentagon is required to take action against any contractor engaging in any activities related to labor trafficking, sex trafficking and child soldiering. The Contractor should familiarize its employees with TIP by going to the DoD CTIP site at: http://ctip.defense.gov/Home.aspx. The Contractor should immediately report all suspicious activity of its employees to the COR or CO.
File details come from the government source that posted it. Updated .