Attachment 1 Base Contract PWS for ECS.pdf
PDF 994 KB Posted
- Attached to
- Marine Corps Systems Command (MARCORSYSCOM) Electronic and Communication Systems (ECS) Multiple Award Task Order Contract (MATOC) Federal contract opportunity
- Solicitation number
- M6785420R7829
- Issued by
- United States Marine Corps
About this file
This is a performance work statement for an Electronic and Communication Systems multiple award task order contract to be awarded by the United States Marine Corps. The contract is for life cycle management support and other Marine Corps training requirements involving electronic and communication services. The scope includes support for training systems such as the Marine Air-Ground Task Force Tactical Warfare Simulation System and Deployable Virtual Training Environment. The performance work statement outlines general requirements, security requirements, program management, and risk management framework support. It also addresses engineering changes, systems engineering, and validation and testing. Contractors must comply with various Department of Defense, Department of the Navy, and Marine Corps instructions and manuals. Task orders will specify location and schedule requirements and will be awarded on a firm-fixed price basis.
View the file
Other files for this federal contract opportunity
Show all 50
Marine Corps Systems Command (MARCORSYSCOM) Electronic and Communication Systems (ECS) Multiple Award Task Order Contract (MATOC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
M67854-20-R-7829 Attachment 1
UNCLASSIFIED
Base Contract Performance Work Statement (PWS) for the
Electronic and Communication Services (ECS)
Version 0.1
18 September 2020
Prepared by
Program Manager, Training Systems
DISTRIBUTION STATEMENT A. Approved for public release. Distribution is unlimited.
- 2 -
UNCLASSIFIED
Table of Contents INTRODUCTION ............................................................................................................... - 4 -
GENERAL ................................................................................................................... - 4 -
SCOPE ......................................................................................................................... - 4 -
APPLICABLE DOCUMENTS ........................................................................................... - 5 -
DEPARTMENT OF DEFENSE INSTRUCTIONS, DIRECTIVES, STANDARDS AND
GUIDES ....................................................................................................................... - 5 -
DEPARTMENT OF THE NAVY INSTRUCTIONS, DIRECTIVES, STANDARDS AND
GUIDES ....................................................................................................................... - 6 -
MARINE CORPS ORDERS, MANUALS, DIRECTIVES AND GUIDES ............... - 6 -
AVAILABILITY OF DOD DOCUMENTS ................................................................ - 6 -
OTHER DOCUMENTS, DRAWINGS AND PUBLICATIONS ................................ - 7 -
REQUIREMENTS .............................................................................................................. - 7 -
GENERAL REQUIREMENTS ................................................................................... - 7 -
NON-PERSONAL SERVICES ....................................................................................... - 7 -
BUSINESS RELATIONS ................................................................................................ - 7 -
CONTRACTOR PERSONNEL, DISCIPLINES, AND SPECIALTIES ........................ - 9 -
RESOURCE REQUIREMENTS ................................................................................... - 10 -
SECURITY REQUIREMENTS .................................................................................... - 12 -
VISIT REQUESTS ........................................................................................................ - 17 -
SAFETY ........................................................................................................................ - 17 -
LOCATIONS AND HOURS OF WORK ...................................................................... - 17 -
DRESS AND CONDUCT ............................................................................................. - 20 -
TRAVEL ........................................................................................................................ - 21 -
PROGRAM MANAGEMENT ...................................................................................... - 22 -
GOVERNMENT PROPERTY ...................................................................................... - 31 -
RISK MANAGEMENT FRAMEWORK (RMF) SUPPORT ....................................... - 32 -
ENGINEERING CHANGE PROPOSALS (ECPs) ....................................................... - 43 -
SYSTEM CHANGES .................................................................................................... - 43 -
SYSTEMS ENGINEERING (SE) ................................................................................. - 43 -
SOFTWARE ENGINEERING ...................................................................................... - 43 -
INTERFACE AND DATA MANAGEMENT .............................................................. - 43 -
INFORMATION SECURITY MANAGEMENT ......................................................... - 43 -
CONFIGURATION MANAGEMENT ......................................................................... - 43 -
- 3 -
UNCLASSIFIED
VALIDATION AND TESTING ................................................................................... - 43 -
SPECIAL QUALIFICATIONS/REQUIREMENTS ..................................................... - 43 -
3.1.23 MANAGEMENT INFORMATION REPORT…………………………………………-44-
3.1.24 SYSTEM FOR AWARD MANAGEMENT (www.sam.gov) SERVICE CONTRACT
REPORTING…………………………………………………………………………...-44-
3.2 DELIVERABLES ............................................................................................................ - 44 -
3.3 SPECIFIC REQUIREMENTS........................................................................................... - 45 -
APPENDIX A. JOINING CONTRACTOR MACHINE TO THE MCEN .............................. - 46 -
APPENDIX B. USMC CONTRACT SUPPORT USER AGREEMENT FOR THE MCEN .. - 47 -
APPENDIX C. CONTRACTS TO BE PERFORMED IN JAPAN ......................................... - 50 -
APPENDIX D. STATUS OF FORCES AGREEMENT (SOUTH KOREA) .......................... - 56 -
- 4 -
UNCLASSIFIED
INTRODUCTION
GENERAL
This Performance Work Statement is in support of the Electronic and Communication
Services (ECS) Multiple Award, Task Order Contract (MATOC). This MATOC is structured for maximum flexibility in the form of the issuance of task orders (TOs) through an expedited ordering process to satisfy the ECS requirements for overall total life cycle management support, as well as other Marine Corps training requirements that fall within the scope described below. TO Performance Work Statements (PWSs) will provide the specific performance requirements, performance standards, metrics, assessment measures, and schedules for each TO.
SCOPE
All DoD services fall within one of nine (9) Service Portfolio Groups within DoD’s Taxonomy of
Services, which is required pursuant to DoD FAR Supplement (DFARS) Policy, Guidance and
Instruction (PGI) 237.102-74. The Program Manager, Training Systems’ (PM TRASYS’) contracting authority is limited to the Marine Corps Systems Command’s (MARCORSYSCOM’s) authority delegated in SECNAVINST 5400.15C. PM TRASYS is the MARCORSYSCOM Program
Manager responsible for the life cycle systems support for training systems, services, environments, and devices. Therefore, PM TRASYS has the authority to award contracts in support of five (5) of the 9 Service Portfolio Groups identified in DoD’s Taxonomy of Services, which includes the ECS
Portfolio Group.
PM TRASYS intends to award MATOCs that are primarily aligned with the Service Portfolio Group within DoD’s Taxonomy of Services. This PWS is in support of the ECS Portfolio Group, which includes the following Service Portfolios, which have Portfolio Categories and corollary PSCs identified in DoD’s Taxonomy of Services: IT Services; Telecom Services; Equipment Maintenance;
and Equipment Leases.
The scope of this effort is intended to be broad in nature and entails ECS support for all existing and any future USMC training systems and any corollary Foreign Military Sales including, but not limited to: the Marine Air-Ground Task Force (MAGTF) Tactical Warfare Simulation System
(MTWS); the Deployable Virtual Training Environment (DVTE); Combined Arms Command and
Control Training Upgrade System (CACCTUS); Combat Convoy Simulator (CCS); Indoor
Simulated Marksmanship Trainer (ISMT); Marine Corps Driver Trainer (MCDT); Supporting Arms
Virtual Trainer (SAVT); and Combat Vehicle Training Systems (CVTS).
In general, equipment to be supported under this MATOC are simulators or simulations systems that use electronic and/or mechanical means to reproduce conditions necessary for an individual, team, unit, or crew to rehearse operational tasks and technical skills in accordance with training objectives.
The simulators and simulations systems replicate the functions and environment of actual equipment or systems and consist of training devices, machines, or apparatuses that reproduce operational conditions synthetically.
TOs will provide the specific performance requirements, locations, schedules, standards, metrics, and assessment measures for each TO issued against this ECS MATOC. In the event of a conflict between this Base Contract PWS and the TO PWS, the TO PWS requirements that are specific to
- 5 -
UNCLASSIFIED
the training system takes precedence. The specific scope of the TO can include, but is not limited to the following: post deployment software support (PDSS); non-PDSS; and cybersecurity.
This ECS MATOC does not include any construction of real property. Construction of real property is an installation requirement and will be performed by Government personnel or under a Naval
Facilities Engineering Command contract. Should the Contractor identify a requirement for the construction or repair of real property, it shall report it to the Contracting Officer Representative for appropriate action.
APPLICABLE DOCUMENTS
The current version of the following documents form a part of this PWS to the extent specified herein. Moreover, the latest version of the following documents in effect at the time of the issuance of a TO PWS will supersede the prior version of the document cited in this PWS. In addition, the
Contractor shall also comply with all applicable local and base policies. Unless otherwise noted, in the event of a conflict between the PWS and the references cited herein, the text of the TO PWS takes precedence.
DEPARTMENT OF DEFENSE INSTRUCTIONS, DIRECTIVES, STANDARDS AND
GUIDES
DoDD 4715.E Environmental, Safety, and Occupational Health (ESOH)
DoDM 5200.1 Volume 1 – DoD Information Security Program: Overview, Classification, and Declassification
DoDM 5200.1 Volume 2 – DoD Information Security Program: Marking of Classified
Information
DoDM 5200.1 Volume 3 – DoD Information Security Program: Protection of Classified
Information
DoDI 5200.48 Controlled Unclassified Information
DoD Directive 5205.02E – DoD Operations Security (OPSEC) Program
DoDI 5220.22 – National Industrial Security Program (NISP)
DoD 5220.22-M – National Industrial Security Program Operating Manual
DoDI 5230.09 – Clearance of DoD Information for Public Release
DoDI 5230.24 – Distribution Statements on Technical Documents
DoDD 5230.25 – Withholding of Unclassified Technical Data from Public Disclosure
DoDI 5400.11 – DoD Privacy and Civil Liberties Programs
DOD 5500.07-R – Joint Ethics Regulation
DoDI 6055.01 – DoD Safety and Occupational Health (SOH) Program
DoDD 8140.01– Cyberspace Workforce Management
DoDI 8500.01 – Cybersecurity
DoDI 8510.01 – Risk Management Framework (RMF) for DoD Information Technology (IT)
DoD 8570.01-M – Information Assurance Workforce Improvement Program
DoDD 4500.54E DoD Foreign Clearance Program
- 6 -
UNCLASSIFIED
DEPARTMENT OF THE NAVY INSTRUCTIONS, DIRECTIVES, STANDARDS AND
GUIDES
SECNAVINST 3070.2 – Operations Security
SECNAV M-5216.5 – Department of the Navy Correspondence Manual
SECNAV M-5239.1 – Department of the Navy Information Assurance Manual
SECNAVINST 5510.30C – Department of the Navy Personnel Security Program
SECNAVINST 5510.36B – Department of the Navy Information Security Program
MARINE CORPS ORDERS, MANUALS, DIRECTIVES AND GUIDES
MCO 3070.2A – The Marine Corps Operations Security Program
MCO 5100.29 B – Marine Corps Safety Program
MCO 5200.17E – Standardization of Military and Associated Terminology
MCO 5216.20B – Marine Corps Supplement to the Department of the Navy Correspondence
Manual
MCO 5216.9Y – Headquarters U.S. Marine Corps Organization and Organization Codes
MCO 5239.2B – Marine Corps Cybersecurity
MCO 5510.18B – United States Marine Corps Information and Personnel Security Program
(IPSP)
MCO 5510.20B – Disclosure of Military Information to Foreign Governments and Interests
MCO 5530.14A – Marine Corps Physical Security Program Manual
MCO 11000.5 – Facilities Sustainment, Restoration and Modernization Program
ALMAR 010/01, USMC Policy on Civilian Guests
MCBul 5603 – Marine Corps Doctrinal Proponency Assignments
MCINCR-MCBQO 5530.2 – Access Control Policy
MSTP Security Standard Operating Procedures (SECSOP)
NAVMC DIR 5100.8, Marine Corps Occupational Safety and Health (OSH) Program
Manual
AVAILABILITY OF DOD DOCUMENTS
DoD Directives, Manuals, Instructions, and Publications are available online at http://www.DTIC.mil/ or from the National Technical Information Services (NTIS), 5285
Port Royal Road, Springfield, VA 22161
DoN Directives, Manuals, Instructions, and Publications are available online at https://doni.documentservices.dla.mil/default.aspx
USMC Orders, Manuals, Directives, and Guides are available online at http://www.marines.mil/News/Publications/ELECTRONIC-LIBRARY/
Electronic Foreign Clearance Guide available online at https://www.fcg.pentagon.mil/fcg.cfm https://www.fcg.pentagon.mil/fcg.cfm
- 7 -
UNCLASSIFIED
OTHER DOCUMENTS, DRAWINGS AND PUBLICATIONS
CNSS Instruction No. 4009 National Information Assurance (IA) Glossary
OSHA regulation 1910.142 Occupational Safety and Health Standards
Parts 120-130 of Title 22, Code of Federal Regulations (also known as the “International
Traffic in Arms Regulations”)
Parts 730-774 of Title 15, Code of Federal Regulations (also known as the “Export
Administration Regulations”)
United States Forces Korea Regulation 700-19, Appendix B
JP 1-02 – DoD Dictionary of Military and Associated Terms
U.S. Forces Japan Instruction 31-207 – Firearms and Other Weapons in Japan
U.S. Forces Japan Instruction 36-2611 – Change of Status by Persons in Japan to One of the
Categories Authorized by the Status of Forces Agreement
U.S. Forces Japan Instruction 64-100 – Contract Performance in Japan
U.S. Forces Japan Instruction 64-102 – United States Contractors and their Employees
U.S. Forces Korea Regulation 700-19 – The Invited Contractor and Technical Representative
Program
REQUIREMENTS
All tasks identified in this PWS are for providing ECS services to support Marine Corps training and education requirements of the Fleet Marine Forces, which includes both active duty and reserve components, and all supporting establishments.
GENERAL REQUIREMENTS
NON-PERSONAL SERVICES
The Government will neither supervise Contractor personnel nor control the method by which the
Contractor performs the required tasks. The Government will not assign tasks, nor prepare work schedules for individual Contractor personnel. The Contractor shall manage its personnel and guard against any actions that give the perception of personal services. To provide a clear distinction between Government employees and Contractor employees, Contractor employees shall identify themselves as such by introducing themselves or being introduced as Contractor personnel and displaying distinguishing badges or other visible identification for meetings with Government personnel, as well as appropriately identifying themselves as Contractor personnel in telephone conversations and in formal and informal written correspondence. Contractor personnel shall present their badges upon request by Government employees and their representatives. If the Contractor believes that any actions constitute or are perceived to constitute personal services, it shall be the
Contractor's responsibility to notify the Contracting Officer (KO) and the Contracting Officer’s
Representative (COR) immediately.
BUSINESS RELATIONS
The Contractor shall successfully integrate and coordinate all activities needed to execute the requirements contained herein and in any TO. The Contractor shall provide corrective action plans,
- 8 -
UNCLASSIFIED
proposal submittals, timely identification of issues, and effective management of subcontractors. The
Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all
Contractor personnel.
COOPERATION
While it is not planned, there may be instances in which more than one Marine Corps contractor is required to work on the same base/location. In such instances, it is the expectation of the
Government that the Contractor extends basic professional courtesy and collaborative interaction.
Should an issue arise, the Contractor shall reach a mutual agreement without the assistance of the
Government. In the event that the contractors cannot resolve an issue, it is the responsibility of the
Contractor to promptly notify the Contracting Officer in writing and furnish recommendations for a solution. The Contractor shall not be relieved of its obligations under the MATOC (and corresponding TO) or be entitled to any other adjustment because of failure to promptly refer matters to the Contracting Officer or failure to implement the Contracting Officer’s directions. The
Contractor is not relieved of any contract requirements or entitled to any adjustments to the contract terms or price because of a failure to resolve a disagreement with another contractor unless the
Contractor provides prior notice to the Contracting Officer and proof to the Contracting Officer that the failure to resolve was not due to the Contractor’s negligence, fault, failure to cooperate, or failure to perform its obligations in good faith.
Should Contracting Officer intervention be required, the Government reserves the right to terminate the TOs for convenience at no cost to the Government. If a TO is terminated, the Government may make an award to (or negotiate an award with) another MATOC Contractor based on proposals received in response to the initial request for TO proposals.
CONSTRUCTIVE CHANGES
No modification, statement, or conduct of Government personnel who might visit the Contractor’s facility or in any other manner communicate with Contractor personnel during the performance of this contract will constitute a change under the “Changes” clause of this contract. No understanding or agreement, contract modification, change order, or other matter deviating from or constituting an alteration or change of the terms of the contract will be effective or binding upon the Government unless formalized by contractual documents executed by the Contracting Officer.
The Contracting Officer is the only person authorized to approve changes in the requirements of this contract, and, notwithstanding provisions contained elsewhere in the contract, the said authority remains solely with the Contracting Officer. In the event that the Contractor effects any change(s) at the direction of any person other than the Contracting Officer, these change(s) will be at the
Contractor’s expense. No adjustment will be made in the contract price or other contract terms and conditions, as the Contracting Officer did not approve consideration for the unauthorized change.
Further, should the unauthorized change be to the Government’s detriment, the Contractor may be held financially responsible for its correction.
RESPONSIBILITY IN SUBCONTRACTING
The Contractor shall provide the technology processes, test procedures, data, drawings, and other information required to facilitate competition to the fullest extent feasible and ensure performance by selected subcontractors. The Contractor shall be fully responsible for ensuring that all
- 9 -
UNCLASSIFIED
appropriate contractual provisions and clauses are flowed down to its subcontractors and that those provisions are enforced.
TASK ORDERS
The Government will rely upon competition among MATOC awardees to obtain fair and reasonable pricing and maintain quality services. The Government may, in its discretion, terminate any
MATOC for convenience at any point in the ordering period if the Contractor fails to respond to more than one request for a TO proposal. In such cases, the Contractor agrees by the submission of their proposal in response to this solicitation, which includes a signed SF33 by an agent of the
Offeror, who has the authority to sign on behalf of the Offeror, that the Minimum Guarantee fully satisfies any obligation of the Government to pay termination for convenience costs. Termination for convenience under this paragraph will prohibit the Contractor from participating in future TO competitions, but, does not relieve the Contractor from the obligation to perform on any previously awarded TO or prohibit the Government from exercising an option on any previously awarded TO.
TOs for services or work described herein may be issued by the Contracting Officer at any time during the effective term of this contract. The Contracting Officer will be responsible for assuring that the requirements of DFARS 215.404 are met in the event that the conditions identified in FAR
16.505(b)(2) are utilized.
Except as otherwise provided in a specific TO, the Contractor shall furnish all materials and services necessary to accomplish the work specified therein. These materials shall include consumable items, device repair parts/components, tools and test equipment, and support equipment not otherwise provided by the Government to the Contractor. The provisions of this agreement apply to all TOs issued, and to the extent that any inconsistency between a TO and this MATOC might take place, the
MATOC shall take precedence.
Each TO will be individually funded. The appropriation and accounting data required to obligate funds will be included in each TO. As provided in each TO, Contractors may be required to track and invoice multiple lines of accounting (LOA) on each Contract Line Item Number (CLIN). As a result, Contractors must be able to track performance and report based on the applicable LOA.
3.1.2.5 COR AND ACOR
The use of the term COR throughout this document also includes the term Alternate COR
(ACOR), if an ACOR is appointed in writing by the Contracting Officer, unless specifically excluded. An ACOR, if appointed, can only act in the absence of the appointed COR. There can only be one COR for a contract, and the duties of the COR are not delegable.
3.1.2.6 QUALITY ASSURANCE SURVEILLANCE PLAN
The Government conducts surveillance of the Contractor’s performance under this MATOC in accordance with the Quality Assurance Surveillance Plan (QASP). All deliverables will be inspected for content, completeness, accuracy, and conformance to contract requirements by the
Government. This will include inspecting for nonconforming or unjustified markings of data delivered to the Government for acceptance as specified in the contract.
CONTRACTOR PERSONNEL, DISCIPLINES, AND SPECIALTIES
The Contractor shall satisfy the requirements of this PWS and subsequent TOs by employing and
- 10 -
UNCLASSIFIED
utilizing personnel with an appropriate combination of education, knowledge, skills, abilities, and experience (if applicable). The Contractor shall match the appropriate labor categories and the labor hours required to meet all the work required to be performed under the TO. All personnel training, licenses, certification, and qualifications specified in this PWS and/or subsequent TOs shall be obtained, maintained, paid for and otherwise provided for by the Contractor.
RESOURCE REQUIREMENTS
The Contractor shall provide all personnel, equipment, tools, materials, supervision, and quality control necessary to perform the ECS requirements defined in this PWS and subsequent TOs.
MARINE CORPS ENTERPRISE NETWORK (MCEN)
All computer assets necessary to perform any tasks and that are otherwise required by the Contractor to meet the performance requirements of this PWS and subsequent TOs, whether to be connected to the MCEN or to be employed as standalone assets, shall be provided by the Contractor.
Contractor personnel accessing Marine Corps Systems Command Computer systems, must maintain compliance with United States Marine Corps Enterprise Cybersecurity Manual 007
Resource Access Guide. Contractor personnel will submit a DD 2875, and completion certificates for the CYBERC course located on MarineNet located at https://www.marinenet.usmc.mil The
CYBERC course consist of the DOD Cyber Awareness Challenge and Department of the Navy
Annual Privacy Training (PII). Contractors will have to create a MarineNet account in order to acquire the required training.
MCEN IT resources if provided are designated For Official Use Only (FOUO) and other limited authorized purposes. DoD military, civilian personnel, consultants, and contractor personnel performing duties on MCEN information systems may be assigned to one of three position sensitivity designations.
1) ADP-I (IT-1): Favorably adjudicated T-5, T5R, Single Scope Background
Investigation (SSBI)/SSBI Periodic Reinvestigation (SBPR)/SSBI Phased Periodic
Reinvestigation (PPR)
2) ADP-II (IT-2): Favorably adjudicated T-3, T3R, Access National Agency Check and Inquiries (ANACI)/ National Agency Check with Law and Credit (NACLC)/Secret
Periodic Review (S-PR)
3) ADP-III (IT-3): Completed T-1, National Agency Check with Inquiries (NACI)
All privileged users (IT-1) must undergo an SSBI regardless of the security clearance level required for the position. Privileged users must maintain the baseline Cyberspace Workforce
Information Assurance Technical (IAT) or Information Assurance Manager (IAM) relating to the position being filled. Privileged users are defined as anyone who has privileges over a standard user account as in system administrators, developers, network administrators, code signing specialist and Service Desk technicians.
All MCEN users must read, understand, and comply with policy and guidance to protect classified information and CUI, and to prevent unauthorized disclosures in accordance with
United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide and http://www.marinenet.usmc.mil/ http://www.marinenet.usmc.mil/
- 11 -
UNCLASSIFIED
CJCSI 6510.01F.
MCEN Official E-mail usage – MCEN IT resources are provided For Official Use Only
(FOUO) and other limited authorized purposes. Authorized purposes may include personal use within limitations as defined by the supervisor or the local Command. Auto forwarding of e-mail from MCEN-N to commercial or private domains (e.g., Hotmail, Yahoo, Gmail, etc.) is strictly prohibited. E-mail messages requiring either message integrity or non-repudiation are digitally signed using DoD PKI. All e-mail containing an attachment or embedded active content must be digitally signed.
MCEN users will follow specific guidelines to safeguard Controlled Unclassified Information
(CUI), including PII and For Official Use Only (FOUO). Non-official e-mail is not authorized for and will not be used to transmit CUI to include PII and Health Insurance Portability and
Accountability Act (HIPAA) information. Non-official e-mail is not authorized for official use unless under specific situations where it is the only mean for communication available to meet operational requirements. This can occur when the official MCEN provided e-mail is not available but must be approved prior to use by the Marine Corps Authorizing Official (AO).
All personnel will use DoD authorized PKI certificates to encrypt e-mail messages if they contain any of the following:
1. Information that is categorized as For Official Use Only (FOUO).
2. Any contract sensitive information that normally would not be disclosed to anyone other than the intended recipient.
3. Any privacy data, PII, or information that is intended for inclusion in an employee’s personal file or any information that would fall under the tenets of MSGID: DOC/5
USC 552A. Personal or commercial e-mail accounts are not authorized to transmit unencrypted CUI or PII.
4. Any medical or health data, to include medical status or diagnosis concerning another individual.
5. Any operational data regarding status, readiness, location, or deployment of forces or equipment.
Contractor assets connectivity to the MCEN – The contracting company will comply with
MCENMSG-Unification 003-14 ENABLING CONTRACTOR ASSET CONNECTIVITY TO
THE MCEN. The Contractor representative will transfer the contractor owned laptops to the
MCSC G-6, Information Technology Asset Management (ITAM) department to have the MCEN images places on each laptop before it is authorized to connect to the MCEN.
All Contractor owned laps must meet or exceed the USMC laptop specifications. A list of laptops authorized to be attached to the MCEN can be obtained from MCSC G-6 upon request.
Upon completion of the contact or at such time as the contractor reclaims the asset from the
USMC, non-Government owned internal\external hard drives shall become the property of the U.S.
Government. Once the hard drives have been removed, the laptops\assets will be returned to the
Contractor. For additional questions regarding current system specifications contact the MCSC, ITAM lead at (703) 432-4396.
Magnetic Hard Drive Storage Devices – This paragraph covers the requirements of classified and unclassified internal and removable magnetic and Solid State hard drives that store the
Government data. This includes, but is not limited to, storage area network (SAN) devices,
- 12 -
UNCLASSIFIED
servers, workstations, laptops/notebooks, printers, copiers, scanners and multi-functional devices
(MFD) with internal hard drives, removable hard drives and external hard drives. Upon disposal, replacement, turn in of hard drives or completion of the contract, non-Government owned internal\external hard drives shall become the property of the U.S. Government in accordance with
GENADMIN Processing of Magnetic Hard Drive Storage Media for Disposal.
SECURITY REQUIREMENTS
3.1.5.1 SECURITY REQUIREMENTS
TOs may require the contractor to have a Secret Facility Clearance and will require certain contractors to obtain and maintain classified access eligibility. If a Secret Facilty Clearance is a requirement of the TO, then the Contractor shall have a valid Secret Facility Clearance prior to classified performance. The prime contractor and all sub-contractors (through the prime contractor) shall adhere to all aspects of DoD Directive 5220.22-M and DoD Manual 5220.22
Volume 2. All personnel identified to perform on this contract shall maintain compliance with
Department of Defense, Department of the Navy, and Marine Corps Information and Personnel
Security Policy to include completed background investigations (as required) prior to classified performance. This contract shall include a DoD Contract Security Classification Specification
(DD-254) as an attachment. Certain contractors will be required to perform IT-I/II duties that will require favorably adjudicated Tier 5/3 Level investigations. The Defense Counterintelligence
Security Agency (DCSA) will not authorize contractors to submit the necessary Tier Level investigations solely in support of IT level designation requirements, but are required to submit investigations for those employees requiring both Secret access and IT-II designation. The
Government Contracting Activity Security Office (GCASO) is required to submit any required investigations in support of IT-I level designations.
The Contractor is required to provide a roster of prospective contractor personnel performing IT-I duties to the MCSC Contracting Officer’s Representative (COR). This roster shall include: full names, Social Security Numbers, e-mail address and phone number for each contractor requiring investigations in support of IT Level designations. The COR will verify the IT-I requirements and forward the roster to the GCASO. Contractors found to be lacking required investigations will be contacted by the GCASO.
Facility Security Officers (FSOs) are responsible for notifying the MCSC AC/S G-2 Personnel
Security Office (PERSEC Office) via encrypted e-mail to MCSC_Security@usmc.mil or 703-432-
3374/3952 if any contractor performing on this contract receives an unfavorable adjudication. The
FSO must also notify the PERSEC Office, within 24 hours, of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor performing on this contract, if they have been issued a CAC, a MCSC Building Badge and/or granted classified access.
The FSO shall notify the Government (written notice) within 24 hours of any Contractor personnel added or removed from the contract that have been issued a Common Access Card (CAC) and/or a
MCSC Building badge/access.
3.1.5.2 COMMON ACCESS CARD (CAC) REQUIREMENT
The TO COR will identify and approve those Contractor employees performing on a TO that require CACs in order to perform their job function.
mailto:MCSC_Security@usmc.mil
- 13 -
The COR will identify and only approve those contractor employees performing on this contract that require CACs in order to perform their job function. In accordance with Headquarters, United
States Marine Corps issued guidance relative to Homeland Security Presidential Directive – 12
(HSPD-12), all personnel must meet eligibility criteria to be issued a CAC. In order to meet the eligibility criteria, contractor employees requiring a CAC must obtain and maintain a favorably adjudicated Personnel Security Investigation (PSI). Prior to authorizing a CAC, the employee’s
Joint Personnel Adjudication System (JPAS) record must indicate a completed and favorably adjudicated PSI or (at a minimum) that a PSI has been submitted and accepted (opened). The minimum acceptable investigation is a T-1 or a National Agency Check with Written Inquiries
(NACI). If a contractor employee’s open investigation closes and is not favorably adjudicated, the
CAC must be immediately retrieved and revoked. CACs are not issued for convenience.
Facility Security Officers (FSOs) are responsible for notifying the MCSC AC/S G-2 Personnel
Security Office (PERSEC Office) at 703-432-3490/3952 if any contractor performing on this contract receives an unfavorable adjudication after being issued a CAC. The FSO must also immediately notify the PERSEC Office of any adverse/derogatory information associated with the
13 Adjudicative Guidelines concerning any contractor issued a CAC, regardless of whether a
JPAS Incident Report is submitted.
Each CAC is issued with a “ctr@usmc.mil” e-mail account that the individual contractor is responsible to keep active by logging in on a regular basis (at least twice a month), sending an e-mail and clearing any unneeded e-mails. Contractors issued a CAC are prohibited from “auto-forwarding” e-mail from their .mil e-mail account to their .com e-mail account. If the
“ctr@usmc.mil” e-mail account is not kept active, G-6 will deactivate the account and the CAC will also lose its functionality. Contractor employees shall solely use their government furnished
“ctr@usmc.mil” e-mail accounts for work supporting the USMC, conducted in fulfillment of this contract, and shall not use a contractor supplied or personal e-mail account to conduct FOUO government business. The use of a contractor or personal e-mail account for contractor business or personal use is allowed, but only when using cellular or a commercial internet service provider.
If a contractor loses their eligibility for a CAC due to an adverse adjudicative decision, they have also lost their eligibility to perform on MCSC contracts.
3.1.5.3 PUBLIC KEY INFRASTRUCTURE (PKI) REQUIREMENTS
Where interoperable DOD PKI is required for the exchange of unclassified information between
DOD and its vendors and Contractors for access to PK-enabled information systems and websites, industry partners shall obtain all necessary certificates. A DOD PKI certificate or Interim External
Certificate Authority (IECA) certificate is required to enable the Contractor to access to the DOD, USMC, and task/program-specific collaboration resources. Information concerning this certificate can be obtained at the http://iase.disa.mil/pki/eca/index.html website.
3.1.5.4 PHYSICAL SECURITY
At the close of each work period, Government facilities, equipment, and materials shall be secured.
mailto:ctr@usmc.mil http://iase.disa.mil/pki/eca/index.html%20website.
- 14 -
UNCLASSIFIED
3.1.5.5 WEAPONS SECURITY
Any ECS training system weapons are simulated/demilitarized weapons utilized for training and are not real weapons. Notwithstanding that they are not real weapons, in some cases a Federal Firearms
License is required (see paragraph under Special Qualifications below). However, any ECS training system weapons shall be securely stored and transported in accordance with federal, state, and other laws and regulations to ensure security, loss prevention and accountability.
3.1.5.6 SYSTEM SECURITY
1. System Security Plan and Plans of Action and Milestones (SSP/POAM) Reviews
a. Within 30 days of TO award, the Contractor shall make its System Security Plan(s) (SSP(s)) for its covered contractor information system(s) available for review by the Government at the contractor’s facility. The SSP(s) shall implement the security requirements in Defense Federal
Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which is included in this contract. The Contractor shall fully cooperate in the Government's review of the SSPs at the
Contractor's facility.
b. lf the Government determines that the SSP(s) does not adequately implement the requirements of
DFARS clause 252.204-7012 then the Government shall notify the Contractor of each identified deficiency. The Contractor shall correct any identified deficiencies within 30 days of notification by the Government. The contracting officer may provide for a correction period longer than 30 days and, in such a case, may require the Contractor to submit a plan of action and milestones (POAM) for the correction of the identified deficiencies. The Contractor shall immediately notify the contracting officer of any failure or anticipated failure to meet a milestone in such a POAM.
c. Upon the conclusion of the correction period, the Government may conduct a follow-on review of the SSP(s) at the Contractor's facilities. The Government may continue to conduct follow-on reviews until the Government determines that the Contractor has corrected all identified deficiencies in the
SSP(s).
d. The Government may, in its sole discretion, conduct subsequent reviews at the Contractor's site to verify the information in the SSP(s). The Government will conduct such reviews at least every three
(3) years (measured from the date of contract award) and may conduct such reviews at any time upon thirty days' notice to the Contractor.
2. Compliance to NIST 800-171
a. The Contractor shall fully implement the CUI Security Requirements (Requirements) and associated Relevant Security Controls (Controls) in NIST Special Publication 800-171 (Rev. I)
(NIST SP 800-171), or establish a SSP(s) and POAMs that varies from NIST 800-171 only in accordance with DFARS clause 252.204-7012(b)(2), for all covered contractor information systems affecting this contract.
b. Notwithstanding the allowance for such variation, the contractor shall identify in any SSP and
POAM their plans to implement the following, at a minimum:
(1) Implement Control 3.5.3 (Multi-factor authentication). This means that multi-factor authentication is required for all users, privileged and unprivileged accounts that log into a network.
In other words, any system that is not standalone should be required to utilize acceptable multi-factor authentication. For legacy systems and systems that cannot support this requirement, such as CNC
- 15 -
UNCLASSIFIED
equipment, etc., a combination of physical and logical protections acceptable to the Government may be substituted;
(2) Implement Control 3.1.5 (least privilege) and associated Controls, and identify practices that the contractor implements to restrict the unnecessary sharing with, or flow of, covered defense information to its subcontractors, suppliers, or vendors based on need-to-know principles;
(3) Implement Control 3.1.12 (monitoring and control remote access sessions) - Require monitoring and controlling of remote access sessions and include mechanisms to audit the sessions and methods.
(4) Audit user privileges on at least an annual basis;
(5) Implement:
i. Control 3.13.11 (FIPS 140-2 validated cryptology or implementation of NSA or NIST approved algorithms (i.e. FIPS 140-2 Annex A: AES or Triple DES) or compensating controls as documented in a SSP and POAM); and,
ii. NIST Cryptographic Algorithm Validation Program (CAVP) (see https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program);
(6) Implement Control 3.13.16 (Protect the confidentiality of CUI at rest) or provide a
POAM for implementation which shall be evaluated by the Navy for risk acceptance.
(7) Implement Control 3.1.19 (encrypt CUI on mobile devices) or provide a plan of action for implementation which can be evaluated by the Government Program Manager for risk to the program.
3. Cyber Incident Response:
a. The Contractor shall, within 15 days of discovering the cyber incident (inclusive of the 72-hour reporting periodcovered in 3.1.5.7 below), deliver all data used in performance of the contract that the Contractor determines is impacted by the incident and begin assessment of potential warfighter/program impact.
b. Incident data shall be delivered in accordance with the Department of Defense Cyber Crimes
Center (DC3) Instructions for Submitting Media available at http:/ www.acq.osd.mil/dpap/dars/pgi/docs/Instructions _for_Submitting_Media.docx. In delivery of the incident data, the Contractor shall, to the extent practical, remove contractor-owned information from Government covered defense information.
c. If the Contractor subsequently identifies any such data not previously delivered to DC3, then the
Contractor shall immediately notify the contracting officer in writing and shall deliver the incident data within 10 days of identification. In such a case, the Contractor may request a delivery date later than 10 days after identification. The contracting officer will approve or disapprove the request after coordination with DC3.
4. Naval Criminal Investigative Service (NCIS) Outreach
The Contractor shall engage with NCIS industry outreach efforts and consider recommendations for hardening of covered contractor information systems affecting DON programs and technologies.
5. NCIS/Industry Monitoring
a. In the event of a cyber incident or at any time the Government has indication of a vulnerability or
- 16 -
UNCLASSIFIED
potential vulnerability, the Contractor shall cooperate with the Naval Criminal Investigative Service
(NCIS), which may include cooperation related to: threat indicators; pre-determined incident information derived from the Contractor's infrastructure systems; and the continuous provision of all
Contractor, subcontractor or vendor logs that show network activity, including any additional logs the Contractor, subcontractor or vendor agrees to initiate as a result of the cyber incident or notice of actual or potential vulnerability.
b. If the Government determines that the collection of all logs does not adequately protect its interests, the Contractor and NCIS will work together to implement additional measures, which may include allowing the installation of an appropriate network device that is owned and maintained by
NCIS, on the Contractor1s information systems or information technology assets. The specific details (e.g., type of device, type of data gathered, monitoring period) regarding the installation of an
NCIS network device shall be the subject of a separate agreement negotiated between NCIS and the
Contractor. In the alternative, the Contractor may install network sensor capabilities or a network monitoring service, either of which must be reviewed for acceptability by NCIS. Use of this alternative approach shall also be the subject of a separate agreement negotiated between NCIS and the Contractor.
c. In all cases, the collection or provision of data and any activities associated with this performance work statement shall be in accordance with federal, state, and non-US law.
3.1.5.7 ADDITIONAL SYSTEM SECURITY REQUIREMENTS
To provide adequate security, the Contractor shall implement National Institute of Standards and
Technology (NIST) Special Publication 800-171, Protecting Controlled Unclassified Information in
Nonfederal Systems and Organizations, the Contractor shall provide a System Security Plan (SSP) and Plan of Action and Milestones (POAMs) in accordance with Contractor’s SSP (CDRL A001) indicating whether the Contractor has implemented the security requirements therein, plans to implement the security requirements, or that the requirement is not applicable.
The Contractor shall submit a list in accordance with the Contractor’s Record of Tier 1 Level
Suppliers Receiving/Developing CUI (CDRL A002) of all supporting Tier 1 Level suppliers receiving or developing covered defense information, otherwise known as CUI. In addition, the
Contractor shall provide its plan to government review and approval to track flow down of covered defense information and to assess DFARS Clause 252.204-7012 compliance of known Tier 1 Level suppliers.
The Contractor shall document and report all cyber incidents that affect the covered Contractor information system or the covered defense information residing therein, or that affect the
Contractor’s ability to perform requirements designated as operationally critical support via the
Cyber Incident Reporting (CDRL A003). The Contractor shall submit malicious software discovered and isolated in connection with a reported cyber incident to the DoD Cyber Crime
Center. The Contractor shall report all cyber incidents or compromise related to Government CUI in accordance with DFARS 252.204-7012 to the Damage Assessment Office (DAMO) via the DIB-
NET Website (http://dibnet.dod.mil) within 72 hours. The Contractor shall if requested, submit media and additional information to support damage assessment.
CDRL A001: DI-MGMT-82247 Contractor’s System Security Plan
CDRL A002: DI-MISC-80508B Contractor’s Record of Tier 1 Level Suppliers http://dibnet.dod.mil/
- 17 -
UNCLASSIFIED
Receiving/Developing CUI
CDRL A003: DI-MISC-80508B Cyber Incident Reporting
VISIT REQUESTS
The Contractor shall comply with DoD 5220.22-M, National Industrial Security Program Operating
Manual and SECNAV M‐5510.30, JUN 2006, DoN Personnel Security Program, ALMAR 010/01, USMC Policy on Civilian Guests and Federal Acquisition Regulation (FAR) 52.204‐2 for access to
USMC bases and information. All Contractor visits requiring a visit access request (VAR) shall be provided by the Facility Security Officer (FSO) via the JPAS system a minimum of five working days prior to scheduled visits. Contractor personnel shall have two forms of picture identification, which shall include a valid employee badge issued by the Contractor, when visiting a worksite either at the home work station or while traveling to other sites.
SAFETY
ACCIDENTS, MISHAPS, AND GOVERNMENT DECLARED EMERGENCIES
The Contractor shall immediately report any accident/incident with safety/security implications or any other conditions or incidents that could reasonably be expected to be of interest to the COR and the Contracting Officer no more than four hours from the accident or mishap. Damage to
Government property or injury to Government or Contractor personnel or civilian guests must be reported to the COR and Contracting Officer within four hours. Contractor initial reports may be verbal but shall be followed up in writing within 24 hours. Contractor reports of incidents with security implications shall include full details of the incident, any remedial actions that were taken by the contractor, and shall comply with all applicable security instructions.
The Contractor shall investigate all accidents occurring on Government property involving
Contractor personnel and report the findings (on applicable forms) to the COR and Contracting
Officer within three calendar days of the incident.
Reportable incidents shall be reported to the Government by the Contractor in accordance with the requirements of this PWS via submission of CDRL B001 - Accident Mishap Report. The data deliverable shall be generated and delivered to the Government for reportable events in accordance with the specific performance requirements that accompany each individual TO for services.
The Contractor may experience an unexpected suspension of training or operation aboard USMC facilities due to Government declared medical or other emergencies. TOs may require Contractor action in response to Government-declared medical or other emergencies to ensure the training systems and related equipment continue to be suitable for training.
CDRL B001: DI-MGMT-82188 Accident Mishap Report
LOCATIONS AND HOURS OF WORK
Each TO for services will identify the specific places of performance applicable to the period of performance for that TO. In addition, each TO will also address any specific conditions applicable to the hours of work related to performance under the order. Federal law (5 U.S.C. 6103) establishes
- 18 -
UNCLASSIFIED
the following public holidays, which will be recognized for the purpose of this requirement:
New Year's Day
Birthday of Martin Luther King, Jr.
Washington's Birthday
Memorial Day
Independence Day
Labor Day
Columbus Day
Veterans Day
Thanksgiving Day
Christmas Day
However, the Government may schedule training events on Federal Government holidays that require Contractor support.
This is a performance-based services acquisition implemented through fixed price TOs. This is not a time-and-materials or labor-hours contract. Therefore, the Contractor is required to meet performance requirements as part of the proposed firm-fixed price even where the Government’s needs necessitate Contractor performance beyond the typical eight-hour work day or forty hour work week.
INCLEMENT WEATHER
In the event of inclement weather, the Contractor shall comply with the local installation’s Inclement
Weather Policy. The Contractor will provide notice to the Contracting Officer and COR, as soon as is reasonably possible, when inclement weather conditions impact one or more of the places of performance provided for under the contract. The Contractor is not required to return to any
Government facilities to survey equipment or conduct operations checks until the installation has announced "all clear."
INSTALLATION ACCESS
The Contractor shall comply with installation, facility, and area commander installation/facility access and local security policies and procedures.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .