Attachment 1 PWS_Amend 0002.pdf
PDF 317 KB Posted
- Attached to
- Marine Corps Tactical Systems Support Activity (MCTSSA) Networks, Engineering, Test and Cybersecurity (NETC) Services Federal contract opportunity
- Solicitation number
- M68909-20-R-7600
- Issued by
- United States Marine Corps
About this file
This is a pre-solicitation notice for a multiple award task order contract to provide network, engineering, testing and cybersecurity services. The Marine Corps Tactical Systems Support Activity plans to issue a solicitation on or around May 1, 2020 seeking these services located at Marine Corps Base Camp Pendleton, California. The period of performance is expected to begin August 10, 2020. The anticipated procurement will be firm fixed price with a 100% small business set-aside. Offerors must register in the System for Award Management to be eligible for award. The North American Industry Classification System code for this requirement is 541512 for computer systems design services.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| M68909-20-R-7600 NETC RFP_Amendment 0003.pdf | ||
| Attachment 5_Past Performance Questionnaire v2.docx | DOCX document | |
| Attachment 6_Notional Travel.pdf | ||
| M68909-20-R-7600 NETC RFP_Amendment 0002.pdf | ||
| Attachment 3 DD254 June 3 2020.pdf | ||
| M68909-20-R-7600 NETC RFP_QA - FINAL_0002.pdf | ||
| M68909-20-R-7600 NETC RFP_Amendment 0001.pdf | ||
| Attachment 3 DD254.pdf | ||
| Attachment 1 PWS_FINAL.pdf | ||
| M68909-20-R-7600 NETC RFP.pdf | ||
| Attachment 5_Past Performance Questionnaire.docx | DOCX document | |
| Attachment 4 Past Performance Worksheet.docx | DOCX document | |
| Attachment 2 CDRL_FINAL.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement for the
Marine Corps Tactical Systems Support Activity (MCTSSA) Networks, Engineering, Test, and Cybersecurity Services
13 May 2020
Prepared by:
UNITED STATES MARINE CORPS
Marine Corps Tactical Systems Support Activity
Camp Pendleton, CA 92055-5171
PWS for MCTSSA Engineering, Test, Networks, and Cybersecurity ii
TABLE OF CONTENTS
1 INTRODUCTION
1.1 Mission
1.2 Background
1.3 Scope
1.3.1 Engineering
1.3.2 Testing
1.3.3 Laboratory Management
1.3.4 Configuration Management
1.3.5 Specialized Services Support
2 APPLICABLE DOCUMENTS
2.1 Compliance Documents
2.2 Guidance Documents
3 REQUIREMENTS
3.1 General Requirements
3.1.1 Contract Data Requirements List (CDRL) Item Deliverables
3.1.2 Quality Control Plan (QCP)
3.1.3 Non-Personal Services
3.1.4 Business Relations
3.1.5 Contractor Personnel, Disciplines, and Specialties
3.1.6 Resource Requirements
3.1.7 Security Requirements
3.1.8 Safety – Accidents and Mishaps
3.1.9 Locations and Hours of Work
3.1.10 Dress and Conduct
3.1.11 Travel
3.1.12 Privacy Act Information
3.1.13 Program Management
3.1.14 Government-Furnished Information (GFI)
3.1.15 Invoicing
3.1.16 Administrative Authority
3.2 Specific Requirements
4 ORGANIZATIONAL CONFLICT OF INTEREST
APPENDIX A – ACRONYMS ................................................................................................. A-1 APPENDIX B – CDRL SUMMARY ........................................................................................ B-1
1 INTRODUCTION
The acquisition strategy for the Marine Corps Tactical Systems Support Activity (MCTSSA) Networks, Engineering, Test, and Cybersecurity Services requirement is to award a Multiple Award Task Order Contract (MATOC). The anticipated contract will have five 1-year ordering periods.
1.1 Mission
MCTSSA is a subordinate command to Marine Corps Systems Command (MCSC). MCTSSA supports the Program Managers in the conduct of developmental testing, integration, and sustainment support of Command, Control, Communications, Computers, and Intelligence (C4I) Programs of Record (PoRs). These C4I systems and PoRs form the foundation of the Marine Corps net-centric operational focus and are vital to the Marine Corps continued success.
1.2 Background
MCTSSA supports over 50 PoRs throughout all phases of the acquisition life cycle. The majority of this support is provided to program managers within MCSC and Program Executive Office Land Systems (PEO LS) and extends to other organizations, such as Marine Forces Cyber Command, Marine Corps Operational Test and Evaluation Activity, Naval Air Warfare Command, Special Operations Command, as well as providing direct support to the Fleet Marine Forces. The MCTSSA technical workforce is comprised of civilians and active duty Marines, with educational backgrounds in electrical engineering, computer engineering, computer science, and information technology. The MCTSSA technical services span the spectrum of Department of Defense (DoD) weapons systems and information technologies and operates in an increasingly complex, networked, joint information environment. As a result, cybersecurity considerations generally apply to all C4I Systems, due to interfacing with a combination of networks, platforms, support systems, or other elements of the operating environment that are potentially exploitable by constantly evolving cyber threats. Current cybersecurity certifications involve assessments of compliance-based security controls and are necessary for establishing a secure foundation;
however, they are not sufficient to protect systems in the operational environment from the cyber threat. DoDI 5000.02 has recently been updated to direct that all systems will conduct an adversarial cyber assessment as part of Developmental Testing (DT). MCTSSA is responsible for DT, integration development, and sustainment of integrated Enterprise C4I PoRs.
This MATOC provides services in the following functional areas that support the command’s mission of developmental testing, integration, and sustainment support of the C4I PORs:
• Engineering
• Testing
• Laboratory management
• Configuration management
• Specialized services
1.3 Scope
The Contractor shall provide personnel with suitable technical and analytical expertise to perform the support activities outlined in this document, as well as each subsequent task order.
The Contractor shall ensure technical management, coordination of task activities, and administrative support be provided as required. Detailed tasks will be provided in each task order PWS.
1.3.1 Engineering
Engineering services include technical investigation of systems in all phases of a program life cycle, for tactical and enterprise-level C4I systems, and reporting, analysis, resolving and documenting technical issues. The C4I subject matter expert (SME) will be required to have 5 years of experience, at a minimum.
The Contractor shall provide the following engineering services:
• Develop and evaluate Engineering Change Proposals (ECPs), which may include subsequent testing
• Develop and evaluate technical documentation
• Design Architectures
• Evaluate emerging and alternative technologies
• Perform tasks associated with Government acceptance testing in support of fielding efforts
• Perform systems Information Assurance (IA) compliance testing
1.3.2 Testing
The Contractor shall perform the following test activities:
• Conduct test planning
• Develop and evaluate technical documentation
• Conduct Project management o Develop test schedules o Identify required resources and resource conflicts o Create meeting notes
• Develop test event architectures
• Develop test plans
• Develop test cases
• Execute test cases
• Collect, reduce, and analyze test data
• Develop test reports
• Perform tasks associated with Government acceptance testing in support of fielding efforts
• Perform systems Information Assurance (IA) compliance testing
1.3.3 Laboratory Management
The Contractor shall provide the following laboratory services:
• Perform security and access control of laboratory spaces o Conduct inventory of Controlled Cryptographic Information (CCI)/Classified
Material Control Center (CMCC) equipment o Maintain the visitor and equipment log books o Ensure accurate equipment accountability
• Maintain and update logical network and hardware rack diagrams
• Perform the following asset management tasks:
o Manage Consolidated Memorandum Report (CMR) accounts o Manage Electronic Key Management System (EKMS) sub-custody accounts o Conduct inventory control and induction/tracking in the maintenance system o Coordinate purchase requests with Chief Information Officer (CIO), Fiscal, and
Contracts
• The Contractor shall provide the following administrative support:
o De-conflict events and resources within the lab.
o Maintain equipment accountability.
o Setup and maintain laboratory audio-visual equipment in support of meetings.
o Record meeting notes o Report and track maintenance requests with MCTSSA Logistics section to ensure a safe and clean work environment.
1.3.4 Configuration Management
The Contractor shall provide the following configuration management support:
• Records Management – Identify, mark, record, and transfer media
• Audit test labs, capture data, and write test incident reports
• Use automated discovery tools where appropriate
• Create and maintain configuration templates
1.3.5 Specialized Services Support
1.3.5.1 Advanced Network Engineering
The required services include providing research, evaluation, and reporting on current and emerging networking technologies and policies. Additionally, the services include identifying, collecting, analyzing, and reporting to MCSC and other required Marine Corps agencies regarding USMC and joint service C4I systems network performance issues. Finally, this service will include providing network engineering for developmental, operational, and integrated test and evaluation of USMC and Joint Service C4I systems.
Each person providing Advanced Network Engineering is required to have DoD 8570 certification (Security+) and 5 years of experience in providing networking support. The team, as a whole, must include individuals with the following education and experience: Computer Science or equivalent degree, Cisco Certified Network Administrator (CCNA), VMware Certified Administrator (VCA), Microsoft Certified System Administrator (MCSA), and Wireshark Certified Network Analyst (WCNA).
The Contractor shall provide the following network engineering services:
• Conduct deep network traffic packet analysis
• Conduct root cause analysis of applications and network flow
• Provide network efficiency recommendations
• Establish application network profile baselines
• Provide enterprise level network analysis
• Design and develop networks for tactical and garrison environments
• Create software defined networks
• Perform cybersecurity hardening
• Develop tools to accelerate network analysis reporting
1.3.5.2 Data Science, Artificial Intelligence (AI), Machine Learning (ML), and Software Development Services
MCTSSA established the Tactical Artificial Intelligence Cell (TAIC) as a premier AI center of excellence for the Marine Corps. The TAIC is tasked to develop ML models/applications for tactical use cases. This includes providing AI systems support for users in the Fleet Marine Force (FMF), creating a knowledgeable workforce, providing test and evaluation for ML applications (as they are introduced into PoRs), and satisfying AI related requests for information.
The Contractor shall provide the following services:
• Validate AI commercial vendor products
• Develop deep learning models
• Translate operational needs into ML requirements
• Evaluate and assess ML model performance
• Identify and assess bias in externally developed models
• Conduct statistical data analysis
• Develop the user interface for deploying ML models
• Leverage a cloud infrastructure for developing and deploying ML models
1.3.5.3 Command, Control, Communication, Computer, and Intelligence (C4I) System Services
The C4I subject matter experts (SMEs) will be required to have 5 years of experience, at a minimum. The Contractor shall provide the following C4I system services:
• Systems administration (e.g., MS Windows, VMware, Fortinet)
• Network engineering (e.g., IPv4/v6, Cisco)
• Application prototyping (e.g., commercial of-the-shelf (COTS), government off-the-shelf
(GOTS))
• Systems integration
• Preventative maintenance and equipment configuration
• Analysis of Tactical Data Links (e.g., Link-16,VMF)
• Systems Operation
1.3.5.4 Cybersecurity
The objective of cyber Research, Development, Test and Evaluation (RDT&E) is to improve the resilience of military capabilities before beginning production and deployment. Early discovery of systems vulnerabilities will facilitate remediation to reduce impact on cost, schedule, and performance. Vulnerabilities are discovered through the performance of comprehensive cybersecurity penetration testing, as defined in the MCTSSA Cyber DT Framework, Standard Operating Procedures (SOP), or awardee processes that have been preapproved by the MCTSSA cyber lead. Testing will be led by the MCTSSA adversarial penetration test team. Testing will be conducted at various sites including MCTSSA DT labs, other Government labs, and through the Joint Information Operations Range. Remote testing efforts require the development of test documentation including, but not limited to: Test Plan, Quick Look Report, and Test Report.
Annual reviews will be performed to ensure continued process improvement of configuration-controlled documentation in the execution of cyber DT, with changes implemented at the recommendation of the MCTSSA cyber lead. Research activities are intended to provide MCTSSA with continuous education on the latest penetration testing techniques, vulnerabilities, and exploits. Research also includes system deep dives and the execution of cyber table top events. Development activities include research, identification, evaluation, creation and refinement of cyber test tools, training environments, test environments, exploit modification/generation, report generation and dissemination, tools, and other cyber software or hardware requirements. Integrated Product Teams (IPTs) consisting of government and contractor personnel will routinely be formed to accomplish tasks and projects.
The Contractor shall provide the following cybersecurity services:
• Perform cybersecurity adversarial penetration test assessments of systems and applications
• Participate in integrated product teams (IPTs)
• Provide input to official taskers
• Conduct cyber research and development activities
• Develop process documentation
2 APPLICABLE DOCUMENTS
2.1 Compliance Documents
Performance shall comply with the current versions of the following documents when performing the work described in this PWS:
a. Department of Defense Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information Technology.
b. Marine Corps Order (MCO) 5239.2A, Marine Corps Cybersecurity Program (MCCSP).
c. A-DUSD IE ICS Memo, Real Property-related Industrial Control System Cybersecurity.
d. DoDI 8500.01, Cybersecurity.
e. DoDI 5000.02, Operation of the Defense Acquisition System.
f. DoDI 8140.01, Cyberspace Workforce Management.
g. DoDI 8570.01-M, Information Assurance Workforce Improvement Program.
h. Chairman of the Joint Chiefs of Staff Manual (CJCSM) 3212.02D, Performing Electronic
Attack in the United States and Canada for Tests, Training And Exercises.
i. CJCSM 5215.01, International Cyberspace Security Cooperation.
j. Federal Information Processing Standard Publication (FIPS PUB) 140-2, Security
Requirements For Cryptographic Modules.
k. National Institute of Standards and Technology (NIST), NIST Handbook 150-20
Checklist – Common Criteria Testing.
l. DoD, IPv6 Standard Profiles for IPv6 Capable Products.
m. Defense Information Systems Agency (DISA), Joint Interoperability Test Command, Department of Defense Internet Protocol Version 6 Generic Test Plan.
n. DoD, Unified Capabilities Requirements.
o. DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM).
2.2 Guidance Documents
The current versions of the following documents shall be used as guidance when performing the work described in this PWS:
a. MCTSSA Technical Document Style Guide.
b. MCTSSA Templates (e.g., test plan, test report, technical report).
c. MCTSSA Cyber Development Test Framework.
d. Internet Research Task Force, Network Working Group, Request For Comments (RFC)
4838, Delay Tolerant Networking Architecture.
e. Internet Research Task Force, Network Working Group, Request For Comments (RFC)
2501, Mobile Ad hoc Networking (MANET): Routing Protocol Performance Issues and Evaluation Considerations.
f. International Organization for Standardization, ISO 15893:2010, Space Data and Information Transfer Systems – Protocol Specification for Space Communications – Transport Protocol.
g. Jenson, Shane, Consolidated Tactical Network Analysis for Optimizing Bandwidth:
Marine Corps Support Wide Area Network (SWAN) and TCP Accelerators, Naval Postgraduate School Thesis.
h. Criston Cox, Optimizing Bandwidth in Tactical Communications Systems, Naval Postgraduate School Thesis.
i. DoD, Internet Protocol IPv6 Transition Plan.
j. Marine Corps Internet Protocol Version 6 (IPv6) Transition Plan, Release 3.3.
k. Nation Institute of Standards Technology, Special Process 500-267; A Profile for IPv6 in the U.S., Government-Version 1.0.
l. OSD Memo, Guidance on Cybersecurity Implementation in Acquisition Programs.
m. Office of the Deputy Assistant Secretary of Defense (DASD) Developmental Test and
Evaluation (DT&E), Guidelines for Cybersecurity DT&E.
n. DoD, Cybersecurity Test and Evaluation Guidebook.
3 REQUIREMENTS
3.1 General Requirements
3.1.1 Contract Data Requirements List (CDRL) Item Deliverables The CDRL items shall be delivered to the Government in the current MCTSSA template format consistent with the contract, the Task Order(s), the Data Item Description (DID), and all the other requirements identified in the respective CDRL DD Form 1423. If MCTSSA does not have a template, the products shall be delivered to the Government per commercial best practices, in the version of Microsoft Office currently used by MCTSSA. A draft deliverable is due by the date established by the Government in the Task Order PWS. The final deliverable is due 5 working days after receipt of government comments on the draft, unless a different schedule is identified in the respective CDRL, or otherwise agreed to between the Government and the Contractor
3.1.2 Quality Control Plan (QCP)
The Contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services, such as a service output that does not meet the standard of performance associated with the PWS. The contractor’s quality control plan shall be defined and described in the contractor’s management plan to support the requirements of this PWS, per section 3.1.16.1. The Task Order PWS will establish a due date for the draft Management Plan. The final deliverable is due 5 working days after receipt of government comments on the initial submission, unless a different schedule is agreed to by the Government and the Contractor.
• CDRL B001 – DI‐MISC‐80508B, Management and Technical Plan
3.1.3 Non-Personal Services
The Government shall neither supervise nor control the method by which contractor personnel perform the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor personnel. It shall be the responsibility of the Contractor to manage its personnel and to guard against any actions that are of the nature of personal services, or which give the perception of personal services. If the Contractor believes that any actions constitute, or are perceived to constitute, personal services, it shall be the Contractor’s responsibility to notify the Procuring Contracting Officer (PCO) immediately.
3.1.4 Business Relations
The Contractor shall successfully integrate and coordinate all activities needed to execute the requirement. The Contractor shall manage the timeliness, completeness, and quality of problem identification. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.
3.1.5 Contractor Personnel, Disciplines, and Specialties
The Contractor shall satisfy the requirements of this PWS and subsequent task orders by employing and utilizing personnel with an appropriate combination of education, knowledge, skills, abilities, and experience. The contractor shall not employ Government personnel (military or civilian) for performance of any work described in this PWS.
3.1.6 Resource Requirements
The Contractor shall provide all personnel, tools, materials, supervision, and quality control necessary to meet the MCTSSA support services requirements defined by this PWS and subsequent task orders. Personnel training, certifications, and qualifications specified in this PWS or subsequent task orders shall be provided for by the Contractor, with the exception of the training listed in section 3.1.18.
3.1.6.1 Marine Corps Enterprise Network (MCEN)
Contractor personnel accessing Marine Corps Systems Command Computer systems, must maintain compliance with United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide. Contractor personnel will submit a DD 2875, and completion certificates for the CYBERC course located on MarineNet located at https://www.marinenet.usmc.mil The CYBERC course consist of the DOD Cyber Awareness Challenge and Department of the Navy Annual Privacy Training (PII). Contractors will have to create a MarineNet account in order to acquire the required training.
MCEN IT resources if provided are designated For Official Use Only (FOUO) and other limited authorized purposes. DoD military, civilian personnel, consultants, and contractor personnel performing duties on MCEN information systems may be assigned to one of three position sensitivity designations.
1. ADP-I (IT-1) – Favorably adjudicated T-5, T5R (formerly known as Single Scope Background Investigation (SSBI)/SSBI Periodic Reinvestigation (SBPR)/SSBI Phased Periodic Reinvestigation (PPR))
2. ADP-II (IT-2) – Favorably adjudicated T-3, T3R (formerly known as Access National Agency Check and Inquiries (ANACI)/National Agency Check with Law and Credit (NACLC)/Secret Periodic Review (S-PR))
3. ADP-III (IT-3) – Completed T-1 (formerly known as National Agency Check with Inquiries (NACI))
All privileged users (IT-1) must undergo an SSBI regardless of the security clearance level required for the position. Privileged users must maintain the baseline Cyberspace Workforce Information Assurance Technical (IAT) or Information Assurance Manager (IAM) relating to the position being filled. Privileged users are defined as anyone who has privileges over a standard user account, such as system administrators, developers, network administrators, code signing specialist, and Service Desk technicians.
All MCEN users must read, understand, and comply with policy and guidance to protect classified information and CUI and to prevent unauthorized disclosures, in accordance with United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide and
CJCSI 6510.01F.
MCEN Official E-mail usage – MCEN IT resources are provided FOUO and other limited authorized purposes. Authorized purposes may include personal use within limitations as defined by the supervisor or the local Command. Auto forwarding of e-mail from MCEN-N to commercial or private domains (e.g., Hotmail, Yahoo, Gmail etc.) is strictly prohibited. E-mail messages requiring either message integrity or non-repudiation are digitally signed using DoD PKI. All e-mail containing an attachment or embedded active content must be digitally signed.
MCEN users will follow specific guidelines to safeguard Controlled Unclassified Information (CUI), including PII and FOUO. Non-official e-mail is not authorized for and will not be used to transmit CUI, to include PII and Health Insurance Portability and Accountability Act (HIPAA) information. Non-official e-mail is not authorized for official use unless under specific situations where it is the only mean for communication available to meet operational requirements. This can occur when the official MCEN provided e-mail is not available, but must be approved prior to use by the Marine Corps Authorizing Official (AO).
All personnel will use DoD authorized PKI certificates to encrypt e-mail messages if they contain any of the following:
1. Information that is categorized as FOUO or Sensitive but Unclassified (SBU).
2. Any contract sensitive information that normally would not be disclosed to anyone other than the intended recipient.
3. Any privacy data, PII, or information that is intended for inclusion in an employee’s personal file or any information that would fall under the tenets of MSGID: DOC/5 USC 552A. Personal or commercial e-mail accounts are not authorized to transmit unencrypted CUI or PII.
4. Any medical or health data, to include medical status or diagnosis concerning another individual.
5. Any operational data regarding status, readiness, location, or deployment of forces or equipment.
Contractor assets connectivity to the MCEN – The contracting company will comply with MCENMSG-Unification 003-14 ENABLING CONTRACTOR ASSET CONNECTIVITY TO THE MCEN. The Contractor representative will transfer the contractor owned laptops to the MCTSSA S-6, Information Technology Asset Management (ITAM) department to have the MCEN images places on each laptop before it is authorized to connect to the MCEN.
All Contractor owned laps must meet or exceed the USMC laptop specifications. A list of laptops authorized to be attached to the MCEN can be obtained from MCTSSA S-6 upon request.
Upon completion of the contact or at such time as the contractor reclaims the asset from the USMC, non-Government owned internal\external hard drives shall become the property of the U.S. Government. Once the hard drives have been removed, the laptops\assets will be returned to the Contractor. For additional questions regarding current system specifications contact the MCTSSA, ITSM lead at (760) 725-8473.
Magnetic Hard Drive Storage Devices – This paragraph covers the requirements of classified and unclassified internal and removable magnetic and Solid State hard drives that store the Government data. This includes, but is not limited to, storage area network (SAN) devices, servers, workstations, laptops/notebooks, printers, copiers, scanners and multi-functional devices (MFD) with internal hard drives, removable hard drives and external hard drives. Upon disposal, replacement, turn in of hard drives or completion of the contract, non-Government owned internal\external hard drives shall become the property of the U.S. Government in accordance with GENADMIN Processing of Magnetic Hard Drive Storage Media for Disposal.
3.1.6.2 Non-MCEN Computers
If required by the specific task order PWS, the contractor will be responsible to furnish their own computers to accomplish work required by the specific task order PWS.
3.1.6.3 Common Access Card (CAC)
The Contracting Officer’s Representative (COR) will approve issuance of a CAC only to those contractor employees performing on this contract that require a CAC to perform their job function. In accordance with Headquarters, United States Marine Corps issued guidance relative to Homeland Security Presidential Directive – 12 (HSPD-12), all personnel must meet eligibility criteria to be issued a CAC. In order to meet the eligibility criteria, contractor employees requiring a CAC must obtain and maintain a favorably adjudicated Personnel Security Investigation (PSI). Prior to authorizing a CAC, the employee’s Joint Personnel Adjudication System (JPAS) record must indicate a completed and favorably adjudicated PSI or (at a minimum) that a PSI has been submitted and accepted (opened). The minimum acceptable investigation is a T-1 or a National Agency Check with Written Inquiries (NACI). If a contractor employee’s open investigation closes and is not favorably adjudicated, the CAC must be immediately retrieved and revoked. CACs are not issued for convenience.
The FSO is responsible for notifying the MCTSSA Security Manager, at 760-725-2365, if any contractor performing on this contract receives an unfavorable adjudication after being issued a CAC. The FSO must also immediately notify the MCTSSA Security Office of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor issued a CAC, regardless of whether a JPAS Incident Report is submitted.
Each CAC is issued with a “ctr@usmc.mil” e-mail account that the individual contractor is responsible to keep active by logging in on a regular basis (at least twice a month), sending an e-mail and clearing any unneeded e-mails. Contractors issued a CAC are prohibited from “auto-forwarding” e-mail from their .mil e-mail account to their .com e-mail account. If the “ctr@usmc.mil” e-mail account is not kept active, S-6 will deactivate the account and the CAC will also lose its functionality. Contractor employees shall solely use their government furnished “ctr@usmc.mil” e-mail accounts for work supporting the USMC, conducted in fulfillment of this contract, and shall not use a contractor supplied or personal e-mail account to conduct FOUO government business. The use of a contractor or personal e-mail account for contractor business or personal use is allowed, but only when using cellular or a commercial internet service provider.
If a contractor loses their eligibility for a CAC due to an adverse adjudicative decision, they have also lost their eligibility to perform on MCSC contracts.
3.1.7 Security Requirements
3.1.7.1 Eligibility for Access to Classified Information
This contract requires the contractor to have a TS facility clearance and requires certain contractor employees to obtain and maintain classified access eligibility. The contractor shall have a valid TS facility clearance prior to classified performance. The prime contractor and all subcontractors shall adhere to all aspects of the NISPOM (DoD 5220.22-M) and DoD Manual
5220.22 Volume 2. All personnel identified to perform on this contract shall maintain compliance with DoD, Department of the Navy (DON), and Marine Corps Information and Personnel Security Policy to include having completed background investigations (as required) prior to classified performance.
This contract shall include a DoD Contract Security Classification Specification (DD-254) as an attachment. Certain contractors will be required to perform IT-I/II duties that will require favorably adjudicated Tier 5/3 Level investigations. The Defense Counterintelligence Security Agency (DCSA) will not authorize Contractors to submit the necessary Tier Level investigations solely in support of IT level designation requirements, but are required to submit investigations for those employees requiring classified access and IT-II designation. The Government Contracting Activity Security Office (GCASO) is required to submit any required investigations in support of IT-I level designations. The Contractor is required to provide a roster of prospective contractor employees performing IT-I duties to the MCTSSA COR. This roster shall include the full name, social security number, e-mail address, and phone number for each Contractor requiring investigations in support of IT level designations. The COR will verify the IT-I requirements and forward the roster to GCASO. Contractors found to be lacking required investigations will be contacted by GCASO.
The Facility Security Officer (FSO) is responsible for notifying the MCTSSA Security Office at 760-725-2365 if a contractor performing on this contract receives an unfavorable adjudication.
The FSO must also notify, within 24 hours, the MCTSSA Security Office of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor performing on this contract, regardless of whether a Joint Personnel Adjudication System (JPAS) incident report is submitted. The FSO shall notify the Government (written notice) within 24 hours of any contractor personnel added to, or removed from, the contract that have been granted classified access, issued a CAC, and/or a MCTSSA building badge/access.
3.1.7.2 Qualified U.S. Contractors
The Contractor shall certify in writing to the Government that personnel supporting this contract are qualified U.S. Contractors, per DoD 5220.22‐M, Chapter 2, Section 2. Qualified U.S.
Contractors are U.S. citizens and persons admitted lawfully into the United States for permanent residence, and are located in the United States. All personnel identified on the certification or supporting this contract, or both, shall be in compliance with the DoD, DON, and the Marine Corps Information and Personnel Security Policy to include completed background investigations (as required) prior to start.
3.1.7.3 Contractor Support Public Trust Determinations
Per MCSC Policy Letter 1-09, all contractor personnel that require a CAC must submit a Standard Form 85P – Questionnaire for Public Trust Positions, and two copies of DD Form 258
– Applicant Fingerprint Card, to the Command’s Security Program office along with a personnel roster of submissions and an addressed Federal Express container addressed to Office of Personnel Management (OPM), 1137 Branchton Road, Box 618, Boyers, PA 16018.
The Contractor is responsible for determining when adjudications have been entered by reviewing the notification status of the respective personnel. After verification, the Contractor may request a CAC using the Trusted Associate Security Service (TASS). If issues are discovered, the DOD Central Adjudication Facility (DODCAF) will place a “No Determination Made” in JPAS and forward the investigation to the submitting office for government adjudication.
3.1.7.4 Security Level
Technical tasks associated with this PWS require access to classified information and a security clearance up to the North Atlantic Treaty Organization (NATO) COSMIC TOP SECRET (CTS).
The Contractor shall not divulge information regarding files, data processing activities or functions, user identifications (IDs), passwords, or other knowledge gained to anyone not authorized access to such information. Contractor personnel shall abide by all government rules, procedures, and standards of conduct.
3.1.7.5 DD Form 254
The work to be performed under this PWS, as delineated in DD Form 254, involves the handling of classified material up to and including Top Secret. The Federal Acquisition Regulation (FAR) 52.204-2 – Security Requirements is applicable to this contract. The Contractor shall (1) be responsible for all security aspects of the work performed under this contract, and (2) assure compliance with the NISPOM (DoD 5220.22-M). The Contractor must have a JPAS account and the security clearance of all contractor personnel shall be listed in JPAS.
3.1.7.6 Security Clearance
Depending on the task order requirement, a fully adjudicated Secret or TS clearance with NATO access is required for personnel supporting this PWS. For specific tasking, contractor personnel with a Secret or TS/SCI clearance are required. No interim clearance will be accepted.
3.1.7.7 Base Security
The Contractor shall comply with Marine Corps Base (MCB) Camp Pendleton, CA security regulations and policies. The Contractor’s staff shall be U.S. or naturalized citizens, whose military duty (if applicable) was not terminated by a dishonorable or bad conduct discharge, are not subject to an outstanding criminal warrant, have no felony convictions, and have no more than three criminal misdemeanor convictions within the last seven years. Additionally, the Contractor shall not have any criminal misdemeanor or felony convictions for crimes of a sexual nature, crimes of violence, crimes related to gang activity or hate crimes, or crimes resulting from the possession or distribution of illegal drugs.
Contractor personnel aboard MCB Camp Pendleton, with the exception of emergency personnel, shall wear a properly issued badge at all times. Contractor personnel shall comply with all emergency rules and procedures established for MCB Camp Pendleton. All personnel aboard MCB Camp Pendleton, are subject to random inspections of their vehicles, personal items, and themselves. Consent to these inspections is given when personnel enter MCB Camp Pendleton.
3.1.7.8 Site Security
In addition to base security requirements (section 3.1.7.7), the Contractor shall comply with site security regulations and policies. Contractor personnel shall wear a properly issued MCTSSA badge at all times. The Contractor shall comply with SECNAV M‐5510.30, June 2006, DON Personnel Security Program (Chapter 11 Visitor Access to Classified Information) and Federal Acquisition Regulation (FAR) 52.204‐2 for access to USMC bases and information. All visit requests shall be provided via the JPAS system at least 5 working days prior to scheduled visits.
Individuals shall have two forms of picture identification.
3.1.7.9 Defense Biometric Identification System (DBIDS)
MCB Camp Pendleton uses DBIDS for base access. The Contractor will need to call 760-763- 7604 for information or go to the Las Pulgas gate to enroll. Failure to participate in the program will restrict access to the base and may not be used as a reason for late or nonperformance of services. All Contractors and their personnel are required by MCB Camp Pendleton regulations to meet the requirement for installation access, pass a background check, and have their identity verified to receive unescorted access. No foreign nationals shall be permitted on MCB Camp Pendleton under this contract.
3.1.7.10 Operations Security (OPSEC) Requirements
OPSEC prevents the inadvertent compromise of sensitive unclassified and classified activities, capabilities, or intentions at the tactical, operational, and strategic levels. Contractor personnel must adhere to all government OPSEC measures currently in place at the government facility.
The Contractor shall provide OPSEC training to all contractor personnel supporting this effort.
Contractor personnel shall not take pictures from any device while aboard the compound or in the test areas.
3.1.7.11 MCTSSA Check-Out Procedures
Upon termination of the contract or contractor personnel no longer performing work under this PWS, contractor personnel must first check out with the MCTSSA Communications Security (COMSEC) Custodian and Personnel Security Managers, before turning the government-issued CAC and MCTSSA badge in to the COR.
3.1.8 Safety – Accidents and Mishaps
The Contractor shall comply with all applicable requirements that are established by the Occupational Safety and Health Act (OSHA) and all applicable installation safety orders and procedures. Accidents and mishaps that involve government property, government personnel, or contractor personnel will be reported to the Government within 24‐hours (8‐hours or less for a Class A mishap). MCTSSA is required to submit an OPREP‐3 or UNIT SITREP report and the Contractor is responsible for OSHA notification.
Damage to government property, or injury to Government or Contractor employees must be reported to the COR and Contracting Officer within four hours. The Contractor’s initial reports may be verbal but shall be followed up in writing within 24 hours. Contractor reports of incidents with security implications shall include full details of the incident, any remedial actions taken by the Contractor, and shall comply with all applicable security instructions.
The Contractor shall investigate all accidents occurring on Government property involving Contractor employees and report the findings (on applicable forms) to the COR and Contracting Officer within three calendar days of the incident.
Reportable incidents shall be reported to the Government by the Contractor, per the requirements of this PWS via submission of CDRL B002 – Accident Mishap Report. The data deliverables shall be generated and delivered to the Government for reportable events in accordance with the specific performance requirements and DD Form 1423 that accompanies each individual order for services issued against the MATOC.
• CDRL B002 – DI‐MISC‐82188, Accident Mishap Report
3.1.9 Locations and Hours of Work
Work will be performed primarily at MCTSSA, Camp Pendleton. Contractor personnel shall be expected to work at MCTSSA, Camp Pendleton when not on travel. Standard work hours are 0730-1630, Monday through Friday, excluding federal government holidays. Contractor personnel may be requested to travel in the Continental United States (CONUS), and occasionally Outside the Continental United States (OCONUS), to support this PWS or subsequent task orders.
All planned absences or changes to the schedule require prior approval by the Government. It is the responsibility of contractor personnel to inform the Government if they will not be present, if there is a change to the schedule, or when working from an alternate location.
3.1.9.1 Short‐Notice Support
The Contractor shall support short-notice exercises and events. Short notice is defined as an exercise or event that has not been forecasted on the MCTSSA Training Exercise and Employment Plan (TEEP).
3.1.10 Dress and Conduct
Contractor personnel shall dress in a manner consistent with the task for which hired and the work being performed. In most cases, business casual is appropriate. Clothing must not be excessively revealing, worn out, or ill‐fitting. Contractor personnel shall, at all times, present a professional demeanor while performing on this contract. Behavior which is disruptive, unsafe, disrespectful, offensive, or detrimental to morale shall not be tolerated. The Contractor shall ensure that its personnel do not allow personal business to interfere with job performance, nor use government resources for personal business.
3.1.11 Travel
CONUS and OCONUS travel to other government facilities or other contractor facilities may be required. All travel requirements (including plans, agenda, itinerary, or dates) shall be pre‐ approved by the Government (subject to local policy procedures), and is on a strictly cost reimbursable basis. Contractor personnel shall be authorized reimbursement for travel expenses consistent with the regulatory implementation of Public Law 99‐234, the substantive provisions of the Joint Travel Regulation (JTR) and FAR 31.205‐46 and the limitation of funds specified in this contract. Costs submitted for reimbursement shall be supported by receipts and shall be limited to the lesser of the actual cost incurred or the then current per diem rates established by the General Services Administration (GSA). With the exception of travel requests related to short notice support requirements, as specified in section 3.1.11.1, all contractor personnel travel shall be requested through the COR a minimum of five working days prior to the start date of travel. Contractor personnel will not be reimbursed for travel to the MCTSSA government facilities located at Camp Pendleton, CA.
Foreign travel may be required during performance under this contract. The requirements for contractor personnel travelling overseas are specified in the DoD Foreign Clearance Manual located at https://www.fcg.pentagon.mil/fcg.cfm. All contractor personnel travel to OCONUS locations will be in accordance with the DoD Foreign Clearance Manual to include country, theater, and special area clearance requirements, as applicable. In addition, contractor personnel required to travel to OCONUS locations shall meet all prescribed training requirements set forth in the then current edition of the DoD Foreign Clearance Manual. Contractor personnel are not eligible for no‐fee passports even for DoD‐sponsored travel. Contractor personnel will travel on the same fee passports as tourists. Contractor personnel shall obtain those passports from the Department of State at no cost to the Government.
The Contractor shall provide a trip/travel report to record the purpose of the trip, observations, and any applicable conclusions or recommendations based on the purpose. The report is due 10 working days after the end of the trip, unless a different schedule is agreed to by the Government and the Contractor.
• CDRL B003 – DI‐MISC‐81943, Trip/Travel Report
3.1.12 Privacy Act Information
The Contractor shall comply with requirements of DoD Directive (DoDD) 5400.11 regarding control of Privacy Act information. Specifically, the Contractor shall ensure that any personally identifiable information (PII) (e.g., individual’s name and associated personal contact information or social security numbers) is restricted to access required for execution of this contract and is not disclosed or stored on any unsecure systems. Contractor personnel shall adhere to the Privacy Act, (5 U.S.C. § 552a) and applicable agency rules and regulations.
Contractor personnel shall not divulge or release privacy data or information developed or obtained in the performance of this contract, until made public or specifically authorized by the Government.
3.1.13 Program Management
The Contractor shall designate a primary point of contact (POC) that will be responsible for the accomplishment of all tasks in this PWS. The designated POC shall plan, organize, manage, schedule, implement, control, analyze, and report on all elements of the PWS. The designated POC shall be prepared to present and discuss the status of contract activities, requirements, and issues with the Government. The designated POC shall also be responsible for assessing requirement changes and implementing approved changes, as authorized by the Contracting Officer.
3.1.13.1 Contract Management Plan
The Contractor shall develop and deliver a management plan to support the requirements of this PWS. The management plan describes the contractor’s organization, assignment of functions, duties, responsibilities, management procedures and policies, and reporting requirements for the conduct of contractually-imposed tasks, projects, or programs.
• CDRL B001 – DI‐MISC‐80508B, Management and Technical Plan
3.1.13.2 Monthly Status Report (MSR)
The Contractor shall prepare and deliver an MSR for the activities supported during the month.
The MSR shall be delivered in the version of Microsoft Office used by MCTSSA. Contractor format is acceptable. The MSR shall be sent to the Government via e-mail and shall address all data required in the DID, which shall include, at a minimum, a description of the support provided during the reporting period, a list of completed events, the status of ongoing efforts, log of all off-site calls , and the number of man-hours per event. Additionally, the MSR will include cost data, such as: Incurred cost to each CLIN/SLIN with brief descriptions, current funding levels for each CLIN, and the overall burn rate for the prime Contractor and any subcontractors.
The reporting period will be from the first to last business day of each month, beginning 30 calendar days after contract award.
The MSR shall be provided to the Government on the 6th day of each month for review. The final MSR shall be delivered by the 10th of each month.
• CDRL B004 – DI‐MGMT‐80227, Contractor’s Progress Status and Management Report
– Monthly Status Report
3.1.13.3 Task Order Mobilization/Phase-Out Period
3.1.13.3.1 Mobilization
During the mobilization period, the Contractor shall prepare to assume full responsibility for all areas of operation in accordance with the terms and conditions of the contract. To minimize any decreases in productivity and to prevent possible negative impacts on services, the Contractor shall have the required personnel on board during the mobilization period. The mobilization period will apply to each task order.
Mobilization periods will not exceed 30 days. The specific period of performance dates for mobilization will be included in Section F of each task order award. The Contractor shall assume responsibility for all contract requirements the first day of full contract performance for each task order.
3.1.13.3.2 Phase-Out
The Contractor shall retain full responsibility for meeting contract requirements until completion of the phase-out period, if any, at the end of the task order’s performance period. The Contractor shall provide all support to ensure a smooth transition to a successor performer or the Government, and minimize impact on operational readiness. The Contractor shall not defer any requirements for the purpose of avoiding responsibility or for transferring such responsibility to the successor Contractor or the Government. The Contractor shall provide access to all work sites and to all documentation on a not‐to‐interfere basis during the phase-out period when the follow‐on contractor is mobilizing.
The Contractor shall deliver all phase‐out deliverables to the Government prior to the conclusion of the task order period of performance. Additionally, the Contractor is responsible for maintaining and delivering an inventory of all technical data delivered, furnished, or otherwise provided to the Government under this contract and the means for transferring all technical data to the succeeding Contractor. The actual transfer of technical data from the incumbent Contractor to the follow-on Contractor will be made through the Government. The Contractor shall report phase-out status monthly in the MSR, while keeping a running record of previous actions in the MSR required to be submitted pursuant to section 3.1.16.2.
3.1.13.4 Identification of Contractor Personnel
The Contractor shall provide to the Government the name or names of the responsible supervisory person or persons authorized to act for the Contractor. The Contractor shall remove from the site any individual whose continued employment is deemed by the Contracting Officer to be contrary to the public interest or inconsistent with the best interests of national security.
The Contractor shall provide to the Government, a roster of contractor personnel assigned to the contract and update the list monthly in its MSR submission required to be submitted pursuant to section 3.1.16.2.
3.1.13.5 Post Award Conference (PAC)
The PAC is the first meeting of key Government and Contractor participants. During the conference, participants will discuss the roles and responsibilities and agree on an interpretation of contract requirements for all parties. The PAC includes a review of contract terms, conditions and requirements, line items, and sequence of events needed for successful execution of the contract effort. The Contractor shall attend and participate in a PAC at the MCTSSA facilities located at Camp Pendleton, CA. The PAC shall be scheduled no later than 10 calendar days after contract award. The Contractor shall coordinate with the Government to arrange a schedule and agenda for the PAC prior to the meeting. The Contractor shall prepare and deliver the conference agenda and meeting minutes. A draft deliverable is due by the due date established by the Government. The final deliverable is due 5 working days after receipt of government comments on the initial submission, unless a different schedule is agreed to by the Government
• CDRL B005 – DI‐ADMN‐81249B, Conference Agenda
• CDRL B006 – DI‐ADMN‐81250A, Conference/Meeting Minutes
3.1.13.6 Technical Documentation
The Contractor shall develop and deliver technical documentation (e.g., process documents, templates, test procedures, test plans, test cases, test…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .