Attachment 1-TSS-3_PWS_Final.pdf

PDF 2 MB Posted

Attached to
MCTSSA Tactical Support Systems-3 (TSS-3) Federal contract opportunity
Solicitation number
M6890922R7602
Issued by
United States Marine Corps

About this file

This is a presolicitation notice for the Marine Corps Tactical Systems Support Activity Tactical Support Systems-3 (TSS-3) indefinite delivery indefinite quantity contract. The United States Marine Corps is seeking proposals to provide continuous worldwide technical support for tactical systems to the Fleet Marine Force. Support will include remote and on-site troubleshooting, setup and configuration, knowledge management, software distribution, training, and fielding support for all Marine Corps systems and Department of Defense systems with which the Marine Corps integrates or interoperates. The contract will have a one year base period and four one-year options, and will utilize firm fixed price task orders for various support requirements. The response date for questions is listed as May 2022, with proposals due in June 2022 and award anticipated in August 2022.

View the file

Other files for this federal contract opportunity

Other files attached to MCTSSA Tactical Support Systems-3 (TSS-3), newest first.
File Type Posted
DD 254_Solicitation_TSS3.pdf PDF
Attachment 2_TSS-QASP_Final.pdf PDF
Presolicitation Notice.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

M68909-22-R-7602

Attachment 1 – PWS

Performance Work Statement

For

Marine Corps Tactical Systems Support

October 2021

Prepared by:

Warfighter Support Division

Marine Corps Tactical Systems Support Activity

Camp Pendleton, CA 92055-5171 i

Summary of revisions:

Revision Number Date Remarks ii

TABLE OF CONTENTS

1 SCOPE

2 APPLICABLE DOCUMENTS

3 PERFORMANCE REQUIREMENTS

3.4.3 Exercise/Contingency Operations (CLIN 0003)

iii

4 DELIVERABLES (CLIN 0007)

4.1.1 Monthly Systems Report

4.1.2 Monthly Financial Forecast Report

4.1.3 Weekly Staffing & Census Report

APPENDIX A ACRONYMS

ADDENDUM 1 Historical Example of Contracted Billet Requirements within the last 12 months ........ 1-1

ADDENDUM 2 Historical Example of On-Site Support ......................................................................... 2-1

1 SCOPE

1.1 BACKGROUND

Marine Corps Systems Command (MARCORSYSCOM) has fielded a host of tactical systems (Systems) that have become essential to modern warfighting and the full range of military operations. As many

Systems are fielded without complete, thorough, accessible, or continuous training plans, Marine Corps

Tactical Systems Support Activity (MCTSSA) has provided support to the warfighter to fill the gap in technical expertise and, ultimately, ensure that they remain mission capable. Born from a communications background, MCTSSA primarily focuses its support on fielded command, control, computer, communications, and intelligence (C4I) systems. The effective results of MCTSSA’s support mission have led many MARCORSYSCOM programs of record to reduce reliance on program-specific Field Service

Representatives (FSRs) and support their respective systems and applications through MCTSSA.

In response to these growing requirements, MCTSSA established the Warfighter Support Division (WSD) to serve as the main effort for all systems support to the fleet Marine forces (FMF)—Marine, Joint, coalition, and other US agencies. WSD provides remote (secure and unsecure phone, email, chat) and on-site tactical systems support covering a variety of system issues, including but not limited to: systems troubleshooting and issue resolution, setup and configuration, information and knowledge management, configuration management, software and documentation distribution, maintenance procedures, operations, network analysis and diagnostics, engineering, and over-the-shoulder training, system/equipment fielding support, and “Delta” training. WSD provides these services for Systems and their associated networks for Marines both in garrison and forward deployed. Additionally, WSD serves as the communications portal between the FMF and MARCORSYSCOM Portfolio Managers, Program Executive Offices and Program Managers for Joint systems that the Fleet Marine Force integrates or interoperates with to address system performance and sustainment issues, resulting in engineering, logistics, and training change opportunities.

While most WSD-supported systems require operational and maintenance (O&M) type support via the 24-hour help desk, certain systems require Research, Development, Test, and Evaluation (RDT&E) support within a laboratory or experimental environment. Advanced Technology Development (ATD), Advanced

Component Development and Prototypes, System Development and Demonstration, and RDT&E

Management Support are RDT&E activities to be supported by highly qualified subject matter experts

(SMEs) in the MCTSSA Laboratories.

This Performance Work Statement (PWS provides tailored capabilities at escalating levels—tiers—of support to ensure that Systems in support of the FMF (FMF) are operational and mission capable:

Tier-0: At this level, Systems users can resolve their own issues using a globally accessible website that hosts how-to videos, system documentation, software, common issues, corrective actions, et cetera. Information created/obtained at Tiers 2/3 is applied at this tier.

Tier-1: Non-systems-expert personnel provide real-time remote (secure and unsecure phone, email, chat) tactical systems support, resolving basic system issues and service requests using personal system knowledge and a knowledge repository of known system issues and corrective actions.

Tier-2: Subject matter experts and personnel with significant knowledge of and experience with specified systems, resolve both basic and complex system issues. This may involve both remote and on-site support.

Tier-3: When issues cannot be resolved by WSD personnel, they are elevated to systems experts outside of WSD—typically engineers or developers—for resolution. Incidents at this level are still tracked for resolution by WSD personnel.

1.2 OBJECTIVE

This PWS is for an Indefinite Delivery Indefinite Quantity (IDIQ) contract that defines the non-personal, technical service support efforts required by MCTSSA to meet the FMF tactical systems and applications support requirements. The primary objective of this service is to provide continuous, worldwide tactical systems technical support—positioned at distinct global locations—to the FMF during the full range of military operations in order to ensure that Marines can successfully and independently employ and operate their tactical systems. This includes the establishment of a 24 hours-per-day, seven days-per-week Tier-1 help desk and a cadre of globally distributed, deployable Tier-2 tactical systems experts. Under this PWS, all MARCORSYSCOM systems and Department of Defense (DoD) systems with which the FMF integrates or interoperates are eligible for support.

This support includes but is not limited to, remote and on-site tactical systems and applications troubleshooting and issue resolution, setup and configuration, configuration management, information and knowledge management, software and documentation distribution, maintenance procedures, operations, network analysis and diagnostics, engineering, over-the-shoulder training, system/equipment fielding support, and “Delta” training. This support does not include work on the Marine Corps Enterprise Network

- Non-Classified Internet Protocol Router Network (MCEN-N) and Marine Corps Enterprise Network -

Secret Internet Protocol Router Network (MCEN-S) infrastructure; that work is provided by other agencies and contracts. Support is provided to various units—Marine, Joint, coalition (in accordance with applicable foreign military sales agreements), and other US agencies—that are in garrison; deployed abroad, on ship, or in combat/hazardous duty zones; and are preparing for or conducting the full range of military operations.

Due to the nature of MCTSSA systems support, some developmental, test, and evaluation support within a laboratory or experimental environment may be required and supported by MCTSSA SMEs. These efforts include the following activities.

1. Support the development of subsystems and components and efforts to integrate subsystems and components into system prototypes for field experiments and/or tests in a simulated environment.

2. Perform efforts necessary to support the evaluation of integrated technologies, representative modes or prototype systems in a high fidelity and realistic operating environment are also to be supported in this budget activity.

3. Perform research, development, test and evaluation efforts to develop, sustain, upgrade, and/or modernize systems that have been fielded or have received approval for full rate production and anticipate production funding in the current or subsequent fiscal year.

Another objective of this IDIQ contract is to provide services via a single vendor to allow the WSD to conduct its operations through a centrally managed support center—staffed by an integrated team of

Marines, federal employees, and contractors—hosted at MCTSSA aboard Camp Pendleton, CA and through contractors that are strategically embedded near Marine units worldwide, including but not limited to North Carolina; Okinawa; Bahrain; and Germany. Through this global distribution, the WSD can consistently provide immediate remote support (phone, text, email, chat) and timely on-site support to the

FMF, regardless of their location or current operations: in garrison, forward deployed, or aboard ship while training, exercises, and the full range of military operations.

One WSD long term objective is to serve as a gateway for the Marine Corps to meet the FMFs’ technical needs for any fielded system. WSD works in collaboration with other technical and field service engineering support agencies—such as the Marine Corps Intelligence Activity and Space and Naval Warfare Systems

Center—to resolve all manner of system issues. These efforts ensure seamless, transparent support to the warfighter regardless of system supported or location of the Marine.

2 APPLICABLE DOCUMENTS

The current version of the following documents form a part of this PWS to the extent specified herein.

Moreover, the latest version of the following documents in effect at the time of the issuance of a Task Order

(TO) PWS will supersede the prior version of the document cited in this PWS. In addition, the Contractor shall also comply with all applicable local and base policies. Unless otherwise noted, in the event of a conflict between the PWS and the references cited herein, the text of the TO PWS takes precedence.

2.1 DEPARTMENT OF DEFENSE INSTRUCTIONS, DIRECTIVES, STANDARDS AND

GUIDES

DoDI 3020.41 Change 2, 31 August 2018, Operational Contract Support, DoDD 4715.E Environmental, Safety, and Occupational Health (ESOH)

DoDM 5200.1 Volume 1 – DoD Information Security Program: Overview, Classification, and Declassification

DoDM 5200.1 Volume 2 – DoD Information Security Program: Marking of Classified

Information

DoDM 5200.1 Volume 3 – DoD Information Security Program: Protection of Classified

Information

DoDI 5200.48 Controlled Unclassified Information

DoD Directive 5205.02E – DoD Operations Security (OPSEC) Program

DoDI 5220.22 – National Industrial Security Program (NISP)

DoD 5220.22-M – National Industrial Security Program Operating Manual

DoDI 5230.09 – Clearance of DoD Information for Public Release

DoDI 5230.24 – Distribution Statements on Technical Documents

DoDD 5230.25 – Withholding of Unclassified Technical Data from Public Disclosure

DoDI 5400.11 – DoD Privacy and Civil Liberties Programs

DOD 5500.07-R – Joint Ethics Regulation

DoDI 6055.01 – DoD Safety and Occupational Health (SOH) Program

DoDD 8140.01– Cyberspace Workforce Management

DoDI 8500.01 – Cybersecurity

DoDI 8510.01 – Risk Management Framework (RMF) for DoD Information Technology (IT)

DoD 8570.01-M – Information Assurance Workforce Improvement Program

DoDD 4500.54E DoD Foreign Clearance Program

2.2 DEPARTMENT OF THE NAVY INSTRUCTIONS, DIRECTIVES, STANDARDS AND

GUIDES

SECNAVINST 3070.2 – Operations Security

SECNAV M-5239.1 – Department of the Navy Information Assurance Manual

SECNAVINST 5510.30C – Department of the Navy Personnel Security Program

SECNAVINST 5510.36B – Department of the Navy Information Security Program

2.3 MARINE CORPS ORDERS, MANUALS, DIRECTIVES AND GUIDES

MCO 3070.2A – The Marine Corps Operations Security Program

MCO 5100.29 B – Marine Corps Safety Program

MCO 5200.17E – Standardization of Military and Associated Terminology

MCO 5216.20B – Marine Corps Supplement to the Department of the Navy Correspondence

Manual

MCO 5239.2B – Marine Corps Cybersecurity

MCO 5510.18B – United States Marine Corps Information and Personnel Security Program

(IPSP)

MCO 5510.20B – Disclosure of Military Information to Foreign Governments and Interests

MCO 5530.14A – Marine Corps Physical Security Program Manual

MCINCR-MCBQO 5530.2 – Access Control Policy

MSTP Security Standard Operating Procedures (SECSOP)

MCTSSA Activity Order P5510.3A – Standard Operating Procedure (SOP) for MCTSSA

Security Operation, 14 November 2014.

NAVMC DIR 5100.8, Marine Corps Occupational Safety and Health (OSH) Program

Manual

2.4 AVAILABILITY OF DOD DOCUMENTS

DoD Directives, Manuals, Instructions and Publications are available online at http://www.DTIC.mil/ or from the National Technical Information Services (NTIS), 5285

Port Royal Road, Springfield, VA 22161

DoN Directives, Manuals, Instructions and Publications are available online at http://www.dtic.mil/ https://doni.documentservices.dla.mil/default.aspx

USMC Orders, Manuals, Directives, and Guides are available online at http://www.marines.mil/News/Publications/ELECTRONIC-LIBRARY/

Electronic Foreign Clearance Guide available online at https://www.fcg.pentagon.mil/fcg.cfm

2.5 OTHER DOCUMENTS, DRAWINGS AND PUBLICATIONS

CNSS Instruction No. 4009 National Information Assurance (IA) Glossary

Information Technology Infrastructure Library (ITIL) 2011 Series

OSHA regulation 1910.142 Occupational Safety and Health Standards

Parts 120-130 of Title 22, Code of Federal Regulations (also known as the “International

Traffic in Arms Regulations”)

Parts 730-774 of Title 15, Code of Federal Regulations (also known as the “Export

Administration Regulations”)

United States Forces Korea Regulation 700-19, Appendix B

U.S. Forces Japan Instruction 31-207 – Firearms and Other Weapons in Japan

U.S. Forces Japan Instruction 36-2611 – Change of Status by Persons in Japan to One of the

Categories Authorized by the Status of Forces Agreement

U.S. Forces Japan Instruction 64-100 – Contract Performance in Japan

U.S. Forces Japan Instruction 64-102 – United States Contractors and their Employees

NATO Status of Force Agreement (SOFA) and Germany Supplementary Agreement to SOFA

US Bahrain SOFA

Treaties in Force: A List of Treaties and Other International Agreements of the United States in

Force

3 PERFORMANCE REQUIREMENTS

GENERAL REQUIREMENTS

NON-PERSONAL SERVICES

The Government will neither supervise Contractor personnel nor control the method by which the

Contractor performs the required tasks. The Government will not assign tasks, nor prepare work schedules for individual Contractor personnel. The Contractor shall manage its personnel and guard against any actions that give the perception of personal services. To provide a clear distinction between

Government employees and Contractor personnel, Contractor personnel shall identify themselves as such by introducing themselves or being introduced as Contractor personnel and, to the extent a badge does not create a safety issue, displaying distinguishing badges or other visible identification for meetings with Government employees, as well as appropriately identifying themselves as Contractor personnel in telephone conversations and in formal and informal written correspondence. Contractor personnel shall present their badges upon request by Government employees and their representatives.

If the Contractor believes that any actions constitute or are perceived to constitute personal services, it http://www.marines.mil/News/Publications/ELECTRONIC-LIBRARY/ http://www.marines.mil/News/Publications/ELECTRONIC-LIBRARY/ https://www.fcg.pentagon.mil/fcg.cfm shall be the Contractor's responsibility to notify the Contracting Officer (KO) and the Contracting

Officer’s Representative (COR) immediately.

BUSINESS RELATIONS

The Contractor shall successfully integrate and coordinate all activities needed to execute the requirements contained herein and in any TO. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The

Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all

Contractor personnel.

3.1.2.1 CONSTRUCTIVE CHANGES

No modification, statement, or conduct of Government personnel who might visit the Contractor’s facility or in any other manner communicate with Contractor personnel during the performance of this contract will constitute a change under the “Changes” clause of this contract. No understanding or agreement, contract modification, change order, or other matter deviating from or constituting an alteration or change of the terms of the contract will be effective or binding upon the Government unless formalized by contractual documents executed by the KO.

The KO is the only person authorized to approve changes in the requirements of this contract, and notwithstanding provisions contained elsewhere in the contract, the said authority remains solely with the

KO. In the event that the Contractor effects any change(s) at the direction of any person other than the

KO, these change(s) will be at the Contractor’s expense. No adjustment will be made in the contract price or other contract terms and conditions, as the KO did not approve consideration for the unauthorized change. Further, should the unauthorized change be to the Government’s detriment, the Contractor may be held financially responsible for its correction.

3.1.2.2 RESPONSIBILITY IN SUBCONTRACTING

The Contractor shall provide the technology processes, test procedures, data, drawings, and other information required to facilitate competition to the fullest extent feasible and ensure performance by selected subcontractors. The Contractor shall be fully responsible for ensuring that all appropriate contractual provisions and clauses are flowed down to its subcontractors and that those provisions are enforced.

3.1.2.3 TASK ORDERS

Except as otherwise provided in a specific TO, the Contractor shall furnish all materials and services necessary to accomplish the work specified therein. These materials shall include consumable items, device repair parts/components, tools, and test equipment, and support equipment not otherwise provided by the Government to the Contractor. The provisions of this agreement apply to all TOs issued under the contract.

Each TO will be individually funded. The appropriation and accounting data required to obligate funds will be included in each TO. As provided in each TO, Contractors may be required to track and invoice multiple lines of accounting (LOA) on each Contract Line Item Number (CLIN). As a result, Contractors must be able to accurately track performance and report based on the applicable LOA.

3.1.2.4 COR AND ACOR

The use of the term COR throughout this document also includes the term Alternate COR (ACOR), if an ACOR is appointed in writing by the KO, unless specifically excluded. An ACOR, if appointed, can only act in the absence of the appointed COR. There can only be one COR for a contract, and the duties of the COR are not delegable.

3.1.2.5 QUALITY ASSURANCE SURVEILLANCE PLAN

The Government conducts surveillance of the Contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). All deliverables will be inspected for content, completeness, accuracy, and conformance to contract requirements by the Government. This will include inspecting for nonconforming or unjustified markings of data delivered to the Government for acceptance as specified in the contract.

CONTRACTOR PERSONNEL, DISCIPLINES, AND SPECIALTIES

The Contractor shall satisfy the requirements of this PWS and subsequent TOs by employing and utilizing personnel with an appropriate combination of education, knowledge, skills, abilities, and experience (if applicable). The Contractor shall match the appropriate labor categories and the labor hours required to meet all the work required to be performed under the TO. It is the contractor’s responsibility to provide personnel with all required training, licenses, certification, and qualifications as specified in this PWS and/or subsequent TOs to perform the requirement against which the employee is matched. The costs to obtain, maintain, pay for and otherwise support the required training, licenses, certification, and qualifications is the responsibility of the Contractor. The selection, assignment, reassignment, transfer, supervision, management, and control of Contractor personnel shall be the responsibility of the

Contractor. The Contractor shall not seek hiring approval from the Government, unless required by law or regulation.

The labor categories, qualifications, and experience requirements proposed by the Contractor will be incorporated into the resulting contract and become the minimum qualifications for the life of the contract. Contractors will replace its employees when necessary with an employees with equal or greater qualifications as was proposed and incorporated.

When providing on-site support at locations other than their home base, contractor personnel shall wear clothing that indicates their affiliation with the Warfighter Support Division and/or the MCTSSA Tactical

Systems Support (TSS) contract and/or the USMC Technical Support to the Operating Forces program more prominently than any other affiliation/information. An exception shall be made when deploying in support of contingency operations—in which case the contractor personnel shall adhere to the civilian clothing policy of the unit to which they’re attached.

The Contractor is required to comply with Public Law 105-270, Section 5(2)(A). This law states that contractors will not perform inherently governmental functions. If Contractor employees are requested to perform in a manner that appears to require the performance of personal services, the employee must report such to the Contractor who must in writing, immediately inform the Contracting Officer. Section

5(2)(A) of this Public Law defines the term “inherently Governmental function” as “a function that is so intimately related to the public interest as to require performance by Federal Government employees.” Per

Section 5(2)(B), inherently Governmental functions include management of Government programs requiring value judgements, conduct of foreign relations, selection of program priorities, and the direction of intelligence and counterintelligence operations. Per Section 5(2)(C), inherent Governmental functions

DO NOT include, (i) gathering information for or providing advice, opinions, recommendations, or ideas to Federal Government officials or (ii) any function that is primarily ministerial and internal in nature.

Due to the nature of the requirement to provide information and instructions to Marines that could potentially be in harm’s way, all Contractor personnel shall have the ability to communicate clearly in

English in both verbal and written form.

RESOURCE REQUIREMENTS

The Contractor shall provide personnel with all required training, education, certification and all equipment, tools, materials, supervision, and quality control necessary to perform the TSS-

3requirements defined in this PWS and subsequent TOs.

MARINE CORPS ENTERPRISE NETWORK (MCEN)

The Contractor shall procure all IT assets that connect to the Marine Corps Enterprise Network

(MCEN) and are approved for procurement by the Contracting Officer’s Representative (COR), via the applicable Contract Other Direct Cost (ODC) Contract Line Item Number (CLIN), that are required to accomplish the tasks delineated in the performance work statement. The Contractor shall ensure that all required computer assets are maintained, serviceable, and functional throughout the period of performance of the contract. For any computers that will be connected to the MCEN, the Contractor shall procure only those makes and models listed on the Marine Corps Enterprise Desktop

Standardization (MCEDS) Supported Models list. The Contractor shall deliver to the COR all computers requiring connectivity to the MCEN. The COR will facilitate reimaging of these computers for authorization to connect to the MCEN. Upon completion of reimaging, the COR will notify the

Contractor that the computer(s) are available for pickup and are now authorized for connection to the

MCEN. The completion time for MCEN imaging is anticipated to take approximately no more than five business days from delivery of computer(s) to notification of pickup. Upon end of the contract term, whether via the end of any period of performance, termination, or otherwise, the Contractor shall return the assets purchased under the contract to the Government for disposition unless otherwise directed by the COR as provided under FAR 52.245-1(j).

Contractor personnel accessing Marine Corps Systems Command Computer systems, must maintain compliance with United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access

Guide. Contractor personnel will submit a DD 2875, and completion certificates for the CYBERC course located on MarineNet located at https://www.marinenet.usmc.mil The CYBERC course consist of the DOD Cyber Awareness Challenge and Department of the Navy Annual Privacy Training (PII).

Contractors will have to create a MarineNet account in order to acquire the required training.

MCEN IT resources if provided are designated For Official Use Only (FOUO) and other limited authorized purposes. DoD military, civilian personnel, consultants, and contractor personnel performing duties on MCEN information systems may be assigned to one of three position sensitivity designations.

1) ADP-I (IT-1): Favorably adjudicated T-5, T5R, Single Scope Background

Investigation (SSBI)/SSBI Periodic Reinvestigation (SBPR)/SSBI Phased Periodic

Reinvestigation (PPR)

2) ADP-II (IT-2): Favorably adjudicated T-3, T3R, Access National Agency Check and

Inquiries (ANACI)/ National Agency Check with Law and Credit (NACLC)/Secret Periodic http://www.marinenet.usmc.mil/ http://www.marinenet.usmc.mil/

Review (S-PR)

3) ADP-III (IT-3): Completed T-1, National Agency Check with Inquiries (NACI)

All privileged users (IT-1) must undergo an SSBI regardless of the security clearance level required for the position. Privileged users must maintain the baseline Cyberspace Workforce Information Assurance

Technical (IAT) or Information Assurance Manager (IAM) relating to the position being filled.

Privileged users are defined as anyone who has privileges over a standard user account as in system administrators, developers, network administrators, code signing specialist and Service Desk technicians.

All MCEN users must read, understand, and comply with policy and guidance to protect classified information and CUI, and to prevent unauthorized disclosures in accordance with United States

Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide and CJCSI 6510.01F.

MCEN Official E-mail usage – MCEN IT resources are provided For Official Use Only (FOUO) and other limited authorized purposes. Authorized purposes may include personal use within limitations as defined by the supervisor or the local Command. Auto forwarding of e- mail from

MCEN-N to commercial or private domains (e.g., Hotmail, Yahoo, Gmail, etc.) is strictly prohibited.

E-mail messages requiring either message integrity or non-repudiation are digitally signed using DoD

PKI. All e-mail containing an attachment or embedded active content must be digitally signed.

MCEN users will follow specific guidelines to safeguard Controlled Unclassified Information (CUI), including PII and For Official Use Only (FOUO). Non-official e-mail is not authorized for and will not be used to transmit CUI to include PII and Health Insurance Portability and Accountability Act

(HIPAA) information. Non-official e-mail is not authorized for official use unless under specific situations where it is the only mean for communication available to meet operational requirements.

This can occur when the official MCEN provided e-mail is not available but must be approved prior to use by the Marine Corps Authorizing Official (AO).

All personnel will use DoD authorized PKI certificates to encrypt e-mail messages if they contain any of the following:

1. Information that is categorized as For Official Use Only (FOUO).

2. Any contract sensitive information that normally would not be disclosed to anyone other than the intended recipient.

3. Any privacy data, PII, or information that is intended for inclusion in an employee’s personal file or any information that would fall under the tenets of MSGID: DOC/5

USC 552A. Personal or commercial e-mail accounts are not authorized to transmit unencrypted CUI or PII.

4. Any medical or health data, to include medical status or diagnosis concerning another individual.

5. Any operational data regarding status, readiness, location, or deployment of forces or equipment.

Contractor assets connectivity to the MCEN – The contracting company will comply with

MCENMSG-Unification 003-14 ENABLING CONTRACTOR ASSET CONNECTIVITY TO

THE MCEN. The Contractor representative will transfer the contractor owned laptops to the MCSC

G-6, Information Technology Asset Management (ITAM) department to have the MCEN images places on each laptop before it is authorized to connect to the MCEN.

All Contractor owned laps must meet or exceed the USMC laptop specifications. A list of laptops authorized to be attached to the MCEN can be obtained from MCTSSA S-6 upon request.

Upon completion of the contact or at such time as the contractor reclaims the asset from the USMC, non-Government owned internal\external hard drives shall become the property of the U.S. Government.

Once the hard drives have been removed, the laptops\assets will be returned to the Contractor. For additional questions regarding current system specifications contact the MCTSSA, ITSM lead at (760)

725-8473.

Magnetic Hard Drive Storage Devices – This paragraph covers the requirements of classified and unclassified internal and removable magnetic and Solid State hard drives that store the Government data. This includes, but is not limited to, storage area network (SAN) devices, servers, workstations, laptops/notebooks, printers, copiers, scanners and multi-functional devices (MFD) with internal hard drives, removable hard drives and external hard drives. Upon disposal, replacement, turn in of hard drives or completion of the contract, non-Government owned internal\external hard drives shall become the property of the U.S. Government in accordance with GENADMIN Processing of Magnetic Hard

Drive Storage Media for Disposal.

SECURITY REQUIREMENTS

3.1.5.1 SECURITY REQUIREMENTS

TOs will require the Contractor to have a Facility Clearance and will require certain Contractors to obtain and maintain classified access eligibility. If a Facility Clearance is a requirement of any TO, the

Contractor shall not begin performance of any classified work without having a valid Facility

Clearance. The prime contractor and all subcontractors (through the prime contractor) shall adhere to all aspects of DoD Directive 5220.22-M and DoD Manual 5220.22 Volume 2. All personnel identified to perform on this contract shall maintain compliance with Department of Defense, Department of the

Navy, and Marine Corps Information and Personnel Security Policy to include completed background investigations (as required) prior to classified performance. This contract shall include a DoD Contract

Security Classification Specification (DD-254) as an attachment. Certain contractors will be required to perform IT-I/II duties that will require favorably adjudicated Tier 5/3 Level investigations. The

Defense Counterintelligence Security Agency (DCSA) will not authorize contractors to submit the necessary Tier Level investigations solely in support of IT level designation requirements, but are required to submit investigations for those employees requiring both appropriate access and IT-II designation. The Government Contracting Activity Security Office (GCASO) is required to submit any required investigations in support of IT-I level designations.

The Contractor is required to provide a roster of prospective contractor employees performing IT-I duties to the MCSC COR. This roster shall include: full names, Social Security Numbers, e-mail address and phone number for each contractor requiring investigations in support of IT Level designations. The COR will verify the IT-I requirements and forward the roster to the GCASO.

Contractors found to be lacking required investigations will be contacted by the GCASO.

Facility Security Officers (FSOs) are responsible for notifying the MCSC AC/S G-2 Personnel Security

Office (PERSEC Office) via encrypted e-mail to MCSC_Security@usmc.mil or 703-432- 3374/3952 if any contractor employee performing on this contract receives an unfavorable adjudication. The FSO must also notify the PERSEC Office, within 24 hours, of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor performing on this contract, if they have mailto:MCSC_Security@usmc.mil been granted an IT designation, issued a CAC, a MCSC Building Badge and/or granted classified access. The FSO shall notify the Government (written notice) within 24 hours of any Contractor personnel added or removed from the contract that have been granted IT designations, issued a Common

Access Card (CAC) and/or a MCSC Building badge/access.

3.1.5.1.1 TOP SECRET SECURITY REQUIREMENTS

The Contractor shall be responsible for all security aspects of the work performed under this contract and assure compliance with the NISPOM.

The work to be performed under this PWS, as delineated in the DD Form 254, can involve access to the handling of classified material up to Top Secret with a favorable adjudicated Single Scope Background

Investigation (TS/SSBI) or Tier 5 (T5/T5R) investigation level. At a minimum, a Secret clearance is required for all Contractor personnel supporting this PWS, and a security clearance up to the TS/SSBI level may be required for an estimated nine personnel. No interim/temporary access will be accepted. The

Contractor shall possess a Defense Information Security System (DISS) account, and Contractor personnel clearances shall be verifiable in JPAS.

The Contractor shall comply with site location security regulations and policies. Contractor personnel shall be U.S. or naturalized citizens, who:

have not terminated military service through a dishonorable or bad conduct discharge;

are not debarred from handling export controlled materials;

are not subject to an outstanding criminal warrant;

have no felony convictions;

and have no more than three criminal misdemeanor convictions within the last seven years.

Additionally, Contractor personnel shall have no criminal misdemeanor or felony conviction for crimes of a sexual nature, crimes of violence, crimes related to gang activity or hate crimes, or crimes resulting from the possession or distribution of any illegal drug.

All Contractor personnel aboard military installations, with the exception of emergency personnel, shall wear a properly issued badge at all times. Contractor personnel shall comply with all emergency rules and procedures established for each worksite. All personnel aboard Government installations are subject to random inspections of their vehicles, personal items, and of themselves. Consent to these inspections is given when personnel enter Government installations.

This contract will require the contractor to have a Top Secret Facility Clearance and will require certain contractors to obtain and maintain classified access eligibility. The contractor shall have a valid Top

Secret Facility Clearance prior to classified performance. The prime contractor and all sub-contractors

(through the prime contractor) shall adhere to all aspects of DoD Directive 5220.22-M and DoD Manual

5220.22 Volume 2. All personnel identified to perform on this contract shall maintain compliance with

Department of Defense, Department of the Navy, and Marine Corps Information and Personnel Security

Policy to include completed background investigations (as required) prior to classified performance.

This contract shall include a DoD Contract Security Classification Specification (DD-254) as an attachment. The contractor shall notify the Government (written notice) within twenty-four hours of any contractor personnel added or removed from the contract that have been granted classified access, issued a Common Access Card (CAC) and/or MCSC Building badge/access.

3.1.5.2 COMMON ACCESS CARD (CAC) REQUIREMENT

The TO COR will identify and approve those Contractor employees performing on a TO that require

CACs in order to perform their job function.

The COR will identify and only approve those contractor employees performing on this contract that require CACs in order to perform their job function. In accordance with Headquarters, United States

Marine Corps issued guidance relative to Homeland Security Presidential Directive – 12 (HSPD-12), all personnel must meet eligibility criteria to be issued a CAC. In order to meet the eligibility criteria, contractor employees requiring a CAC must obtain and maintain a favorably adjudicated Personnel

Security Investigation (PSI). Prior to authorizing a CAC, the employee’s Joint Personnel Adjudication

System (JPAS) record must indicate a completed and favorably adjudicated PSI or (at a minimum) that a

PSI has been submitted and accepted (opened). The minimum acceptable investigation is a T-1 or a

National Agency Check with Written Inquiries (NACI). If a contractor employee’s open investigation closes and is not favorably adjudicated, the CAC must be immediately retrieved and revoked. CACs are not issued for convenience.

Facility Security Officers (FSOs) are responsible for notifying the MCSC AC/S G-2 Personnel Security

Office (PERSEC Office) at 703-432-3490/3952 if any contractor performing on this contract receives an unfavorable adjudication after being issued a CAC. The FSO must also immediately notify the

PERSEC Office of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor issued a CAC, regardless of whether a JPAS Incident Report is submitted.

Each CAC is issued with a “ctr@usmc.mil” e-mail account that the individual contractor is responsible to keep active by logging in on a regular basis (at least twice a month), sending an e- mail and clearing any unneeded e-mails. Contractors issued a CAC are prohibited from “auto- forwarding” e-mail from their .mil e-mail account to their .com e-mail account. If the “ctr@usmc.mil” e-mail account is not kept active, G-6 will deactivate the account and the CAC will also lose its functionality. Contractor employees shall solely use their government furnished “ctr@usmc.mil” e-mail accounts for work supporting the USMC, conducted in fulfillment of this contract, and shall not use a contractor supplied or personal e-mail account to conduct FOUO government business. The use of a contractor or personal e-mail account for contractor business or personal use is allowed, but only when using cellular or a commercial internet service provider.

If a contractor loses their eligibility for a CAC due to an adverse adjudicative decision, they have also lost their eligibility to perform on MCSC contracts.

3.1.5.3 PHYSICAL SECURITY

At the close of each work period, Government facilities, equipment, and materials shall be secured.

KEY CONTROL

The Contractor shall establish and implement methods of making sure all keys/key cards issued to the

Contractor by the Government are not lost or misplaced and are not used by unauthorized persons.

NOTE: All references to keys include electronic key/access cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering Key Control that shall be included in the Quality Control Plan (QCP). Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall mailto:ctr@usmc.mil mailto:ctr@usmc.mil mailto:ctr@usmc.mil immediately report any occurrences of lost or duplicate keys/key cards to the local Government contracting surveillance individuals within 12 hours and the KO within twenty-four hours.

In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the TO KO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re- keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.

The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the

Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the by the COR, KO, or designated

Government representative.

LOCK COMBINATIONS

The Contractor shall provide all lock combinations to the COR, and establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Quality Control Plan

(QCP).

PASSWORDS

Passwords shall be protected at all times. The sharing of passwords is strictly prohibited.

3.1.5.7 SYSTEM SECURITY

1. System Security Plan and Plans of Action and Milestones (SSP/POAM) Reviews

a. Within 30 days of TO award, the Contractor shall make its System Security Plan(s) (SSP(s)) for its covered contractor information system(s) available for review by the Government at the contractor’s facility. The SSP(s) shall implement the security requirements in Defense Federal Acquisition

Regulation Supplement (DFARS) clause 252.204-7012, which is included in this contract. The

Contractor shall fully cooperate in the Government's review of the SSPs at the Contractor's facility.

b. lf the Government determines that the SSP(s) does not adequately implement the requirements of

DFARS clause 252.204-7012 then the Government shall notify the Contractor of each identified deficiency. The Contractor shall correct any identified deficiencies within 30 days of notification by the

Government. The KO may provide for a correction period longer than 30 days and, in such a case, may require the Contractor to submit a plan of action and milestones (POAM) for the correction of the identified deficiencies. The Contractor shall immediately notify the KO of any failure or anticipated failure to meet a milestone in such a POAM.

c. Upon the conclusion of the correction period, the Government may conduct a follow-on review of the

SSP(s) at the Contractor's facilities. The Government may continue to conduct follow-on reviews until the Government determines that the Contractor has corrected all identified deficiencies in the SSP(s).

d. The Government may, in its sole discretion, conduct subsequent reviews at the Contractor's site to verify the information in the SSP(s). The Government will conduct such reviews at least every three

(3) years (measured from the date of contract award) and may conduct such reviews at any time upon thirty days' notice to the Contractor.

2. Compliance to NIST 800-171

a. The Contractor shall fully implement the CUI Security Requirements (Requirements) and associated

Relevant Security Controls (Controls) in NIST Special Publication 800-171 (Rev. I) (NIST SP 800-

171), or establish a SSP(s) and POAMs that varies from NIST 800-171 only in accordance with

DFARS clause 252.204-7012(b)(2), for all covered contractor information systems affecting this contract.

b. Notwithstanding the allowance for such variation, the contractor shall identify in any SSP and

POAM their plans to implement the following, at a minimum:

(1) Implement Control 3.5.3 (Multi-factor authentication). This means that multi-factor authentication is required for all users, privileged and unprivileged accounts that log into a network. In other words, any system that is not standalone should be required to utilize acceptable multi-factor authentication. For legacy systems and systems that cannot support this requirement, such as CNC equipment, etc., a combination of physical and logical protections acceptable to the Government may be substituted;

(2) Implement Control 3.1.5 (least privilege) and associated Controls, and identify practices that the contractor implements to restrict the unnecessary sharing with, or flow of, covered defense information to its subcontractors, suppliers, or vendors based on need-to-know principles;

(3) Implement Control 3.1.12 (monitoring and control remote access sessions) - Require monitoring and controlling of remote access sessions and include mechanisms to audit the sessions and methods.

(4) Audit user privileges on at least an annual basis;

(5) Implement:

i. Control 3.13.11 (FIPS 140-2 validated cryptology or implementation of NSA or NIST approved algorithms (i.e. FIPS 140-2 Annex A: AES or Triple DES) or compensating controls as documented in a SSP and POAM); and,

ii. NIST Cryptographic Algorithm Validation Program (CAVP)

(see https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program);

(6) Implement Control 3.13.16 (Protect the confidentiality of CUI at rest) or provide a

POAM for implementation which shall be evaluated by the Navy for risk acceptance.

(7) Implement Control 3.1.19 (encrypt CUI on mobile devices) or provide a plan of action for implementation which can be evaluated by the Government Program Manager for risk to the program.

3. Cyber Incident Response:

a. The Contractor shall, within 15 days of discovering the cyber incident (inclusive of the 72-hour reporting period covered in 3.1.5.9 below), deliver all data used in performance of the contract that the

Contractor determines is impacted by the incident and begin assessment of potential warfighter/program impact.

b. Incident data shall be delivered in accordance with the Department of Defense Cyber Crimes

Center (DC3) Instructions for Submitting Media available at http:/www.acq.osd.mil/dpap/dars/pgi/docs/Instructions_for_Submitting_Media.docx. In delivery of the incident data, the Contractor shall, to the extent practical, remove contractor-owned information from Government covered defense information.

http://www.acq.osd.mil/dpap/dars/pgi/docs/Instructions

c. If the Contractor subsequently identifies any such data not previously delivered to DC3, then the

Contractor shall immediately notify the KO in writing and shall deliver the incident data within 10 days of identification. In such a case, the Contractor may request a delivery date later than 10 days after identification. The KO will approve or disapprove the request after coordination with DC3.

4. Naval Criminal Investigative Service (NCIS) Outreach

The Contractor shall engage with NCIS industry outreach efforts and consider recommendations for hardening of covered contractor information systems affecting DON programs and technologies.

5. NCIS/Industry Monitoring

a. In the event of a cyber incident or at any time the Government has indication of a vulnerability or potential vulnerability, the Contractor shall cooperate with the Naval Criminal Investigative Service

(NCIS), which may include cooperation related to: threat indicators; pre-determined incident information derived from the Contractor's infrastructure systems; and the continuous provision of all

Contractor, subcontractor or vendor logs that show network activity, including any additional logs the

Contractor, subcontractor or vendor agrees to initiate as a result of the cyber incident or notice of actual or potential vulnerability.

b. If the Government determines that the collection of all logs does not adequately protect its interests, the Contractor and NCIS will work together to implement additional measures, which may include allowing the installation of an appropriate network device that is owned and maintained by NCIS, on the

Contractor1s information systems or information technology assets. The specific details (e.g., type of device, type of data gathered, monitoring period) regarding the installation of an NCIS network device shall be the subject of a separate agreement negotiated between NCIS and the Contractor. In the alternative, the Contractor may install network sensor capabilities or a network monitoring service, either of which must be reviewed for acceptability by NCIS. Use of this alternative approach shall also be the subject of a separate agreement negotiated between NCIS and the Contractor.

c. In all cases, the collection or provision of data and any activities associated with this performance work statement shall be in accordance with federal, state, and non-US law.

3.1.5.8 ADDITIONAL SYSTEM SECURITY REQUIREMENTS

To provide adequate security, the Contractor shall implement National Institute of Standards and

Technology (NIST) Special Publication 800-171, Protecting Controlled Unclassified Information in

Nonfederal Systems and Organizations, the Contractor shall provide a System Security Plan (SSP) in accordance with Contractor’s SSP (CDRL A001) indicating whether the Contractor has implemented the security requirements therein, plans to implement the security requirements, or that the requirement is not applicable.

The Contractor shall submit a list in accordance with the Contractor’s Record of Tier 1 Level Suppliers

Receiving/Developing CUI (CDRL A002) of all supporting Tier 1 Level suppliers receiving or developing covered defense information. In addition, the Contractor shall provide its plan to government review and approval to track flow down of covered defense information and to assess

DFARS Clause 252.204-7012 compliance of known Tier 1 Level suppliers.

The Contractor shall document and report all cyber incidents that affect the covered Contractor information system or the covered defense information residing therein, or that affect the Contractor’s ability to perform requirements designated as operationally critical support via the Cyber Incident

Reporting (CDRL A003). The Contractor shall submit malicious software discovered and isolated in connection with a reported cyber incident to the DoD Cyber Crime Center.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .