Threat_Engineering_Support_-_SOW_20181103.docx

DOCX document 22 KB Posted

Attached to
THREAT ENGINEERING SUPPORT Federal contract opportunity
Solicitation number
N0017819Q0009
Issued by
Department of the Navy Naval Sea Systems Command

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

THREAT ENGINEERING SUPPORT

STATEMENT OF WORK (SOW)

1.0 BACKGROUND

The purpose of this contract is to provide threat research, development, engineering, and analyses support to the Naval Surface Warfare Center, Dahlgren Division (NSWCDD), Warfare Systems Engineering and Integration Department (V).

2.0APPLICABLE DOCUMENTS
2.1Acquisition Threat Engineering Products (ATEP) Models and Simulations; and
2.2War Room Template.
3.0REQUIREMENTS
3.1The contractor shall provide Threat Engineering Analytical Support in order to produce a threat technology roadmap and enable a forum to communicate the results to the leadership at NSWCDD, V Department.
3.2The contractor shall produce and provide flight engagement performance results from three (3) ATEPs in representative operational environments and two ATEPs while under development (CDRL A001).
3.3The contractor shall produce and provide five (5) SIMDIS visualizations to demonstrate threat behavior and performance as obtained in the flight engagement performance results (CDRL A002).
4.0DELIVERABLES
4.1The contractor shall provide ATEP Performance Results IAW CDRL A001.
4.2The contractor shall provide SIMDIS Visualizations from ATEP Performance Runs IAW CDRL A002.
5.0GOVERNMENT-FURNISHED PROPERTY/MATERIAL/INFORMATION (GFP/GFM/GFI)

The Government will provide ATEP models and simulations and the War Room Template to the contractor immediately upon award of the order.

6.0 TRAVEL

The contractor will be required to travel in performance of this contract. The number of trips and types of personnel traveling shall be limited to the minimum required to accomplish work requirements and shall be coordinated with the technical point of contact. All travel shall be conducted in accordance with the Federal Travel Regulations (FTR). The following travel is anticipated: The Government anticipates the contractor will conduct local travel to the NSWCDD located in Dahlgren, Virginia, six (6) times and with two (2) personnel during the period of performance.

7.0 SECURITY

All work under this SOW will be accomplished at the SECRET level. The Department of Defense Contract Security Classification Specification (DD Form 254) (Attachment J.1) provides the security classification requirements for this order. The contractor shall obtain facility and personnel security clearances at the Secret level required by the Department Industrial Security Program prior to starting to work on tasks requiring clearances. Access to classified spaces and material and generation of classified material shall be in accordance with the attached DD Form 254.

Execution of this effort under the SOW requires the Contractor to have access to classified information, systems, system data/products, and detailed analysis of systems up to SECRET. While working on classified tasks, the Contractor shall safeguard all classified materials in accordance with applicable Government and industrial security regulations. The Contractor may be required to use the Defense Courier Service (DCS) and the Defense Technical Information Center (DTIC). The Contractor is responsible for taking Information Security Awareness training annually, via their Facility Security Officer (FSO), as part of the mandatory training requirements.

All personnel performing on-site must maintain the appropriate level security clearance. A security clearance is required in order to access Government computer systems. Access to and the preparation of classified material may be required in the execution of tasking associated with this contract.

In order to successfully execute the tasking identified in this statement of work, the contractor may require access to Restricted Data, Formerly Restricted Data, Foreign Government Information, and Controlled Unclassified Information (CUI). Additionally, the contractor may be required to receive, store, and generate classified and controlled unclassified information or material.

7.1 Portable Electronic Devices (PEDs): Non-Government and/or personally owned portable electronic devices (PEDs) are prohibited in all NSWCDD buildings with the exception of personally owned cell phones which are authorized for use in spaces up to and including Controlled Access Areas. The contractor shall ensure the onsite personnel remain compliant with this PED policy. NSWCDD instruction defines PEDs as the following: any electronic device designed to be easily transported, with the capability to store, record, receive or transmit text, images, video, or audio data in any format via any transmission medium. PEDs include, but are not limited to, pagers, laptops, radios, compact discs and cassette players/recorders. In addition, this includes removable storage media such as flash memory, memory sticks, multimedia cards and secure digital cards, micro-drive modules, ZIP drives, ZIP disks, recordable CDs, DVDs, MP3 players, iPADs, digital picture frames, electronic book readers, kindle, nook, cameras, external hard dish drives, and floppy diskettes.

PEDs belonging to an external organization shall not be connected to NSWCDD networks or infrastructure without prior approval from the NSWCDD Information Assurance and Compliance Branch. This approval will be granted using the TARIS form and action tracker process.

Personally owned hardware or software shall not be connected or introduced to any NSWCDD hardware, network or information system infrastructure.

7.2 Electronic Spillages: Electronic spillages (ES) are unacceptable and pose a risk to national security. An electronic spillage is defined as classified data placed on an information system (IS), media or hardcopy document possessing insufficient security controls to protect the data at the required classification level, thus posing a risk to national security (e.g., sensitive compartmented information (SCI) onto collateral, Secret onto Unclassified, etc.). The contractor's performance as it relates to ES will be evaluated by the Government. ES reflects on the overall security posture of the Government and a lack of attention to detail with regard to the handling of classified information of IS security discipline and will be reflected in the contractor's performance rating. In the event that a contractor is determined to be responsible for an ES, all direct and indirect costs incurred by the Government for ES remediation will be charged to the contractor.

NSWCDD Command Security will continue to be responsible for the corrective action plan in accordance with the security guidance reflected on the DOD Contract Security Classification Specification - DD254 (Attachment J.1). Command Security will identify the contractor facility and contract number associated with all electronic spillages during the investigation that involve contractor support. Command Security will notify the Contracts Division with the contractor facility name and contract number, incident specifics and associated costs for cleanup. The Contracting Officer will be responsible to work with the Contractor Facility to capture the costs incurred during the spillage clean up. The Contractor is also responsible for taking Information Security Awareness training annually, via their Facility Security Officer (FSO), as part of the mandatory training requirements. If a spillage occurs additional training will be required to prevent recurrence.

7.3 Information Security and Computer System Usage: In accordance with U.S. Navy policy, any personnel, including the contractor, who utilizes DOD owned systems, shall assume responsibility for adherence to restrictions regarding internet and e-mail usage. Navy policy prohibits racist, sexist, threatening, pornographic, personal business, subversive or politically partisan communications. All personnel, including the contractor, are accountable and must act accordingly. DOD computer systems are monitored to ensure that the use is authorized, to facilitate protection against unauthorized access, and to verify security procedures, survivability and operational security. During monitoring, information may be examined, recorded, copied, and used for authorized purposes. All information, including personal information, placed on or sent over a DOD system may be monitored. Use of a DOD system constitutes consent to monitoring. Unauthorized use may result in criminal prosecution. Evidence of unauthorized use collected during monitoring may be used as a basis for recommended administrative, criminal or adverse action.

In accordance with DOD and DON cybersecurity workforce (CSWF) requirements, contractors assigned to an IT Level-I designated position with SECRET access will be required to have a favorably adjudicated Single Scope Background Investigation (SSBI) completed every 5 years. Contractors supporting IT Level-I designated positions must have a final Secret clearance on the day the Period of Performance (PoP) starts. The SSBI will be requested, via the emergency appointment process, and will be initiated by NSWCDD Command Security (if the contract is Secret) or the FSO (if the contract is Top Secret). Once the SSBI is submitted, the contractor may begin working at the IT Level-I.

7.4Use of Information System (IS) Resources: Contractor Provision of IS Resources. Except in special circumstances explicitly detailed elsewhere in this document, the contractor shall provide all IS resources needed in the performance of this contract. This includes, but is not limited to computers, software, networks, certificates, and network addresses.
7.5Contractor Use of NSWCDD IS Resources: In the event that the contractor is required to have access to NSWCDD IS resources, the login name used for access shall conform to the NMCI login naming convention. If the contractor requires access to applications/systems that utilize client certificates for authentication, the contractor is responsible for obtaining requisite certificates from a DOD or External Certificate Authority.

If this contract requires that the contractor be granted access and use of NSWCDD IS resources (at any site), the IS shall be accredited for contractor use in accordance with procedures specified by the Information Assurance Office.

Connections between NSWCDD and Contractor Facilities. If there is a requirement (specifically delineated elsewhere in this contract) for interconnection (e.g., link level or Virtual Private Network (VPN)) between any facilities and/or ISs owned or operated by the contractor and ISs owned or operated by NSWCDD, such interconnection shall take place only after approval from the Information Assurance Office. All such connections as well as the ISs connected thereto will be accredited in accordance with DOD policy (DODI 5200.40) by the cognizant Designated Approving Authority (DAA) and comply with the requirements of CJCSI 6211.02B regarding Memorandums of Agreement. All such connections will be made outside the appropriate NSWCDD firewall.

7.6Operations Security (OPSEC): All Contractors (including Sub-contractors) shall supplement their current security practices by requiring any personnel involved in executing this Contract to complete Government-sponsored and administered Operations Security (OPSEC) training. In addition, all Contractors should be aware of the Critical Information List (CIL) for the department they are supporting as well as the OPSEC plan for NSWCDD. Upon Contract award, all identified Contractors (including Sub-contractors) shall sign a Contractor's conformance statement and submit it to the NSWCDD COR named in block 13 of the attached DD-254 thereby acknowledging that they will meet the requirements of this Contract. The COR shall contact their Department Training Coordinator to schedule key employees to attend the Government-sponsored OPSEC training. The Contractor must immediately notify the Government upon the discovery of any nonconformance with the OPSEC Plan.
8.0TECHNICAL POINT OF CONTACT

To be provided at time of award.

File details come from the government source that posted it.