N0017822R4401.pdf
PDF 582 KB Posted
- Attached to
- IT and Telecom – Cyber Security and Data Backup Federal contract opportunity
- Solicitation number
- N0017822R4401
About this file
This is a solicitation for Risk Management Framework (RMF) security authorization package creation and maintenance services. The solicitation is issued by the Naval Surface Warfare Center, Dahlgren Division (NSWCDD) in support of their cybersecurity requirements. The requirement is set aside 100% for small businesses. Offerors must be registered in the System for Award Management. The contract will be a single award on a firm-fixed-price basis for a period of five years. The final award basis will be best value tradeoff. Responses are due by 3:00 PM on 22 July 2022, and award is anticipated around 23 January 2023. The services required include RMF package creation, maintenance of existing packages, vulnerability scanning and remediation, documentation preparation and updates, and subject matter expertise.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| N0017822R4401-0002.pdf | ||
| Exhibit A -- CDRL A006 - Meeting Minutes Ver 1 Signed-mmh.pdf | ||
| Exhibit A -- CDRL A001 - Project Management Plan Ver 1 Signed-mmh.pdf | ||
| Exhibit A -- CDRL A003 - Technical Report-Study-Services Signed-mmh.pdf | ||
| Exhibit A -- CDRL A007.REV1 - Presentation Material Ver 1 Signed-mmh.pdf | ||
| Exhibit A -- CDRL A005 - Conference Report Ver 1 Signed-mmh.pdf | ||
| Exhibit A -- CDRL A002 - Contracting Officers Mgmt Report Ver 1 Signed-mmh.pdf | ||
| Exhibit A -- CDRL A008 - Weekly Status Report Ver 1 Signed-mmh.pdf | ||
| Exhibit A -- CDRL A004 - GFP Inventory Report Ver 1 Signed-mmh.pdf | ||
| SF1449_N0017822R4401.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
N0017822R4401 22-Jun-2022
b. TELEPHONE NUMBER
(540) 653-4706
8. OFFER DUE DATE/LOCAL TIME
03:00 PM 22 Jul 2022
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
N001789. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
TEMICA L. SCROGGINS
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
0 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED OR X
SMALL BUSINESSX
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
NSWCDD 1
ATTN: TEMICA SCROGGINS/0241
17632 DAHLGREN ROAD
DAHLGREN VA 22448
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS AX
13b. RATING
DO-C9
CODE15. DELIVER TO CODE N00178 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
NSWCDD
RECEIVING OFFICER
6220 TISDALE ROAD STE 159 BLDG 125
DAHLGREN VA 22448-5114
TEL: 540-653-7306 FAX:
FAX:
TEL: SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
$30,000,000
NAICS:
541519
X
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF99
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
N0017822R4401
Section SF 1449 - CONTINUATION SHEET
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 1 Lot RMF Package Creation & Maintenance
FFP
BASE PERIOD RMF Package Creation & Maintenance FOB: Destination
PSC CD: DJ01
NET AMT
0002 1 Lot OPTION RMF Package Creation & Maintenance
FFP
OPTION PERIOD 1 RMF Package Creation & Maintenance
0003 1 Lot OPTION RMF Package Creation & Maintenance
FFP
OPTION PERIOD 2 RMF Package Creation & Maintenance
0004 1 Lot OPTION RMF Package Creation & Maintenance
FFP
OPTION PERIOD 3 RMF Package Creation & Maintenance
0005 1 Lot OPTION RMF Package Creation & Maintenance
FFP
OPTION PERIOD 4 RMF Package Creation & Maintenance
0006 4 Each OPTION Travel - Washington DC
FFP
Base Period Option - Qty. 2 trips for 2 individuals to Washington, DC
0007 72 Each OPTION Travel - Virginia Beach, VA
FFP
Base Period Option - Qty. 24 trips for 3 individuals - Virginia Beach, VA
0008 4 Each OPTION Travel - Port Hueneme, CA
FFP
Base Period Option - Qty. 2 trips for 2 individuals - Port Hueneme, CA
0009 4 Each OPTION Option Period 1 Travel - Washington DC
FFP
Option Period 1 - Qty. 2 trips for 2 individuals - Washington, DC
0010 72 Each OPTION Option Period 1 Travel-Virginia Beach,VA
FFP
Option Period 1 - Qty. 24 trips for 3 individuals - Virginia Beach, VA
0011 4 Each OPTION Option Period 1 Travel- Port Hueneme, CA
FFP
Option Period 1 - Qty. 2 trips for 2 individuals to Port Hueneme, CA
0012 4 Each OPTION Option Period 2 Travel - Washington DC
FFP
Qty. 2 trips for 2 individuals to Washington DC.
0013 72 Each OPTION Option Period 2 Travel-Virginia Beach,VA
FFP
Qty. 24 trips for 3 individuals to Virginia Beach, VA
0014 4 Each OPTION Option Period 2Travel - Port Hueneme, CA
FFP
Qty. 2 trips for 2 individuals to Port Hueneme, CA.
0015 4 Each OPTION Option Period 3 Travel - Washington DC
FFP
Qty. 2 trips for 2 individuals to Washington, DC.
0016 72 Each OPTION Option Period 3 Travel-Virginia Beach,VA
FFP
Qty. 24 trips for 3 individuals to Virginia Beach, VA
0017 4 Each OPTION Option Period 3Travel - Port Hueneme, CA
FFP
Qty. 2 trips for 2 individuals to Port Hueneme, CA.
0018 4 Each OPTION Option Period 4 Travel - Washington, DC
FFP
Qty. 2 trips for 2 individuals to Washington, DC.
0019 72 Each OPTION Option Period 4 Travel-Virginia Beach,VA
FFP
Qty. 24 trips for 3 individuals to Virginia Beach, VA
0020 4 Each OPTION Option Period 4 Travel -Port Hueneme, CA
FFP
Qty. 2 trips for 2 individuals to Port Hueneme, CA.
Base Period CDRL
FFP
Base Period CDRL
OPTION Option Period 1 CDRL
Option Period 1 CDRL
OPTION Option Period 2 CDRL
Option Period 2 CDRL
OPTION Option Period 3 CDRL
Option Period 3 CDRL
OPTION Option Period 4 CDRL
Option Period 4 CDRL
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government 0002 Destination Government Destination Government 0003 Destination Government Destination Government 0004 Destination Government Destination Government 0005 Destination Government Destination Government 0006 Destination Government Destination Government
0007 Destination Government Destination Government 0008 Destination Government Destination Government 0009 Destination Government Destination Government 0010 Destination Government Destination Government 0011 Destination Government Destination Government 0012 Destination Government Destination Government 0013 Destination Government Destination Government 0014 Destination Government Destination Government 0015 Destination Government Destination Government 0016 Destination Government Destination Government 0017 Destination Government Destination Government 0018 Destination Government Destination Government 0019 Destination Government Destination Government 0020 Destination Government Destination Government 0021 N/A N/A N/A N/A 0022 N/A N/A N/A N/A 0023 N/A N/A N/A N/A 0024 N/A N/A N/A N/A 0025 N/A N/A N/A N/A
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /
CAGE
0001 12 mths. ADC 1 NSWCDD
RECEIVING OFFICER
6220 TISDALE ROAD STE 159 BLDG 125
DAHLGREN VA 22448-5114
540-653-7306
N00178
0002 24 mths. ADC 1 (SAME AS PREVIOUS LOCATION)
0003 36 mths. ADC 1 (SAME AS PREVIOUS LOCATION)
0004 48 mths. ADC 1 (SAME AS PREVIOUS LOCATION)
0005 60 mths. ADC 1 (SAME AS PREVIOUS LOCATION)
0006 12 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0007 12 mths. ADC 72 (SAME AS PREVIOUS LOCATION)
0008 12 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0009 24 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0010 24 mths. ADC 72 (SAME AS PREVIOUS LOCATION)
0011 24 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0012 36 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0013 36 mths. ADC 72 (SAME AS PREVIOUS LOCATION)
0014 36 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0015 48 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0016 48 mths. ADC 72 (SAME AS PREVIOUS LOCATION)
0017 48 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0018 60 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0019 60 mths. ADC 72 (SAME AS PREVIOUS LOCATION)
0020 60 mths. ADC 4 (SAME AS PREVIOUS LOCATION)
0021 N/A N/A N/A N/A
0022 N/A N/A N/A N/A
0023 N/A N/A N/A N/A
0024 N/A N/A N/A N/A
0025 N/A N/A N/A N/A
PERFORMANCE WORK STATEMENT
C.1 BACKGROUND
The Naval Surface Warfare Center, Dahlgren Division (NSWCDD) Command (Code 00), Corporate Operations (Code 10) and Technical Departments which include: Strategic and Computing Systems (A-Department); Electromagnetic and Sensor Systems (B-Department); Gun and Electronic Weapon Systems (E-Department); Weapons Control and Integration (H- Department); Warfare Analysis and Digital Modeling (M-Department); Readiness and Training Systems (R-Department); and Integrated Combat Systems (V-Department) have a need for Risk Management Framework (RMF) security authorization packages and to provide RMF Authority to Operate (ATO) maintenance for the entire range of Information Systems (ISs) necessary for NSWCDD and NSWCDD Dam Neck Activity (NSWCDD DNA) located in Virginia Beach, Virginia to meet mission and operational objectives. RMF is the Department of Defense (DoD) process for identifying, implementing, validating, certifying, and managing Cybersecurity (CS) capabilities and services, expressed as Security Controls, Assessment Procedures (APs), and for authorizing the operation of DoD Information Systems (ISs), including testing in live/operational or Research, Development, Test, and Evaluation (RDT&E) environments, in accordance with statutory, federal, and DoD requirements.
C.2 SCOPE
This Performance Work Statement (PWS) defines the requirements for RMF support for Information Technology (IT) Systems supported by NSWCDD personnel, located in Dahlgren and Virginia Beach, Virginia. This effort primarily includes Information Assurance (IA)/Cybersecurity policy and control evaluations, preparation of supporting RMF and current Government approved process for packages and artifacts, implementation of security postures, and Subject Matter Expertise (SME) in IA/Cybersecurity Life-Cycle management, coordination, implementation, and deployment via the Naval Sea Systems Command (NAVSEA) Functional Authorizing Official (FAO) and the Navy Authorizing Official (NAO). The scope of this effort also encompasses the RMF work to be performed by NSWCDD personnel for IT Systems under the purview of the Naval Air Systems Command (NAVAIR) FAO, Defense Threat Reduction Agency (DTRA), Army, Marine Corps processes, and/or other Authorizing Officials.
Performance will be measured against the requirements of the Performance Work Statement (PWS) and standards laid out in Attachment J.2 – Quality Assurance Surveillance Plan (QASP).
C.3 APPLICABLE DOCUMENTS
The following documents are applicable to this Performance Work Statement (PWS). The documents listed in this Section may be revised, reissued, or superceded since original publication.
When such is the case, the requirements of the revised, reissued, or superceding document shall apply. Weblinks are provided solely for convenience; it is the Contractor's responsibility to maintain awareness of current versions.
Document No. Title Date
DISN CPG Defense Information Systems Network (DISN) Connection Process Guide, Version 5.1 https://www.disa.mil/~/media/Files/DISA/Services/DISN- Connect/References/DISN_CPG.pdf
Sep-16
DoD 5400.7-R Department of Defense Freedom of Information Act Program http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/540007p.
Sep-98
DoD 8570.01-M Information Assurance Workforce Improvement Program, Incorporating Change 4 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/857001m .pdf
10-Nov-15
DOD Cloud CPG V2.0 Department of Defense (DoD) Cloud Connection Process Guide, Version 2 https://www.disa.mil/~/media/Files/DISA/Services/DISN- Connect/References/CCPG.pdf
Mar-17
DOD Cloud SRG V1R3
Department of Defense (DoD) Cloud Computing Security Requirements Guide, Version 1 Release 3
DCCS Document Library – DoD Cyber Exchange
6-Mar-17
DoD Instruction 8551.01
Ports, Protocols, and Services Management (PPSM) Incorporating Chg 1 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/855101p.
27-Jul-17
DoDD 8140.01 Cyberspace Workforce Management
DoDD 8140.01, Cyberspace Workforce Management, October 5, 2020 (whs.mil)
11-Aug-15
DoDI 8500.01 Cybersecurity http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2 014.pdf
14-Mar-14
DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT), Incorporating Chg 1
24-May-16
DoDI 8510.01, " Risk Management Framework (RMF) for DoD Information Technoloogy (IT)," March 12, 2014, Incorporating change 3 on December 29, 2020 (whs.mil)
DON CIO
Memorandum 02-10
Information Assurance Policy Update for Platform Information Technology http://www.doncio.navy.mil/contentview.aspx?id=873
26-Apr-10
Joint Travel Reg The Joint Travel Regulations http://www.defensetravel.dod.mil/Docs/perdiem/JTR.pdf
1-Oct-17
NAVSEA 9400.2-M NAVSEA PIT-Control System Cybersecurity Implementation Manual, Version 5.0 https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Us e%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468 310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB56
8%2D78916015EBAD%7D
Oct-16
NAVSEA FAO RMF
CPIG
NAVSEA Functional Authorizing Official Risk Management Framework Conversion Process Implementation Guidance https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Us e%2FRMF%20Bridge%20Conversion&FolderCTID=0x01 20001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%
2D0A7C%2D4941%2DB568%2D78916015EBAD%7D
11-May-17
NAVSEA Website NAVSEA Enterprise Cybersecurity website:
https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx#
19-Jan-18
NAVSEAINST
5239.2B
Naval Sea Systems Command (NAVSEA) Cybersecurity Program
Pages - Enterprise Cybersecurity (deps.mil)
20-Sep-16
NIST SP 800-37 Guide for Applying the Risk Management Framework to Federal Information Systems, Revision 1, February 2010 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf
5-Jun-14
NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations, Revision 4, April 2013 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
22-Jan-15
NIST SP 800-53A Assessing Security and Privacy Controls in Federal Information Systems and Organizations, Revision 4 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf
18-Dec-14
NSWCDDINST
5239.6 Series
Policy on Portable Electronic Devices 16-Dec-14 https://wwwdd.csd.disa.mil/documents/forms_and_directives/dir7261/NSWC DDINST_5239.3D.pdf & NMCI:
https://wwwdd.nmci.navy.mil/documents/forms_and_directives/dir7261/NS WCDDINST_5239.3D.pdf
RDT&E A&A Policy Research, Development, Test and Evaluation Assessment and Authorization Policy for Isolated Enclaves https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Us e%2FIsolated%20Enclave%20Policy%5FRDTnE&FolderCTID=0x0120001 D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7
C%2D4941%2DB568%2D78916015EBAD%7D
11-Apr-17
RPG 3.2 Risk Management Framework Process Guide, Version 3.2
Policies - Home View (navy.mil)
2-Sep-20
SECNAV M-5239.2 Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification Manual
SECNAV-M-5239-2.pdf (osd.mil)
Jun-16
SECNAV M-5510.36 Department of the Navy Information Security Program https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Us e%2FVarious%20Classification%20Guides&FolderCTID=0x0120001D3A81 7011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D
4941%2DB568%2D78916015EBAD%7D
Jun-06
SECNAVINST
5239.3C
Department of the Navy Cybersecurity Policy
5239.3.pdf (navy.mil)
2-May-16
SPAWAR
Memorandum 5000 Ser 5.0/362
Navy Qualified Validator (NQV)
NQV Qualifications and Application Documentation - All Documents (navy.mil)
19-Apr-16
USN RMF Strategy US Navy Risk Management Framework Implementation Strategy https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2F hq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Us e&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View
={64D3A4AD-0A7C-4941-B568-78916015EBAD}
1-Feb-17
C.4 DESCRIPTION OF SERVICES
NSWCDD has a requirement to support the Command in Cybersecurity policy and control evaluations, preparation of supporting RMF and current Government approved process for packages and artifacts, implementation of security postures, and Subject Matter Expertise (SME) in IA/Cybersecurity Life-Cycle management, coordination, implementation, and deployment via the Naval Sea Systems Command (NAVSEA) Functional Authorizing Official (FAO) and the Navy Authorizing Official (NAO).
On-site services will also be required at NSWCDD DNA. The Contractor shall provide recommended solutions for technical IT issues and perform to the standards, and the degree of ability, knowledge, skills and timeliness required in the PWS. The Contractor shall have the capability of developing technologies and have the technical expertise to transition into new operating environments.
The following Paragraphs describe the required Assessment and Authorization (A&A) support services in detail.
C.4.1 RMF Package Creation
C.4.1.1 The Contractor shall provide RMF ashore and customer/afloat package creation and RMF ATO maintenance support throughout the lifecycle of the IT system. The Contractor shall fulfill Information System Security Engineer (ISSE) assignments in accordance with RMF to assess and authorize new ISs, and re-authorize existing system packages. The Contractor shall also fulfill assignments in accordance with RMF to provide package creation and maintenance support for ISs determined to be Assess Only or Non-IT Designation. These systems are primarily located at NSWCDD and its detachments listed in Section 1.0. IT Systems supported on this contract are primarily under NAVSEA FAO and NAO, but may be under the purview of the Naval Air Systems Command (NAVAIR) FAO, Defense Threat Reduction Agency (DTRA), Army, Marine Corp processes, and/or other Authorizing Officials. The Contractor will not be required to perform internal or external penetration testing on ISs.
The Contractor shall provide a staffing plan document to encompass each requirement location.
The Contractor shall deliver A&A creation and maintenance of packages; project planning schedules and charts; provide presentations on A&A creation; and provide maintenance documentation of changes and updates applied to Systems and Networks in accordance with CDRL A001, CDRL A002, and CDRL A003.
C.4.1.2 The Contractor shall assist NSWCDD and NSWC Dam Neck System POCs with developing overall RMF improvement strategies (i.e., inheritance, template utilization) to streamline approval processes and reduce the timeframe for overall RMF processing. Contractor shall also provide bi-monthly training and lessons-learned to System Representatives on best practices and strategies improve RMF workflows. (CDRL A003)
C.4.1.3 The Contractor shall provide all required information assurance/A&A document creation/preparation services and/or A&A maintenance services for security authorization packages throughout the lifecycle of the IT system. Creation/preparation services and/or A&A maintenance services includes standard RMF packages (to include PIT), Non-IT Designation packages, Assess Only packages, Interim Authorization to Test (IATT) packages, and Warfare Center Interim Authorization to Connect (IATC) documentation.
C.4.1.4 The Contractor shall have direct knowledge of Enterprise Mission Assurance Support Service (eMASS) and a minimum of six (6) years of experience utilizing the Navy’s instance of eMASS. Additionally, the Contractor shall have performed duties previously as an ISSE for Navy RMF packages, which resulted in the granting of thirty (30) or more RMF Authorizations to Operate (ATOs).
C.4.1.5 The Contractor shall adhere to the respective Authorizing Official-specific processes to identify and properly manage the risk of IT Systems in accordance with the DoD Instruction (DoDI) 8510.01, RMF for DoD Information Technology (IT), and when applicable, taking into consideration Navy–unique operational and environmental demands detailed in the Department of Navy Risk Management Process Guide and all superseding updates to the document. The Contractor shall follow the published Authorizing Official/Echelon II Business Rules (see Section 2) and supplemental Guidance (i.e., NAVSEA A&A News You Can Use notifications). The Command Information System Security Manager (ISSM) in coordination with the respective Authorizing Official will resolve any conflict between these rules.
C.4.1.6 The Contractor shall collaborate with the designated Authorizing Official (AO) (Navy Authorizing Official (NAO) or Functional Authorizing Official (FAO)) and their representatives for Platform IT (PIT) Afloat, PIT Ashore, RDT&E Zone A, B, C, D, and Cloud-based environment packages throughout all steps of the RMF process. Collaborate with the designated Naval Authorizing Official (NAO) and/or their representatives for Defense Business Systems (DBS), Zone A, Afloat Site, and all packages categorized as HIGH Risk, throughout all steps of the RMF process. The Authorizing Official responsible for package authorization may change at the discretion of the Government.
C.4.1.7 The Contractor shall ensure that any IT system functioning/being operated under a legacy DIACAP or PIT accreditation will be transitioned to RMF under package creation services.
There are currently over 10 legacy systems under DIACAP or PIT accreditation, of which the Government plans to transition to RMF. Over the past five years, a total of two (2) legacy systems have been transitioned to RMF. The Government expects the number of transitions to remain consistent until all remaining legacy systems are transitioned.
C.4.1.8 The Contractor shall ensure that any newly established IT systems assigned to the Contractor will be transitioned to RMF under package creation services.
C.4.1.9 The Contractor shall ensure maintenance services will be provided/included for any newly created packages throughout the year the ATO for that package was awarded as part of the package creation service. One (1) year following the award of the ATO, the package will then transition under A&A maintenance services and be charged accordingly.
C.4.1.10 The Contractor shall create/develop A&A artifacts such as to: PIT Designation, System Categorization, Security Plan (SP), Implementation Plan, Security Assessment Plan (SAP), Security Assessment Report (SAR), Privacy Impact Assessment (PIA), Risk Assessment documents, System Level or Information System Continuous Monitoring (SLCM) Strategy, hardware/software lists, and network/architecture diagrams for all assigned ISs as required by DoD, DON, NAVSEA, NSWCDD, and Navy Enterprise Mission Assurance Support Service (eMASS). (CDRL A003)
C.4.1.11 The Contractor shall collect, collaborate, or conduct vulnerability scans for all applicable environments and interpret results with Authorizing Official/Security Control Assessor (SCA)-accepted tools. Networked environments shall be scanned monthly. Non-networked/isolated environments shall be scanned quarterly.
C.4.1.12 The Contractor, during package creation activities, shall analyze, remediate (after coordinating with the respective System Administration team or System ISSO), and document vulnerabilities by:
• Performing vulnerability analysis;
• Remediating vulnerabilities posing a corresponding risk to operations (e.g., remove or quarantine); and
• Documenting residual risks into Plan of Action and Milestones (POA&Ms), Risk
Assessments and other applicable documents in eMASS.
C.4.1.13 The Contractor shall provide vulnerability scanning through the Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP) of the ISs (or subsequent tools mandated by Authorizing Officials). The Contractor is not expected to provide any scanning tools or scanning software licenses for this contract. Contractor scans shall either include full authorization boundaries or include sampling of authorization boundaries, as directed by the Government.
C.4.1.14 The Contractor shall scan and apply remediation (after coordinating with the respective environment System Administrator or System Representative) in accordance with the Defense Information Security Agency (DISA) Security Technical Implementation Guide (STIG), Security Requirements Guide (SRG), Security Readiness Review (SRR), and generate DISA checklists and/or artifacts.
C.4.1.15 The Contractor shall coordinate and collaborate with the respective System Administrator Team or System Representative before applying mitigation and remediation actions.
The Contractor will ensure mitigation and remediation actions are first applied to a sample environment/asset and receive concurrence from the System Administrator Team or Representative that the sample environment/asset still functions as desired before proceeding with applying remediation to the entire boundary. In the event of technical problems because of remediation (i.e., asset not functioning as desired), the Contractor will work with the appropriate System Administrator or Representative to “roll back” any changes and document them accordingly in the POA&M.
C.4.1.16 The Contractor shall prepare ISs for the authorization process within the timeframes outlined in 4.1.16. The Contractor shall perform ACAS and SCAP scans, all applicable Security Technical Implementation Guide (STIG), Security Requirements Guide (SRG), Security Readiness Review (SRR) checks, DISA checklists, and remediate system assets to acceptable levels as required by the ISSM or respective Information System Security Officer (ISSO). The Contractor shall create all documentation to prove compliance with requirements utilizing eMASS.
C.4.1.17 The Contractor shall collectively complete and submit all ISO/ISSE required tasks for each RMF step within the timeline identified.
• RMF Step 1 – Six (6) business days
• RMF Step 2 – Ten (10) business days
• RMF Step 3 – Thirty (30) business days
• RMF Step 4 – Twenty (20) business days
• RMF Step 5 – Ten (10) business days
• RMF Step 6 - Twenty (20) business days
C.4.1.18 The Contractor shall ensure in the event RMF is replaced by a new cybersecurity standard, the scope of required services in this PWS shall continue in accordance with the requirements identified in the new standard.
C.4.2 RMF Package Maintenance
The Contractor shall perform A&A maintenance for all assigned PIT (Afloat, Ashore, Site, Non-Navy), and assigned RMF authorization packages, including re-authorization efforts. The Contractor shall also fulfill assignments in accordance with RMF to provide package maintenance support for ISs determined to be Assess Only or Non-IT Designation. The tasking shall include creating, updating, and documenting all required artifacts.
C.4.2.1 The Contractor shall ensure any RMF Bridge Conversion (RBC) packages are maintained appropriately using the RMF eMASS record including obtaining a full ATO under maintenance services.
C.4.2.2 The Contractor shall ensure the A&A documentation is maintained for any IT System functioning under an expired RMF or RBC authorization under maintenance services to include ATO renewal.
C.4.2.3 The Contractor shall ensure maintenance is provided/included for any new packages created throughout the year the ATO was awarded for that package as part of the package creation services. One (1) year following the award of the ATO, the package will then transition under maintenance services.
C.4.2.4 The Contractor shall perform all requirements to prepare ISs for the re-authorization process by making them compliant within the timeframe identified above. Create all required RMF re-authorization package documentation and artifacts, as necessary. Re-authorization requirements include, but are not limited to, adhering to the Navy RPG, performing ACAS, SCAP scans, all required STIG checks and remediating system assets to acceptable levels in accordance with the PWS. The Contractor shall scan for vulnerability findings and apply remediation in accordance with the DISA STIGs, SRG, SRR tools, and shall generate DISA checklists and/or artifacts within the same timeframe. The Contractor shall utilize eMASS, other repositories, and tools to create and contain all documentation to prove compliance with requirements. The Contractor shall provide any additional artifacts to complete authorization and re-authorization packages based on each package’s unique requirements.
C.4.2.5 The Contractor shall evaluate all vulnerabilities identified during the A&A processes and recommend mitigation measures to System Administrator and System ISSO for reducing or eliminating identified risk items.
C.4.2.6 The Contractor shall perform remediation actions after collaborating with the respective System Administrator or System Representative for each IS, including STIG/SRG/SRR requirements and/or remediation, ACAS scanning and remediation, eMASS requirements, VRAM maintenance, and security control updates and reconciliation. The Contractor shall perform reconciliation of the POA&M and all applicable documentation based on security scans.
C.4.2.7 The Contractor shall work with the ISSO and the ISO to determine and implement (if necessary) fixes/mitigation for weaknesses and to determine the level of revalidation testing that is necessary.
C.4.2.8 The Contractor shall address all conditions and or stipulations identified in ATO and PIT Risk Assessment (PRA) letters.
C.4.2.9 The Contractor shall ensure that all cybersecurity requirements are addressed for A&A package maintenance.
C.4.2.10 The Contractor shall update all relevant security artifacts such as: the PIT Designation, System Categorization, Security Plan (SP), Implementation Plan, Security Assessment Plan (SAP), Security Assessment Report (SAR), Privacy Impact Assessment (PIA), POA&M, Risk Assessment documents, System Level or Information System Continuous Monitoring (SLCM) Strategy, hardware/software lists, and network/architecture diagrams based on the results of the continuous monitoring process for all assigned ISs. All documents shall be updated and uploaded in eMASS.
C.4.2.11 The Contractor shall complete development of system artifacts and appropriate ISSE testing to satisfy recurring review requirements (Annual Security Reviews, Quarterly Reviews, FISMA Reviews, Continuous Monitoring activities, etc.) for the authorized ISs as a result of maintenance performed and change management activities.
C.4.2.12 The Contractor shall self-assess, document, and report all security controls within eMASS.
C.4.2.13 The Contractor shall perform an Annual Security Review (ASR) of Security Controls and APs for the authorized ISs and document within eMASS.
C.4.2.14 The Contractor shall report the security status of the ISs (including the effectiveness of security controls employed within and inherited by the system) to the AO – through the Command ISSM – and other appropriate organizational officials in accordance with the monitoring strategy in the monthly status updates in accordance with CDRL A002.
C.4.2.15 The Contractor shall review the reported security status of the ISs (including the effectiveness of security controls employed within and inherited by the ISs) on an ongoing basis, in accordance with the monitoring strategy, to determine whether the risk to operations, organizational assets, individuals, or other organizations remains acceptable.
C.4.2.16 The Contractor shall provide support to the responsible IT System ISSO or System Representative (as requested) to prepare various documentation to support RMF submissions, various A&A projects, and inspections (i.e., Inspector General) such as Ports, Protocols, and Services Management (PPMS) registration submission, Tabletop Mission Cyber Risk Assessment (TMCRA), Conditional Authorization Requests (CARs), Memorandums of Understanding (MOUs)/Memorandums of Agreement (MOAs), security agreements, Concept of Operations (CONOPS) documents and waivers (as necessary) to include Public Key Infrastructure (PKI), and Host Based Solution Services (HBSS)), and DoDIN.
C.4.2.17 The Contractor shall assist the Government with determining the security impact of proposed or actual changes to the ISs and their environment of operation.
C.4.2.18 The Contractor shall routinely monitor configuration management of the assigned NSWCDD IT Systems, updating respective IT system Security Authorization Packages as needed, preparing necessary Authorization Modification (i.e., "Use Case" or Memorandum for Record (MFR)) documentation, and ensuring approvals are documented.
C.4.2.19 The Contractor shall adhere to required package maintenance intervals (i.e., daily, weekly, monthly, quarterly, annually) and updating IT System documentation as dictated by IT system configuration management system Change Control Board (CCB) (hardware/software addition/removal) to include vulnerability scanning intervals, etc.
C.4.2.20 The Contractor shall maintain the IS artifacts, update artifacts based on change management and perform reporting as required by DoD, DON, NAVSEA, NSWCDD, and eMASS.
C.4.2.21 The Contractor shall self-assess, document, and report all security controls within eMASS.
C.4.2.22 The Contractor shall capture meeting minutes from any and all A&A related collaboration meetings (informal, formal, adhoc, or otherwise) pertaining to the assigned IT System and provide said minutes to the Government Technical Points of Contact (TPOCs) in accordance with CDRL A006.
C.4.2.23 The Contractor shall determine when the updated Security Authorization Package is ready, complete, and of adequate quality for submission to external organizations (i.e., NAVSEA, NAO, SPAWAR) for review as required.
C.4.2.24 The Contractor shall be responsible for conducting the ISSM Quality Review (i.e., ensure NAVSEA/NAO checklists are accurate and complete) and advising the ISSM when packages are complete and ready for submission to external organizations (i.e., NAVSEA, NAO).
C.4.2.25 The Contractor shall prepare NAVSEA Trusted Package Submitting Officer (PSO) briefing material, such as draft Authorization to Operate letters and brief NAVSEA personnel to include Technical Area Experts (TAEs), FAOs, and/or their representatives during any and all RMF Checkpoint or Collaboration Meetings. (CDRL A007)
C.4.2.26 The Contractor shall respond when necessary by phone or e-mail to the Government Technical Points of Contact (TPOCs) or ISSM requests within one (1) business day.
C.4.2.27 The Contractor shall respond in writing to all package update requests (made by NAVSEA, NAO, etc.) within two (2) business days.
C.4.2.28 The Contractor shall make all ISSE required package updates in accordance with DOD, DON, and NAVSEA requests and requirements within three (3) business days. If more time is required, this must be coordinated with the Government Technical Points of Contact (TPOCs).
C.4.2.29 The Contractor shall provide hardware and software data gathered/updated during the RMF process (creation and maintenance) for inclusion in the applicable local asset-tracking database (i.e., NSWCDD Internet Protocol and Authorization (IPA) Database, Dell KACE). The Contractor shall ensure the data is provided in a format that is capable of being imported into the respective database.
C.4.2.30 The Contractor shall allow usage of any NSWCDD tools (i.e., Findings Management and Tracking System (FMATS), Internet Protocol and Authorization (IPA)) and applications developed for NSWCDD Package creation and maintenance by System Administrators or System Representatives for the duration of the contract and lifecycle of the
ATO.
C.4.2.31 The Contractor shall utilize NSWCDD or Warfare Center tools (as determined by the NSWCDD ISSM) (i.e., eMASSTer, STIG Manager, Evaluate STIG, Findings Management and Tracking System (FMATS), Internet Protocol and Authorization (IPA)) and applications developed for NSWCDD Package creation and maintenance for the duration of the contract and lifecycle of the ATO.
C.4.2.32 The Contractor shall ensure that any proprietary tools and applications/software, scripts etc. related to completion of A&A tasks used by, or developed during contract performance by the Contractor, will be available for use by the Government, at no additional cost, for the life of the contract.
C.4.2.33 The Contractor shall collaborate with Department resources as necessary for the potential development of tools, applications, and overall A&A strategies that may enhance or streamline the A&A documentation process.
C.4.2.34 The Contractor shall develop all necessary A&A documentation and upon completion deliver to System Representative (i.e., System ISSO/Program Manager) for acceptance on the Program’s behalf. System Representative shall ensure documentation accurately represents the IT System.
C.4.2.35 The Contractor shall provide a completion report to the respective System Representatives for all IT systems under maintenance that identifies the tasks done to complete the overall maintenance effort.
C.4.3 HOURS OF OPERATION AND COVERAGE
C.4.3.1 On-site Contractor personnel shall provide required services and staffing coverage for NSWCDD during normal business hours (Monday through Friday).
C.4.3.2 On-site Contractor shall be structured to allow for broadest range of support coverage in a specified work area during their arrival and departure of the workday.
C.4.3.3 All Contractor employees are encouraged to work in accordance with the same schedules as the Government office that they are supporting.
C.4.4 ABSENCE/LATE ARRIVAL
The Contractor shall notify the Governments TPOC via telephone or email for any delayed arrival or absence of on-site Contractor personnel as soon as possible
C.4.5 TELEWORK
C.4.5.1 Telework for Contractor personnel will be at the discretion of the Contractor and will not require Government TPOC and COR concurrence.
C.4.5.2 Government requires notification of telework days/schedule.
C.4.5.3 In the event of telework, the Contractor shall track all Government Furnished Equipment (GFE)/Government Furnished Property (GFP), listing personnel, asset tag numbers and serial numbers for all Navy/Marine Corps Intranet (NMCI) computer equipment in the Contractor’s possession (CDRL A004). All equipment shall be returned to the Government by the end of the Contract or when equipment is no longer in use, whichever comes first.
C.4.6 WORK LOCATION
The primary work location is at NSWCDD, which includes the primary locations of Dahlgren, VA, and Dam Neck Activity (DNA), Virginia Beach, VA.
C.5 MANDATORY REQUIREMENTS
All mandatory requirements must be maintained through the life of the Task Order. The mandatory requirements are as follows:
C.5.1 Requirement 1 - FCL: The Prime Contractor supporting this requirement must have a FCL of SECRET.
C.5.2 Requirement 2 - Personnel Security Clearance: All personnel performing under this Task Order shall have, at a minimum, SECRET Security Clearances in DISS. Interim clearances are acceptable.
C.6 SKILLS AND TRAINING
The Contractor shall provide capable personnel with qualifications, experience levels, security clearances, and necessary licenses, certifications, and training required by Federal, State and Local laws and regulations. Information assurance functions require certifications specified in
DFARS 252.239-7001 INFORMATION ASSURANCE CONTRACTOR TRAINING AND
CERTIFICATION.
Training necessary to ensure that personnel performing under this Contract maintain the knowledge and skills to successfully perform the required functions is the responsibility of the Contractor. Training necessary to maintain professional certification is the responsibility of the Contractor. Contractors that require privileged use shall maintain the appropriate Information Assurance Technology (IAT) certification (IAT II) and have current certification IAW DoD Directives 8570.01-M or successor at the IAM/IAT Level III or higher.
C.7 OTHER DIRECT COSTS
C.7.1 Contractor Travel Requirements
(a) During the performance of this effort, Contractor personnel may be required to travel to other sites to support program activities. Costs for travel between the Contractor's facility, NSWC Dahlgren, and/or NSWCDD DNA are unallowable and will not be reimbursed.
(b) The numbers of trips and types of personnel traveling shall be limited to the minimum required to accomplish work requirements and shall be coordinated with the COR via the specific work area Program Manager.
Projected travel destinations include:
NAVSEA, Washington Navy Yard, Washington, DC NSWCPHD, Port Hueneme, CA
C.7.2 Materials and Equipment
The Contractor is responsible for providing any additional materials and equipment necessary to perform the work under the PWS that is not identified elsewhere in this contract as provided by the Government.
C.8 GOVERNMENT FURNISHED OFFICE SPACE, EQUIPMENT, AND MATERIALS
C.8.1 Government Furnished Office Space
The Government will provide office space to include all NSWCDD allowable IT equipment, phone, and general office supplies.
Base Year Opt Year I Opt Year II Opt Year
III
Opt Year
IV
TOTAL
ON
SITE
TOTAL
8 Full-time equivalents
(FTEs)
8 Full-time equivalents
(FTEs)
8 Full-time equivalents
(FTEs)
8 Full-time equivalents
(FTEs)
8 Full-time equivalents
(FTEs)
40 Full-time equivalents
(FTEs)
C.8.2 Government Furnished Materials
The Government will provide GFE as required by the individual tasking to the Contractor. Laptops will be provided as GFP and can be found in Attachment J.3 – Government Furnished Property (GFP). The Contractor shall report the status of all GFE. (CDRL A004)
C.9 GOVERNMENT FURNISHED INFORMATION
C.9.1 The Government will provide access to information and documentation required for Contract performance.
C.9.2 All information and documentation shall be retained at the Government work site.
C.9.3 The Government will provide access to the Navy A&A Tracking System, eMASS.
C.9.4 The Government will provide non-disclosure agreements and conflict of interest statements.
C.10 SECURITY REQUIREMENTS
The Department of Defense Contract Security Classification Specification (DD Form 254) (Attachment J.1 - Defense Contract Classification Specification) provides the security classification requirements for this order. The Contractor shall obtain facility and personnel security clearances at the level required by the National Industrial Security Program prior to starting to work on tasks requiring clearances. Access to classified spaces and material and generation of classified material shall be in accordance with the attached DD Form 254. All personnel performing on-site must maintain the appropriate level security clearance. Some positions will require IT-Level 1 designation. In accordance with DoD/DON CSWF requirements, Contractors designated with IT Level-I are required to have at a minimum, a SECRET clearance based upon a favorably adjudicated T5/T5R completed within the last 6 years. Contractor employees that do not have a final clearance investigation within Defense Information Security System (DISS) are ineligible for IT Level-I designation until the T5/T5R has been favorably adjudicated, shall remain at IT level-II status in DISS and shall not be assigned to a Contract position requiring IT Level-I designation.
C.10.1 FCL: The Contractor shall possess and maintain an FCL of SECRET.
C.10.2 Physical Security: The Contractor shall be responsible for safeguarding all Government information or property provided for Contractor use. At the end of each work period, Government information, facilities, equipment and materials shall be secured as specified by the NISPOM and the NSWCDD Command Security Manual. No SECRET storage is required at the Contractor’s facility in order to meet requirements of receiving and generating classified material in accordance with this Contract.
C.10.3 The Contractor shall require access to Communications Security (COMSEC) in order to use crypto keying material. Access to Non-SCI intelligence is needed in order to utilize intelligence documents related to foreign Government weapons systems. Access to NATO is required to obtain a SIPRnet account and to utilize the DTIC system to obtain documents on intelligence. Access to Foreign Government Information is not required to obtain documents on specific weapon systems. Controlled Unclassified Information (CUI), to include For Official Use Only (FOUO) and Personally Identifiable Information (PII), generated and/or provided under this contract shall be safeguarded and marked as specified in DoD Instruction 5200.48. All above accesses are needed to support and provide the system engineering, software development, and maintenance of Navy tactical initiatives and spiral and baseline developments to support NSWCDD. In performing under this contract, the Contractor shall have access to U.S. classified information.
C.10.4 Portable Electronic Devices (PEDs)
(a) Non-Government and/or personally owned portable electronic devices (PEDs) are prohibited in all NSWCDD buildings with the exception of personally owned cell phones which are authorized for use in spaces up to and including Controlled Access Areas. The Contractor shall ensure the onsite personnel remain compliant with this PED policy. NSWCDD instruction defines PEDs as the following: any electronic device designed to be easily transported, with the capability to store, record, receive or transmit text, images, video, or audio data in any format via any transmission medium. PED’s include, but are not limited to, pagers, laptops, radios, compact discs and cassette players/recorders. In addition, this includes removable storage media such as flash memory, memory sticks, multimedia cards and secure digital cards, micro-drive modules, ZIP drives, ZIP disks, recordable CDs, DVDs, MP3 players, iPad, digital picture frames, electronic book readers, kindle, nook, cameras, external hard dish drives, and floppy diskettes.
(b) Personal Wearable Fitness Devices (PWFDs) marketed primarily as fitness or sleep devices are allowed in all Navy spaces where collateral non-Sensitive Compartmented Information (SCI), classified information is processed, stored, or discussed up to and including secret. User must ensure PWFD is compliant with all requirements in NAVADMIN 216/15, Cyber Hygiene Authorization to use Personal Wearable Fitness Devices (e.g., Fitbit, Jawbone UP, etc.) in Navy Spaces, dated 14 September 2015 and register PWFD in the NSWCDD Fitness Device Tracker.
(c) PED’s belonging to an external organization shall not be connected to NSWCDD networks or infrastructure without prior approval from the NSWCDD Information Assurance and Compliance Branch. This approval will be granted using the TARIS form and action tracker process.
(d) Personally owned hardware or software shall not be connected or introduced to any NSWCDD hardware, network or information system infrastructure.
C.10.5 Electronic Spillages
(a) Electronic spillages (ES) are unacceptable and pose a risk to national security. An electronic spillage is defined as classified data placed on an information system (IS), media or hardcopy document possessing insufficient security controls to protect the data at the required classification level, thus posing a risk to national security (e.g., sensitive compartmented information (SCI) onto collateral, Secret onto Unclassified, etc.). The Contractor's performance as it relates to ES will be evaluated by the Government. ES reflects on the overall security posture of the Government and a lack of attention to detail with regard to the handling of classified information of IS security discipline and will be reflected in the Contractor's performance rating. In the event that a Contractor is determined to be responsible for an ES, all direct and indirect costs incurred by the Government for ES remediation will be charged to the Contractor.
(b) NSWCDD Command Security will be responsible for the corrective action plan in accordance with the security guidance reflected on the DOD Contract Security Classification Specification - DD254. NSWCDD Security will identify the Contractor facility and Contract number associated with all electronic spillages that involve the Contractor. NSWCDD Security will identify the Contractor facility and Contract number associated with all electronic spillages that involve the Contractor. NSWCDD Security will notify the Contracts Division with the Contractor facility to capture name and Contract number, incident specifics and associated costs for clean-up. The Contracting Officer will be responsible to work with the Contractor Facility to capture the costs incurred during the spillage clean up. The Contractor is also responsible for taking Information Security Awareness training annually, via their Facility Security Officer (FSO), as part of the mandatory training requirements. If a spillage occurs additional training will be required to prevent recurrence.
C.10.6 Operations Security (OPSEC)
Contractor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .