N0025321Q0010 RFQ.pdf

PDF 984 KB Posted

Attached to
Cyber Security Services Federal contract opportunity
Solicitation number
N0025321Q0010
Issued by
Department of the Navy Naval Sea Systems Command

View the file

Other files for this federal contract opportunity

Other files attached to Cyber Security Services, newest first.
File Type Posted
N0025321Q0010 Amend3.pdf PDF
N0025321Q0010 Amend2.pdf PDF
N0025321Q0010 Amend1.pdf PDF
DD254 21Q0010.pdf PDF
21Q0010 CDRL A002 redacted.pdf PDF
21Q0010 CDRL A001 redacted.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUM

(No Collect Calls)

N0025321Q0010 15-Oct-2020

b. TELEPHONE NUMBER

360-315-5706

8. OFFER DUE DATE/LOCAL TIME

02:00 PM 29 Oct 2020

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA – FAR (48 CFR) 53.212

(TYPE OR PRINT)

(SIGNATURE OF CONTRACTING OFFICER)

ADDENDA ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

23.

CODE 10. THIS ACQUISITION IS

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

TELEPHONE NO.

N002539. ISSUED BY

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

EDWIN J DONOR

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

20.

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

. YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

% FOR:SET ASIDE:UNRESTRICTED OR X

SMALL BUSINESSX

17a.CONTRACTOR/ CODE FACILITY

OFFEROR CODE

NAVAL UNDERSEA WARFARE CENTER

ATTN: EDWIN DONOR

EDWIN.DONOR@NAVY.MIL

610 DOWELL STREET

KEYPORT WA 98345

18a. PAYMENT WILL BE MADE BY CODE

RATED ORDER UNDER

DPAS (15 CFR 700)

13a. THIS CONTRACT IS AX

13b. RATING

DO-S1

CODE15. DELIVER TO CODE N00253 16. ADMINISTERED BY

12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

14. METHOD OF SOLICITATION

RFQ IFB RFPX

NAVAL UNDERSEA WARFARE CENTER

RECEIVING OFFICER

ATTN: DIVISION KEYPORT SUPPLY OFFICER

BLDG 893

610 DOWELL STREET

KEYPORT WA 98345-7610

TEL: 360 396-2760 FAX:

FAX:

TEL: 360-315-5706

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

8(A)

HUBZONE SMALL

BUSINESS

SIZE STANDARD:

$30,000,000

NAICS:

541512

X

OFFER DATED

29. AWARD OF CONTRACT: REF.

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

EMAIL:

TEL:

31c. DATE SIGNED

SEE SCHEDULE

SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT

24.22.21.19.

WOMEN-OWNED SMALL BUSINESS (WOSB)

ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

PAGE 2 OF59

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 2/2012) BACK

Prescribed by GSA – FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

SEE SCHEDULE

20.

SCHEDULE OF SUPPLIES/ SERVICES

21.

QUANTITY UNIT

22. 23.

UNIT PRICE

24.

AMOUNT

19.

ITEM NO.

N0025321Q0010

Section SF 30 - BLOCK 14 CONTINUATION PAGE

PERFORMANCE WORK STATEMENT

ASSESSMENT AND AUTHORIZATION (A&A)/SECURITY AUTHORIZATION

PACKAGE CREATION AND MAINTENANCE

PERFORMANCE WORK STATEMENT (PWS)

1.0 BACKGROUND

Naval Undersea Warfare Center (NUWC) Division Keyport requires contractor support in processing the Risk Management Framework

RMF system accreditation package for the NUWC Keyport Secret

Defense Research Engineering Network (SDREN) system.

2.0 APPLICABLE DOCUMENTS

The following documents are applicable to this PWS.

2.1 Department of the Navy Chief Information Officer

Memorandum 02-10, Information Assurance Policy Update for Platform Information Technology, 26 April 2010;

http://www.doncio.navy.mil/contentview.aspx?id=873.

2.2 DoD 5400.7-R, Department of Defense Freedom of

Information Act Program, September 1998;

http://www.esd.whs.mil/Portals/54/Documents/DD/issuance s/dodd/540007p.pdf.

2.3 DoD 8570.01-M, Information Assurance Workforce

Improvement Program, Incorporating Change 4, 10

November 2015;

http://www.esd.whs.mil/Portals/54/Documents/DD/issuance s/dodm/857001m.pdf.

2.4 DoDD 8140.01, Cyberspace Workforce Management, 11

August 2015;

http://www.esd.whs.mil/Portals/54/Documents/DD/issuance s/dodd/814001_2015_dodd.pdf

2.5 DoDI 8500.01, Cybersecurity, 14 March 2014;

http://www.esd.whs.mil/Portals/54/Documents/DD/issuance s/dodi/850001_2014.pdf.

2.6 DoDI 8510.01, Risk Management Framework (RMF) for DoD

Information Technology (IT), Incorporating Change 1, effective 24 May 2016;

http://www.esd.whs.mil/Portals/54/Documents/DD/issuance s/dodi/851001_2014.pdf.

http://www.doncio.navy.mil/contentview.aspx?id=873 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/540007p.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/540007p.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/857001m.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/857001m.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/814001_2015_dodd.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/814001_2015_dodd.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2014.pdf

2.7 DoD Instruction 8551.01 Ports, Protocols, and Services

Management (PPSM); https://www.disa.mil/Network-

Services/Enterprise-Connections/PPSM.

2.8 NAVSEA Assessment and Authorization Business Rules for

Risk Management Framework via the Functional

Authorizing Official Construct, Version 1, 29 September

2017;

https://navsea.navy.deps.mil/hq/00i/ia/RDTE_CandA_KC/de fault.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FRDTE%5FCandA%5

FKC%2FShared%20Documents%2FRMF%20Business%20Rules&Folde rCTID=0x0120007ABD9FAD9DD2F841981833BF4D42D983&View=%7B

20282DE2%2D6855%2D4EF1%2DB6B7%2D17A0D1320FCE%7D

2.9 NAVSEA 9400.2-M, NAVSEA PIT-Control System

Cybersecurity Implementation Manual, Version 5.0, October 2016;

https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x

0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD

%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D

2.10 NAVSEA INSTRUCTION 9400.2A, NAVSEA Platform Information

Technology-Control Systems Cybersecurity Governance and

Guidance, 20 September 2016;

https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x

0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD

%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D

2.11 SECNAV M-5510.36, Department of the Navy Information

Security Program, June 2006;

https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use%2FVarious%20Classification%20Guides

&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&Vi ew=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D

2.12 US Navy Risk Management Framework Implementation

strategy, 1 February 2017;

https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use&FolderCTID=0x0120001D3A817011E18846

8310622FCCDCF5D8&View={64D3A4AD-0A7C-4941-B568-

78916015EBAD}

https://www.disa.mil/Network-Services/Enterprise-Connections/PPSM https://www.disa.mil/Network-Services/Enterprise-Connections/PPSM https://navsea.navy.deps.mil/hq/00i/ia/RDTE_CandA_KC/default.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FRDTE%5FCandA%5FKC%2FShared%20Documents%2FRMF%20Business%20Rules&FolderCTID=0x0120007ABD9FAD9DD2F841981833BF4D42D983&View=%7B20282DE2%2D6855%2D4EF1%2DB6B7%2D17A0D1320FCE%7D https://navsea.navy.deps.mil/hq/00i/ia/RDTE_CandA_KC/default.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FRDTE%5FCandA%5FKC%2FShared%20Documents%2FRMF%20Business%20Rules&FolderCTID=0x0120007ABD9FAD9DD2F841981833BF4D42D983&View=%7B20282DE2%2D6855%2D4EF1%2DB6B7%2D17A0D1320FCE%7D https://navsea.navy.deps.mil/hq/00i/ia/RDTE_CandA_KC/default.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FRDTE%5FCandA%5FKC%2FShared%20Documents%2FRMF%20Business%20Rules&FolderCTID=0x0120007ABD9FAD9DD2F841981833BF4D42D983&View=%7B20282DE2%2D6855%2D4EF1%2DB6B7%2D17A0D1320FCE%7D https://navsea.navy.deps.mil/hq/00i/ia/RDTE_CandA_KC/default.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FRDTE%5FCandA%5FKC%2FShared%20Documents%2FRMF%20Business%20Rules&FolderCTID=0x0120007ABD9FAD9DD2F841981833BF4D42D983&View=%7B20282DE2%2D6855%2D4EF1%2DB6B7%2D17A0D1320FCE%7D https://navsea.navy.deps.mil/hq/00i/ia/RDTE_CandA_KC/default.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FRDTE%5FCandA%5FKC%2FShared%20Documents%2FRMF%20Business%20Rules&FolderCTID=0x0120007ABD9FAD9DD2F841981833BF4D42D983&View=%7B20282DE2%2D6855%2D4EF1%2DB6B7%2D17A0D1320FCE%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FPIT%20Documentation&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FVarious%20Classification%20Guides&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FVarious%20Classification%20Guides&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FVarious%20Classification%20Guides&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FVarious%20Classification%20Guides&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FVarious%20Classification%20Guides&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7b64D3A4AD-0A7C-4941-B568-78916015EBAD%7d https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7b64D3A4AD-0A7C-4941-B568-78916015EBAD%7d https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7b64D3A4AD-0A7C-4941-B568-78916015EBAD%7d https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7b64D3A4AD-0A7C-4941-B568-78916015EBAD%7d https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7b64D3A4AD-0A7C-4941-B568-78916015EBAD%7d

2.13 NAVSEAINST 5239.2B, Naval Sea Systems Command (NAVSEA)

Cybersecurity Program, 19 January 2018;

https://navsea.navy.deps.mil/field/cnrmc-marmc/1100/cybersecurity/Cybersecurity%20Library/Mock_2

5Feb_IG/NAVSEA-5239.2B.pdf#search=5239%2E2B.

2.14 NIST Special Publication 800-37, Guide for Applying the

Risk Management Framework to Federal Information

Systems, Revision 1, February 2010, Includes Updates as of 06-05-2014;

http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NI

ST.SP.800-37r1.pdf.

2.15 NIST Special Publication 800-53, Revision 4, Security

and Privacy Controls for Federal Information Systems and Organizations, April 2013, Includes Updates as of

01-22-2015;

http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NI

ST.SP.800-53r4.pdf.

2.16 NIST Special Publication 800-53A Revision 4, Assessing

Security and Privacy Controls in Federal Information

Systems and Organizations, 18 December 2014;

http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NI

ST.SP.800-53Ar4.pdf.

2.17 SECNAVINST 5239.3C, Department of the Navy

Cybersecurity Policy, 2 May 2016;

https://doni.documentservices.dla.mil/Directives/05000%

20General%20Management%20Security%20and%20Safety%20Serv ices/05-

200%20Management%20Program%20and%20Techniques%20Service s/5239.3C.pdf.

2.18 SECNAV M-5239.2, Cyberspace Information Technology and

Cybersecurity Workforce Management and Qualification

Manual, June 2016;

https://doni.daps.dla.mil/SECNAV%20Manuals1/5239.2%20(2

016).pdf.

2.19 SPAWAR Memorandum 5000, Ser 5.0/362, 19 April 2016:

Navy Qualified Validator (NQV);

https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Fo rms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fod aa%2FNavy%20Risk%20Management%20Framework%20RMF%2FRefer ences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB2

4AB21C8092BDDC5F94&View={BFB9943D-D8DC-4363-8003-

46D6928A3CB7}.

https://navsea.navy.deps.mil/field/cnrmc-marmc/1100/cybersecurity/Cybersecurity%20Library/Mock_25Feb_IG/NAVSEA-5239.2B.pdf#search=5239%2E2B https://navsea.navy.deps.mil/field/cnrmc-marmc/1100/cybersecurity/Cybersecurity%20Library/Mock_25Feb_IG/NAVSEA-5239.2B.pdf#search=5239%2E2B https://navsea.navy.deps.mil/field/cnrmc-marmc/1100/cybersecurity/Cybersecurity%20Library/Mock_25Feb_IG/NAVSEA-5239.2B.pdf#search=5239%2E2B http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf https://doni.documentservices.dla.mil/Directives/05000%20General%20Management%20Security%20and%20Safety%20Services/05-200%20Management%20Program%20and%20Techniques%20Services/5239.3C.pdf https://doni.documentservices.dla.mil/Directives/05000%20General%20Management%20Security%20and%20Safety%20Services/05-200%20Management%20Program%20and%20Techniques%20Services/5239.3C.pdf https://doni.documentservices.dla.mil/Directives/05000%20General%20Management%20Security%20and%20Safety%20Services/05-200%20Management%20Program%20and%20Techniques%20Services/5239.3C.pdf https://doni.documentservices.dla.mil/Directives/05000%20General%20Management%20Security%20and%20Safety%20Services/05-200%20Management%20Program%20and%20Techniques%20Services/5239.3C.pdf https://doni.documentservices.dla.mil/Directives/05000%20General%20Management%20Security%20and%20Safety%20Services/05-200%20Management%20Program%20and%20Techniques%20Services/5239.3C.pdf https://doni.daps.dla.mil/SECNAV%20Manuals1/5239.2%20(2016).pdf https://doni.daps.dla.mil/SECNAV%20Manuals1/5239.2%20(2016).pdf https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Framework%20RMF%2FReferences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB21C8092BDDC5F94&View=%7bBFB9943D-D8DC-4363-8003-46D6928A3CB7%7d https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Framework%20RMF%2FReferences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB21C8092BDDC5F94&View=%7bBFB9943D-D8DC-4363-8003-46D6928A3CB7%7d https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Framework%20RMF%2FReferences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB21C8092BDDC5F94&View=%7bBFB9943D-D8DC-4363-8003-46D6928A3CB7%7d https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Framework%20RMF%2FReferences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB21C8092BDDC5F94&View=%7bBFB9943D-D8DC-4363-8003-46D6928A3CB7%7d https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Framework%20RMF%2FReferences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB21C8092BDDC5F94&View=%7bBFB9943D-D8DC-4363-8003-46D6928A3CB7%7d https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Framework%20RMF%2FReferences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB21C8092BDDC5F94&View=%7bBFB9943D-D8DC-4363-8003-46D6928A3CB7%7d https://usff.navy.deps.mil/sites/fcc-c10f/odaa/Navy%20Risk%20Management%20Framework%20RMF/Forms/AllItems.aspx?RootFolder=%2Fsites%2Ffcc%2Dc10f%2Fodaa%2FNavy%20Risk%20Management%20Framework%20RMF%2FReferences&PageView=Shared&FolderCTID=0x0120007917A2C2D8CEB24AB21C8092BDDC5F94&View=%7bBFB9943D-D8DC-4363-8003-46D6928A3CB7%7d

2.20 The Joint Travel Regulations, 01 October 2017;

http://www.defensetravel.dod.mil/Docs/perdiem/JTR.pdf.

2.21 Risk Management Framework Process Guide, Version 2.0, 4

August 2017;

https://portal.secnav.navy.mil/orgs/OPNAV/N2N6/DDCION/P olicies/DDCIO(N)%20Guide%20-

%20Risk%20Management%20Framework%20Process%20Guide%20v2

.0.pdf.

2.22 Department of Defense (DoD) Cloud Connection Process

Guide, Version 2, March 2017;

https://www.disa.mil/~/media/Files/DISA/Services/DISN-

Connect/References/CCPG.pdf.

2.23 Research, Development, Test and Evaluation Assessment

and Authorization Policy for Isolated Enclaves, 11

April 2017;

https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use%2FIsolated%20Enclave%20Policy%5FRDT nE&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&

View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D

2.24 NAVY AUTHORIZING OFFICIAL (NAO) GUIDANCE MEMORANDUM;

APPROVAL OF CHANGES TO DEFENSE INFORMATION ASSURANCE

CERTIFICATION AND ACCREDITATION PROCESS (DIACAP)

ACCREDITED SYSTEMS, NETWORKS OR APPLICATIONS 29 Mar https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use%2FUse%20Case%20%2D%20Change%20Reque st&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&

View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D

2.25 NAVY AUTHORIZING OFFICIAL (NAO) GUIDANCE MEMORANDUM;

APPROVAL OF

CHANGES TO RISK MANAGEMENT FRAMEWORK (RMF) AUTHORIZED

SYSTEMS, NETWORKS OR APPLICATIONS 29 Mar 2018 https://navsea.navy.deps.mil/hq/00i/ia/Documents/Forms/

AllItems.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2

FAnA%20News%20You%20Can%20Use%2FUse%20Case%20-

%20Change%20Request&FolderCTID=0x0120001D3A817011E18846

8310622FCCDCF5D8&View=%7B774EBA9B-E274-44EF-B68F-

E1EBF618C563%7D

2.26 NAVSEA Functional Authorizing Official Risk Management

Framework Conversion Process Implementation Guidance, http://www.defensetravel.dod.mil/Docs/perdiem/JTR.pdf https://portal.secnav.navy.mil/orgs/OPNAV/N2N6/DDCION/Policies/DDCIO(N)%20Guide%20-%20Risk%20Management%20Framework%20Process%20Guide%20v2.0.pdf https://portal.secnav.navy.mil/orgs/OPNAV/N2N6/DDCION/Policies/DDCIO(N)%20Guide%20-%20Risk%20Management%20Framework%20Process%20Guide%20v2.0.pdf https://portal.secnav.navy.mil/orgs/OPNAV/N2N6/DDCION/Policies/DDCIO(N)%20Guide%20-%20Risk%20Management%20Framework%20Process%20Guide%20v2.0.pdf https://portal.secnav.navy.mil/orgs/OPNAV/N2N6/DDCION/Policies/DDCIO(N)%20Guide%20-%20Risk%20Management%20Framework%20Process%20Guide%20v2.0.pdf https://www.disa.mil/~/media/Files/DISA/Services/DISN-Connect/References/CCPG.pdf https://www.disa.mil/~/media/Files/DISA/Services/DISN-Connect/References/CCPG.pdf https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FIsolated%20Enclave%20Policy%5FRDTnE&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FIsolated%20Enclave%20Policy%5FRDTnE&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FIsolated%20Enclave%20Policy%5FRDTnE&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FIsolated%20Enclave%20Policy%5FRDTnE&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FIsolated%20Enclave%20Policy%5FRDTnE&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FIsolated%20Enclave%20Policy%5FRDTnE&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20%2D%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20%2D%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20%2D%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20%2D%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20%2D%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Documents/Forms/AllItems.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20-%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B774EBA9B-E274-44EF-B68F-E1EBF618C563%7D https://navsea.navy.deps.mil/hq/00i/ia/Documents/Forms/AllItems.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20-%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B774EBA9B-E274-44EF-B68F-E1EBF618C563%7D https://navsea.navy.deps.mil/hq/00i/ia/Documents/Forms/AllItems.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20-%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B774EBA9B-E274-44EF-B68F-E1EBF618C563%7D https://navsea.navy.deps.mil/hq/00i/ia/Documents/Forms/AllItems.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20-%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B774EBA9B-E274-44EF-B68F-E1EBF618C563%7D https://navsea.navy.deps.mil/hq/00i/ia/Documents/Forms/AllItems.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20-%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B774EBA9B-E274-44EF-B68F-E1EBF618C563%7D https://navsea.navy.deps.mil/hq/00i/ia/Documents/Forms/AllItems.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FUse%20Case%20-%20Change%20Request&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B774EBA9B-E274-44EF-B68F-E1EBF618C563%7D

11 May 2017;

https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use%2FRMF%20Bridge%20Conversion&FolderC

TID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64

D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D

2.27 Navy Security Control Assessor (SCA) Risk Management

Framework (RMF) Assessment and Authorization (A&A)

Testing Guidance Version 1.1, 20 Aug 2018 https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.a spx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20New s%20You%20Can%20Use%2FScans%20-

%20STIGS&FolderCTID=0x0120001D3A817011E188468310622FCCD

CF5D8&View=%7B64D3A4AD-0A7C-4941-B568-78916015EBAD%7D

Note: The applicable documents listed in this Section may be revised, reissued, or superseded throughout the performance of this PWS. When such is the case, the requirements of the superseding document shall take precedence.

3.0 SYSTEM DESCRIPTION/SCOPE

The following sections describe the scope of the system that is to be accredited and scope surrounding the work being requested.

3.1 Keyport Secret Defense Research and Engineering Network (KPT

SDREN) is a secure information network that provides connectivity to other nodes on High Performance Computing Modernization

Program's (HPCMP) SDREN. System environments consist of a collection of like or similar computers located in certified controlled secure spaces. The main network connections are comprised of Ethernet switches and routers connected together over fiber optic, twisted pair cable utilizing authorized National

Security Agency (NSA) Type 1 approved encryption devices. The majority of servers are virtualized using VMware products and virtual desktops are accessed through thin clients. The network and associated system environments operates at the System High

Security mode of operation and at the Secret Classification.

SDREN will allow for added Research Development Test and Evaluation

(SDREN) lab capabilities. The intent is to reduce travel and scheduling costs, add live system testing and communication capabilities for SDREN projects. SDREN will also add to NUWC

Keyport's existing capabilities by linking distributed facilities https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FRMF%20Bridge%20Conversion&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FRMF%20Bridge%20Conversion&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FRMF%20Bridge%20Conversion&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FRMF%20Bridge%20Conversion&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FRMF%20Bridge%20Conversion&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD%2D0A7C%2D4941%2DB568%2D78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FScans%20-%20STIGS&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD-0A7C-4941-B568-78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FScans%20-%20STIGS&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD-0A7C-4941-B568-78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FScans%20-%20STIGS&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD-0A7C-4941-B568-78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FScans%20-%20STIGS&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD-0A7C-4941-B568-78916015EBAD%7D https://navsea.navy.deps.mil/hq/00i/ia/Pages/default1.aspx?RootFolder=%2Fhq%2F00i%2Fia%2FDocuments%2FAnA%20News%20You%20Can%20Use%2FScans%20-%20STIGS&FolderCTID=0x0120001D3A817011E188468310622FCCDCF5D8&View=%7B64D3A4AD-0A7C-4941-B568-78916015EBAD%7D and enabling efficient and effective war fighting capabilities evaluation, testing, and experimentation on an accredited secure encrypted network infrastructure.

SDREN was previously assessed as a security category of Moderate, Moderate, and Low. SDREN is currently accredited through September of 2021. The SDREN spans 4 site locations consisting of Keyport

Washington, Hawaii, Winchelsea Canada, and Zelatched Point Canada.

3.2

The following tables provide additional system details:

Description Quantity

SDREN Users 325

Table 1: Users

Description Quantity

Type 1 Encryptors 10

VM Workstations 40

Scan/Patch/Maintenance 15

Domain Controller 5

L3 Switch Device 8

Infrastructure Router 5

L2 Switch 6

DMZ Switch 4

Perimeter Router 2

Other HW Devices ~60

Total HW Devices ~140

Table 2: Hardware

Description Version

VMware ESXi 6.x

VMware Horizon 7.x

Windows Server 2012/2016

Red Hat Enterprise Linux 7/8

Windows 10

SQL Server 2012/2016

Mozilla Firefox 68.x

Solarwinds 7.0

HBSS 5.X

McAfee 10.x

Java 8.x

Adobe Flashplayer/Reader 32.x/19

MATLAB 9.3

Symantec Backup Exec 2014

Microsoft Office 2013/2016

Other Software Qty: ~56

Table 3: Software

4.0 REQUIREMENTS

The following paragraphs describe A&A support services in detail.

4.1 The Contractor shall provide RMF package creation support.

The Contractor shall fulfill ISSE assignments in accordance with

RMF to assess and authorize new ISs, and re-authorize existing system packages. All ISs included will not have a requirement for any external penetration testing. The Contractor shall deliver

A&A creation of packages; project planning charts; provide presentations on A&A creation; and provide documentation of changes and updates applied to Systems and Networks.

4.2 The Contractor shall have direct knowledge of Enterprise

Mission Assurance Support Service (eMASS) and a minimum of six

(6) years of experience utilizing the Navy’s instance of eMASS.

Additionally, the Contractor shall have performed duties previously as an ISSE for Navy RMF packages, which resulted in the granting of thirty (30) or more Authorities to Operate

(ATOs).

4.3 The Contractor shall adhere to the Navy-specific processes to identify and properly manage the risk of Navy IT in accordance with the DoD Instruction (DoDI) 8510.01, Risk Management Framework

(RMF) for DoD Information Technology (IT), taking into consideration Navy–unique operational and environmental demands detailed in the Department of Navy Risk Management Process Guide and all superseding updates to the document. The Contractor shall follow the published NAVSEA Business Rules (see Section 2) and supplemental NAVSEA Guidance (i.e., NAVSEA A&A News You Can Use notifications). Any conflict between these rules will be resolved by the Command ISSM in coordination with NAVSEA.

4.4 The Contractor shall collaborate with the designated

Authorizing Official (AO) (Navy Authorizing Official (NAO) or

Functional Authorizing Official (FAO)) and/or their representatives for Platform IT (PIT) Afloat, PIT Ashore, RDT&E

Zone A, B, C, D, and Cloud-based environment packages throughout all steps of the RMF process. Collaborate with the designated Naval

Authorizing Official (NAO) and/or their representatives for

Defense Business Systems (DBS), Zone A, Afloat Site, and all packages categorized as HIGH Risk, throughout all steps of the RMF process. The Authorizing Official responsible for package authorization may change at the discretion of the Government.

4.5 The Contractor shall create/develop A&A artifacts including but not limited to: PIT Designation, System Categorization, Security Plan (SP), Implementation Plan, Security Assessment Plan

(SAP), Security Assessment Report (SAR), Privacy Impact Assessment

(PIA), POA&M, Risk Assessment documents, System Level or

Information System Continuous Monitoring (SLCM) Strategy, hardware/software lists, and network/architecture diagrams for all assigned ISs as required by DoD, DON, NAVSEA, NUWC Keyport, and

Navy Enterprise Mission Assurance Support Service (eMASS).

4.6 The Contractor shall collect or conduct vulnerability scans and interpret results with Navy-accepted tools.

4.6.1 The Contractor shall analyze, remediate (after

coordinating with the respective System Administration team or

System Representative), and document vulnerabilities by:

• Performing vulnerability analysis;

• Remediating vulnerabilities posing a corresponding risk to operations (e.g., remove or quarantine); and

• Documenting residual risks into Plan of Action and

Milestones (POA&Ms), Risk Assessments and other applicable documents.

4.6.2 The Contractor shall provide vulnerability scanning

through the Assured Compliance Assessment Solution (ACAS) and

Security Content Automation Protocol (SCAP) of the ISs (or subsequent tools mandated by Authorizing Officials). The

Contractor is not expected to provide any scanning tools or software licenses for this contract. Contractor scans shall either include full authorization boundaries or include sampling of authorization boundaries, as directed by the Government.

4.6.3 The Contractor shall scan and apply remediation (after

coordinating with the respective environment System Administrator or System Representative) in accordance with the Defense

Information Security Agency (DISA) Security Technical

Implementation Guide (STIG), Security Requirements Guide (SRG), Security Readiness Review (SRR), and generate DISA checklists and/or artifacts.

4.6.4 The Contractor shall coordinate and collaborate with the respective System Administrator Team or System Representative before applying mitigation and remediation actions. The

Contractor will ensure mitigation and remediation actions are first applied to a sample environment/asset and receive concurrence from the System Administrator Team or Representative that the sample environment/asset still functions as desired before proceeding with applying remediation to the entire boundary. In the event of technical problems because of remediation (i.e., asset not functioning as desired), the

Contractor will work with the appropriate System Administrator or

Representative to “roll back” any changes and document them accordingly in the POA&M.

4.6.5 The Contractor shall prepare ISs for the authorization

process within the timeframe prescribed by the Command Information

System Security Manager (ISSM). The Contractor shall perform ACAS and SCAP scans, all applicable Security Technical Implementation

Guide (STIG), Security Requirements Guide (SRG), Security

Readiness Review (SRR) checks, DISA checklists, and remediate system assets to acceptable levels as required by the ISSM or respective ISSO. The Contractor shall create all documentation to prove compliance with requirements utilizing eMASS.

4.7 The Contractor shall evaluate all vulnerabilities identified during the A&A processes and recommend mitigation measures for reducing or eliminating identified risk items.

4.7.1 The Contractor shall perform remediation actions after

collaborating with the respective System Administrator or System

Representative for each IS, including STIG/SRG/SRR requirements and/or remediation, ACAS scanning and remediation, eMASS requirements, VRAM maintenance, and security control updates and reconciliation. The Contractor shall perform reconciliation of the POA&M and all applicable documentation based on security scans.

4.7.2 The Contractor shall work with the ISSO and the ISO

to determine and implement (if necessary) fixes/mitigation for weaknesses and to determine the level of revalidation testing that is necessary.

4.8 The Contractor shall address all conditions and or

stipulations identified in ATO and PIT Risk Assessment (PRA) letters.

4.9 The Contractor shall ensure that all cybersecurity

requirements are addressed for A&A package maintenance.

4.10 The Contractor shall update the relevant security artifacts including, but not limited to: the PIT Designation, System

Categorization, Security Plan (SP), Implementation Plan, Security

Assessment Plan (SAP), Security Assessment Report (SAR), Privacy

Impact Assessment (PIA), POA&M, Risk Assessment documents, System

Level or Information System Continuous Monitoring (SLCM) Strategy, hardware/software lists, and network/architecture diagrams based on the results of the continuous monitoring process for all assigned ISs.

4.11 The Contractor shall provide support to the responsible IT

System ISSO or System Representative (as requested) to prepare various documentation to support RMF submissions, various A&A projects, and inspections (i.e., Inspector General) including but not limited to Ports, Protocols, and Services Management (PPMS) registration submission, Tabletop Mission Cyber Risk Assessment

(TMCRA), Conditional Authorization Requests (CARs), Memorandums of

Understanding (MOUs)/Memorandums of Agreement (MOAs), security agreements, Concept of Operations (CONOPS) documents and waivers

(as necessary) to include Public Key Infrastructure (PKI), and

Host Based Solution Services (HBSS)), and DoDIN.

4.12 The Contractor shall assist the Government with determining the security impact of proposed or actual changes to the ISs and their environment of operation.

4.13 The Contractor shall provide support for weekday, weekend and holiday surges in order to maintain operations. The Contractor shall require onsite Contractor employees to maintain work schedule within the 0700 to 1600 timeframe, Monday through Friday, with full-time onsite Contractor employees present between NUWC

Keyport core hours of 0900-1500, excluding Federal Holidays.

4.14 The Contractor shall respond when necessary by phone or e-mail to the Government Technical Points of Contact (TPOCs) or

ISSM requests within one (1) business day.

4.14.1 The Contractor shall respond in writing to all package update requests (made by NAVSEA, NAO, etc.) within two (2) business days.

4.14.2 The Contractor shall make all ISSE required package

updates in accordance with DOD, DON, and NAVSEA requests and requirements within three (3) business days. If more time is required, this must be coordinated with the Government Technical

Points of Contact (TPOCs).

5.0 DELIVERABLES

5.1 The Contractor shall provide the following RMF artifacts as contained in CDRL A001.

a) System Categorization

b) Security Plan (SP)

c) Implementation Plan

d) Security Assessment Plan (SAP)

e) Security Assessment Report (SAR)

f) Privacy Impact Assessment (PIA)

g) POA&M, Risk Assessment documents

h) System Level or Information System Continuous Monitoring

(SLCM) Strategy

i) Hardware/Software lists

j) Network/architecture diagrams

5.2 The Contractor shall provide a draft project management plan

10 business days prior to A&A kickoff meeting for government concurrence as noted in CDRL A002.

5.3 The Contractor shall provide the final project management plan prior to A&A kickoff meeting as noted in CDRL 2.

6.0 Reporting

6.1 The Contractor shall provide a monthly progress report.

6.2 The Contractor shall provide weekly status input.

7.0 SECURITY REQUIREMENTS

The Contractor shall maintain a SECRET facility clearance. All personnel performing work under this contract shall be a US Citizen and have and maintain (minimally) a Department of Defense (DoD)

SECRET security clearance. Personnel security clearances shall be verified by the Contractor in the Joint Personnel Adjudication system (JPAS). On-site personnel shall have a current SECRET clearance at the time of the contract award and shall maintain a

SECRET security clearance. Off-site personnel shall have a SECRET security clearance within 30 days of contract issuance.

7.1 Personnel providing direct support to this effort shall be cleared to the level of SECRET. Access to classified spaces and handling of classified material shall be in accordance with DD

Form 254. For this solicitation, the DD254 requirements are as follows:

7.1.2 DD 254 Block 10e(2) – For performance of this contract, the

Contractor shall require access to Certification and

Accreditation/Assessment and Authorization documentation, and associated documentation up to the Secret level.

7.1.3 DD254 Block 10j - For Official User Only (FOUO) – FOUO

information shall be addressed as described in the FOUO Addendum

(updated 29 Nov 2012) of the DD 254 associated within this solicitation.

7.1.4 DD 254 Block 10k – Personally Identifiable Information (PII) shall be addressed as described in the Personally Identifiable

Information (PII) Addendum (Revised 20130103) of the DD254 associated within the solicitation.

7.1.5 DD 254 Block 11a – The actual performance of this work is at NUWC Keyport.

7.2 Electronic Spillage

7.2.1 Electronic Spillages (ES) are unacceptable and pose a risk to national security. An electronic spillage is defined as classified data placed on an information system (IS), media or hardcopy document possessing insufficient security controls to protect the data at the required classification level, thus posing a risk to national security (e.g., sensitive compartmented information (SCI) onto collateral, Secret onto Unclassified, etc).

The contractor's performance as it relates to ES will be evaluated by the Government. ES reflects on the overall security posture of

NUWC Keyport and a lack of attention to detail with regard to the handling of classified information of IS security discipline and will be reflected in the contractor's performance rating. In the event that a contractor is determined to be responsible for an ES, all direct and indirect costs incurred by the Government for ES remediation will be charged to the contractor.

7.2.2 NUWC Keyport Security will continue to be responsible for the corrective action plan in accordance with the security guidance reflected on the DOD Contract Security Classification

Specification - DD254. NUWC Keyport Security will identify the contractor facility and contract number associated with all electronic spillages during the investigation that involve contractor support. NUWC Keyport Security will notify the

Contracts Division with the contractor facility name and contract number, incident specifics and associated costs for cleanup. The

Contracting Officer will be responsible to work with the Contractor

Facility to capture the costs incurred during the spillage clean

up. The Contractor is also responsible for taking Cyber Awareness

Challenge Training annually, via their Facility Security Officer

(FSO), as part of the mandatory training requirements. If a spillage occurs additional training will be required to prevent recurrence.

7.3 Portable Electronic Devices (PEDs)

7.3.1 Non-government and/or personally owned portable electronic devices (PEDs) are prohibited in all NUWC Keyport buildings with the exception of personally owned cell phones which are authorized for use in spaces up to and including Controlled Access Areas to allow for communications in emergent situations. The Contractor shall ensure that onsite personnel remain compliant with the NAVSEA

INSTRUCTION 2200.1A - NAVSEA Portable Electronic Devices Policy and NUWC Keyport PED policy NUWCKPTINST 5239.16. NUWC Keyport instruction defines PEDS as the following: any electronic device designed to be easily transported, with the capability to store, record, receive or transmit text, images, video, or audio data in any format via any transmission medium. PEDS include, but are not limited to, laptops, radios, compact discs, smart watches, phones, digital voice recorders and cassette players/recorders. In addition, this includes removable storage media such as flash memory, memory sticks, multimedia cards and secure digital cards, micro-drive modules, ZIP drives, ZIP disks, recordable CDs, DVDs, MP3 players, iPADs, digital picture frames, electronic book readers, kindle, nook, cameras, external hard disk drives, and floppy diskettes.

7.3.2 PEDs belonging to an external organization shall not be connected to NUWC Keyport networks or infrastructure without prior approval from the NUWC Keyport Cybersecurity and Command ISSM.

This approval will be granted using the TARIS form and action tracker process.

7.3.3 Personally owned hardware or software shall not be connected or introduced to any NUWC Keyport hardware, network or information system infrastructure.

7.4 Visits by Foreign Nationals and Foreign Representatives

7.4.1 Contract performance may require that the contractor host, at an off-base location, foreign nationals and/or foreign representatives. A foreign national is a person who is a citizen of a foreign nation, and who is not a citizen of the United States.

A foreign representative is a person who represents a foreign interest in dealings with the U.S. Government, either directly or through dealings with a U.S. Government contractor. A foreign representative may be a United States citizen.

7.4.2 NUWC Keyport Foreign Visitor Request Process. The NUWC

Keyport has established a foreign visitor approval process. This process requires the electronic submission of a “Foreign National

Visitor Request Form”. Whenever, pursuant to the terms of this contract, a visit to a contractor facility or contractor workspace by a foreign national…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .