SOW_CRS_Cloud_Hosting_Services_Final.docx
DOCX document 38 KB Posted
- Attached to
- Notice of Sole Source to Cyber Range Solutions Federal contract opportunity
- Solicitation number
- N6227119Q1187
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SSJ_CRS_Cloud_Hosting_KO_Signed_Redacted.pdf | ||
| RFQ_N6227119Q1187.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work Cloud Hosting Services for CY3200 Labs Information Sciences Department Naval Postgraduate School
1.0 Background/Introduction: The Cyber Academic Group (CAG) is intended to be a national resource for the interdisciplinary study and design of secure and resilient cyber systems and the conduct of cyber operations. Its breadth covers all areas of cyber operation, including the incorporation of cyber effects into operational plans and offensive and defensive cyber operations. The CAG’s program is transformative, being interdisciplinary with both technical foundations and non-technical challenges. The nature of the cyber environment, its opportunities and vulnerabilities, and the broad range of potential threats demands a comprehensive, multidisciplinary approach to cyber operations education and research. The Cyber Academic Group’s composition reflects this diversity and includes participating faculty from departments including Computer Science, Defense Analysis, Electrical and Computer Engineering, Information Sciences, Mathematics, and Operations Research.
2.0 Scope: The service contractor shall host virtual labs in a cloud environment.
3.0 Tasks: The contractor shall perform the following tasks as follows:
3.1 Implement lab content on a cloud environment
3.2 Host lab content on the cloud environment
3.3 Prepare implementation documentation for labs to be hosted in the cloud environment
3.4 Prepare a change log of system changes, maintenance, updates, and upgrades
4.0 Deliverables: The contractor shall be responsible for providing the following deliverables:
4.1 Lab content hosted on a cloud environment
4.2 Implementation documentation
4.3 Change log of system changes, maintenance, updates, and upgrades.
Performance Measurement - Quality Assurance Plan
| Task |
| Deliverable that will be inspected |
| Acceptable Quality Level (AQL) |
| Method |
| Frequency |
| 3.1 |
| Lab content hosted on a cloud environment |
| 24/7 access and availability |
| 100% Inspection of Deliverables by the TPOC |
| Periodically throughout the period of performance |
| 3.3 |
| Implementation documentation |
| Professional Quality Materials in the agreed upon format |
| 100% Inspection of Deliverables by the TPOC |
| Upon delivery |
| 3.4 |
| Change Log |
| Professional Quality Materials in the agreed upon format |
| 100% Inspection of Deliverables by the TPOC |
| Per change log entry |
If performance falls below the AQL defined above, the Technical Point of Contact (TPOC) shall document the instance(s), coordinate with the Contracting Officer and advise the Contractor. The Contractor will be requested to review the documentation and provide a written response on how performance will be corrected in the future. Re-performance of any work for failure to perform in accordance with the specified AQL or task requirement shall be completed at the Contractor’s own expense and at no additional cost to the Government.
5.0 Minimum Technical Requirements:
· Dedicated servers to support AWS Cloud services
· AWS Cloud services available 24 hours per day, 7 days per week
· Services to support dynamic and burstable usage
· Services to support a minimum of 7 end users and a maximum of 30 end users
6.0 Period of Performance: 12 months from date of award
7.0 Place of Performance: At Contractor’s site.
8.0 Government Furnished Property: None.
9.0 Travel: None
10.0 Transition Activities: It is essential to the Government that services required under this PWS are performed without interruption. At the conclusion of any performance period, including option periods or extensions, the services provided under this PWS may be awarded to another contractor. The contractor in place shall be required to assist in the transition activities.
11.0 Security Requirements: Contractor Key Personnel must be U.S. Citizens.
Contractors performing on this contract are required to familiarize themselves with, and participate in, the Naval Postgraduate School’s OPSEC program. Must be familiar with and comply with NPSINST 3432.1B, the NPS Critical Information List, DOD Directive 5205.02E and their applicable references. The contractor will be required to complete OPSEC and counter-intelligence training within 30 days of beginning the work, or provide proof of OPSEC and counterintelligence training completed within the previous 12 months. The contractor may not publicly release any information about developmental work or curriculum at NPS without prior written approval from the Principal Investigator (PI).
12.0 Human Subject Research: Contractor personnel performing work under this contract may not support, advise, or conduct research involving human subjects. If at any time during the period of performance of this contract the tasks involve human subject research, the Contractor shall immediately notify the Contracting Officer. The contract must be amended in accordance with DoDD 3216.02 and DFAR 252.235-7004 in the event human subject research is proposed.
13.0 Privacy Act Statement: “Pursuant to Title 5 United States Code 552a(m)(l), the contractor and all employees of the contractor working under this contract are required to comply with the requirements of 5 U.S.C. 552a (“The Privacy Act of 1974”).”
14.0 Identification of Contractor Employees: In accordance with DFAR 211.106, there shall be a clear distinction between Government employees and service contractor employees. Service contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel. Contractor personnel will be required to obtain and wear badges or other visible identification for meetings with Government personnel to provide a clear distinction between service contractor employees and Government personnel. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversations and in formal and informal written correspondence. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.
15.0 Non-Personal Services Statement: Contractor employees performing services under this order will be controlled, directed, and supervised at all times by management personnel of the contractor. Contractor management will insure that employees properly comply with the performance work standards outlined in the SOW. Contractor employees will perform their duties independent of, and without the supervision of, any Government official or other Defense Contractor. The tasks, duties, and responsibilities set forth in the task order may not be interpreted or implemented in any manner that results in any contractor employee creating or modifying Federal policy, obligating the appropriated funds of the United States Government, overseeing the work of Federal employees, or otherwise violating the prohibitions set forth in Parts 7.5 and 37.1 of the Federal Acquisition Regulation (FAR). The Government will control access to the facility and will perform the inspection and acceptance of the completed work.
16.0 SUPTXT 204-9400 Contractor Unclassified Access to Federally Controlled Facilities, Sensitive Information, Information Technology (IT) Systems or Protected Health Information (Jan 2017)
Homeland Security Presidential Directive (HSPD)-12, requires government agencies to develop and implement Federal security standards for Federal employees and contractors. The Deputy Secretary of Defense Directive-Type Memorandum (DTM) 08-006 – “DoD Implementation of Homeland Security Presidential Directive – 12 (HSPD-12)” dated November 26, 2008 (or its subsequent DoD instruction) directs implementation of HSPD-12. This clause is in accordance with HSPD-12 and its implementing directives.
APPLICABILITY
This clause applies to contractor employees requiring physical access to any area of a federally controlled base, facility or activity and/or requiring access to a DoN or DoD computer/network/system to perform certain unclassified sensitive duties. This clause also applies to contractor employees who access Privacy Act and Protected Health Information, provide support associated with fiduciary duties, or perform duties that have been identified by DON as National Security Position, as advised by the command security manager. It is the responsibility of the responsible security officer of the command/facility where the work is performed to ensure compliance.
Each contractor employee providing services at a Navy Command under this contract is required to obtain a Department of Defense Common Access Card (DoD CAC). Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.
ACCESS TO FEDERAL FACILITIES
Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this clause will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Navy Command’s Security Manager upon arrival to the Command and shall out-process prior to their departure at the completion of the individual’s performance under the contract.
ACCESS TO DOD IT SYSTEMS
In accordance with SECNAV M-5510.30, contractor employees who require access to DoN or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to information protected under the Privacy Act, to include Protected Health Information (PHI). All contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than IT-II. IT Levels are determined by the requiring activity’s Command Information Assurance Manager.
Contractor employees requiring privileged or IT-I level access, (when specified by the terms of the contract) require a Single Scope Background Investigation (SSBI) or T5 or T5R equivalent investigation, which is a higher level investigation than the National Agency Check with Law and Credit (NACLC) described below. Due to the privileged system access, an investigation suitable for High Risk national security positions is required. Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance Technical Level 1, and must be trained and certified on the Operating System or Computing Environment they are required to maintain.
Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to IT systems is required for performance of the contractor employee’s duties, such employees shall in-process with the Navy Command’s Security Manager and Information Assurance Manager upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual’s performance under the contract. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The decision to authorize access to a government IT system/network is inherently governmental. The contractor supervisor is not authorized to sign the SAAR-N; therefore, the government employee with knowledge of the system/network access required or the COR shall sign the SAAR-N as the “supervisor.”
The SAAR-N shall be forwarded to the Command’s Security Manager at least 30 days prior to the individual’s start date. Failure to provide the required documentation at least 30 days prior to the individual’s start date may result in delaying the individual’s start date.
When required to maintain access to required IT systems or networks, the contractor shall ensure that all employees requiring access complete annual Information Assurance (IA) training, and maintain a current requisite background investigation. The Contractor’s Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required.
INTERIM ACCESS
The Command's Security Manager may authorize issuance of a DoD CAC and interim access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.
DENIAL OR TERMINATION OF ACCESS
The potential consequences of any requirement under this clause including denial or termination of physical or system access in no way relieves the contractor from the requirement to execute performance under the contract within the timeframes specified in the contract. Contractors shall plan ahead in processing their employees and subcontractor employees. The contractor shall insert this clause in all subcontracts when the subcontractor is permitted to have unclassified access to a federally controlled facility, federally-controlled information system/network and/or to government information, meaning information not authorized for public release.
CONTRACTOR’S SECURITY REPRESENTATIVE
The contractor shall designate an employee to serve as the Contractor’s Security Representative. Within three work days after contract award, the contractor shall provide to the requiring activity’s Security Manager and the Contracting Officer, in writing, the name, title, address and phone number for the Contractor’s Security Representative. The Contractor’s Security Representative shall be the primary point of contact on any security matter. The Contractor’s Security Representative shall not be replaced or removed without prior notice to the Contracting Officer and Command Security Manager.
BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR CONTRACTORS ASSIGNED TO NATIONAL SECURITY POSITIONS OR PERFORMING SENSITIVE DUTIES Navy security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Contractor employees under this contract are recognized as Non-Critical Sensitive [ADP/IT-II] positions when the contract scope of work require physical access to a federally controlled base, facility or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to contractor employees who access Privacy Act and Protected Health Information (PHI), provide support associated with fiduciary duties, or perform duties that have been identified as National Security Positions. At a minimum, each contractor employee must be a US citizen and have a favorably completed NACLC or T3 or T3R equivalent investigation to obtain a favorable determination for assignment to a non-critical sensitive or IT-II position. The investigation consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. Each contractor employee filling a non-critical sensitive or IT-II position is required to complete:
· SF-86 Questionnaire for National Security Positions (or equivalent OPM investigative product)
· Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)
· Original Signed Release Statements
Failure to provide the required documentation at least 30 days prior to the individual’s start date shall result in delaying the individual’s start date. Background investigations shall be reinitiated as required to ensure investigations remain current (not older than 10 years) throughout the contract performance period. The Contractor’s Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required.
Regardless of their duties or IT access requirements ALL contractor employees shall in-process with the Command’s Security Manager upon arrival to the command and shall out-process prior to their departure at the completion of the individual’s performance under the contract. Employees requiring IT access shall also check-in and check-out with the Navy Command’s Information Assurance Manager. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The SAAR-N shall be forwarded to the Navy Command’s Security Manager at least 30 days prior to the individual’s start date. Failure to provide the required documentation at least 30 days prior to the individual’s start date shall result in delaying the individual’s start date.
The contractor shall ensure that each contract employee requiring access to IT systems or networks complete annual Information Assurance (IA) training, and maintain a current requisite background investigation. Contractor employees shall accurately complete the required investigative forms prior to submission to the Command Security Manager. The Command’s Security Manager will review the submitted documentation for completeness prior to submitting it to the Office of Personnel Management (OPM); Potential suitability or security issues identified may render the contractor employee ineligible for the assignment. An unfavorable determination is final (subject to SF-86 appeal procedures) and such a determination does not relieve the contractor from meeting any contractual obligation under the contract. The Command’s Security Manager will forward the required forms to OPM for processing. Once the investigation is complete, the results will be forwarded by OPM to the DoD Central Adjudication Facility (CAF) for a determination.
If the contractor employee already possesses a current favorably adjudicated investigation, the contractor shall submit a Visit Authorization Request (VAR) via the Joint Personnel Adjudication System (JPAS) or a hard copy VAR directly from the contractor’s Security Representative. Although the contractor will take JPAS “Owning” role over the contractor employee, the Navy Command will take JPAS "Servicing" role over the contractor employee during the hiring process and for the duration of assignment under that contract. The contractor shall include the IT Position Category per SECNAV M-5510.30 for each employee designated on a VAR. The VAR requires annual renewal for the duration of the employee’s performance under the contract.
BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR CONTRACTORS ASSIGNED TO OR PERFORMING NON-SENSITIVE DUTIES Contractor employee whose work is unclassified and non-sensitive (e.g., performing certain duties such as lawn maintenance, vendor services, etc.) and who require physical access to publicly accessible areas to perform those duties shall meet the following minimum requirements:
· Must be either a US citizen or a US permanent resident with a minimum of 3 years legal residency in the United States (as required by The Deputy Secretary of Defense DTM 08-006 or its subsequent DoD instruction) and
· Must have a favorably completed National Agency Check with Written Inquiries (NACI) or T1 investigation equivalent including a FBI fingerprint check prior to installation access.
To be considered for a favorable trustworthiness determination, the Contractor’s Security Representative must submit for all employees each of the following:
· SF-85 Questionnaire for Non-Sensitive Positions
· Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)
· Original Signed Release Statements
The contractor shall ensure each individual employee has a current favorably completed National Agency Check with Written Inquiries (NACI) or T1 equivalent investigation, or ensure successful FBI fingerprint results have been gained and investigation has been processed with OPM
Failure to provide the required documentation at least 30 days prior to the individual’s start date may result in delaying the individual’s start date.
* Consult with your Command Security Manager and Information Assurance Manager for local policy when IT-III (non-sensitive) access is required for non-US citizens outside the United States.
Office of Contracting and Logistics Management Revised 04 Aug 17
File details come from the government source that posted it.