PWS.pdf
PDF 125 KB Posted
- Attached to
- AUTOMATED DIVE PROFILE TRANSMISSION AND SYNCHRONIZATION (Auto-DPTS) DEVELOPMENT SUPPORT Federal contract opportunity
- Solicitation number
- N65236-18-Q-8377
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| JUSTIFICATION FOR SOLE SOURCE TO POST.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
[Ver dtd 28 Dec 17] 1 of 13
SECTION C – DESCRIPTION/SPECS/WORK STATEMENT
SPECIFICATIONS/STATEMENT OF WORK/PERFORMANCE WORK STATEMENT
Work under this firm fixed price contract will be performed in accordance with the following description/ specifications/ statement of work (SOW) which herein will be referred to as Performance Work Statement (PWS):
SHORT TITLE: AUTOMATED DIVE PROFILE TRANSMISSION AND SYNCHRONIZATION
(Auto-DPTS) DEVELOPMENT SUPPORT
1.0 PURPOSE
Develop a TRL-6 software prototype in response to the Office of Naval Research (ONR) TechSolutions request TS-00711 for Naval Safety Center and follow-on process for Risk Management Framework (RMF) certification and accreditation (C&A) by Naval Sea Systems Command (NAVSEA).
1.1 SCOPE
This PWS covers software engineering, technical, and management support services to the ONR and Space and Naval Warfare Systems Center Atlantic (SPAWARSYSCEN Atlantic). This support encompasses project support, requirements analysis, and software development for the Auto-DPTS system.
2.0 PLACE(S) OF PERFORMANCE
The contractor shall provide support at the following locations:
a. Rockville, Maryland
b. Arlington, Virginia
c. Norfolk, Virginia
d. Panama City, Florida
2.1 GOVERNMENT FACILITIES
No Government facilities (i.e., office space or lab space) are provided on this contract.
2.2 CONTRACTOR FACILITIES
The contractor can have its facility location anywhere as long as the location does not present a hardship to complete work required on task. The contractor shall have real-time communication between the contractor personnel supporting the efforts and government personnel available at time of award.
3.0 PERFORMANCE REQUIREMENTS
The following paragraphs list all required non-personal services tasks that will be required throughout the contract. The contractor shall provide necessary resources with knowledge and experience as cited in the personal qualification clause to support the listed tasks. Contractors shall perform requirements in accordance with Federal Acquisition Regulation (FAR) and/or Defense Federal Acquisition Regulation Supplement (DFARS) which do not include performance of inherently governmental functions. The contractor shall complete all required tasks while controlling and tracking performance and goals in terms of costs, schedules, and resources.
3.1 PROGRAM MANAGEMENT
[Ver dtd 28 Dec 17] 2 of 13
3.1.1 Program Review Support
3.1.1.1 The contractor shall apply business, financial management, and technical disciplines required to support planning, organizing, staffing, controlling, and leading team efforts in managing the development for Auto-DPTS. The contractor shall apply industry-standard management best practices required to monitor and control development support activities. The contractor must demonstrate sufficient maturity in its processes for configuration management, measurement and analysis, project planning, requirements management, risk management and quality assurance to reduce the risks to cost, schedule and technical performance.
3.1.1.2 The contractor shall provide program management support required to advise and assist the Government regarding management and/or technical issues in order to ensure requirements are met on schedule and within budget. The contractor shall provide project reporting artifacts and information accurately, thoroughly, and in a timely manner. Project artifacts include
Coordinate meetings, attendance of meetings, developing agenda items, attending conferences, generating minutes, tracking action items, and developing work breakdown structure (WBS) and plan of action and milestone (POA&M) as necessary (CDRL A001).
3.1.1.3 The contractor shall assist the Government develop cost, technical, and schedule baselines.
Baseline documentation (CDRL A001) shall be prepared and submitted in the format and within the timeframe agreed to by the Contractor program manager and the Government Representative during the Project Kick-Off meeting.
3.1.1.4 The contractor shall submit on the first Monday of each month, a technical, financial and personnel reporting from the prior month (CDRL A002). The report shall detail technical status to include any risks/issues which may adversely effecting cost and schedule baselines. The report shall provide the Government updated actual and anticipated financial expenditures through the period of performance.
3.2 TECHNICAL SUPPORT
3.2.1 Software Development Plan
3.2.1.1 Contractor shall deliver a proposed Software Development Plan (SDP) (CDRL A003) to the government within 30 days of award. No specific format is required; the document is content driven. The contractor shall place the SDP under configuration control after the final version has been approved by the Government. The document shall be resubmitted for review and government approval when periodic updates are performed.
3.2.1.2 Contractor shall develop software component to automate profile data acquisition from dive computer in accordance with software requirements.
3.2.2 Source Code
3.2.2.1 Contractor shall deliver all source code, intermediate code, executable/compiled code, build files/procedure, and benchmark/test files used to develop and maintain software system/application/tool. (CDRL A004)
3.2.3 Software Documentation
3.2.3.1 Contractor shall document requirements and produce documentation on the IT system architecture requirements for the Auto-DPTS database and web server components. (CDRL A005)
[Ver dtd 28 Dec 17] 3 of 13
3.2.3.2 Contractor shall produce use case documentation of the Auto-DPTS system consisting of Dive Jump Reporting System (DJRS) Data Transfer. (CDRL A005)
4.0 INFORMATION TECHNOLOGY (IT) SERVICES REQUIREMENTS
4.1 INFORMATION TECHNOLOGY (IT) GENERAL REQUIREMENTS
The contractor shall adhere to the following requirements when the IT support services and/or supplies are applicable to the requirement:
4.1.1 Ensure that no production systems are operational on any research, development, test and evaluation (RDT&E) network.
4.1.2 Follow DoDI 8510.01 when deploying, integrating, and implementing IT capabilities.
4.1.3 Work with Government personnel to ensure compliance with all current Navy IT & cybersecurity policies, including those pertaining to Cyber Asset Reduction and Security (CARS).
4.1.4 Follow SECNAVINST 5239.3C & DoDI 8510.01 prior to integration and implementation of IT solutions or systems.
4.1.5 Register any contractor-owned or contractor-maintained IT systems utilized on contract in the Department of Defense IT Portfolio Registry (DITPR)-DON.
4.1.6 Ensure all software recommended, procured, and/or developed is compliant with Section 508 of the Rehabilitation Act of 1973, 26 CFR Part 1194 and pursuant to SPAWARINST 5721.1B.
4.1.7 Only perform IT work specified within the limitations of the contract.
4.2 SOFTWARE DEVELOPMENT/MODERNIZATION AND HOSTING
The contractor shall ensure all programs utilizing this contract for software development/ modernization (DEV/MOD), including the development of IT tools to automate SPAWARSYSCEN Atlantic business processes are compliant with DoN Information Management/Information Technology (DoN IM/IT) Investment Review Process Guidance requirements. Contractors shall neither host nor develop IT tools to automate SPAWARSYSCEN Atlantic business processes unless specifically tasked within the contract. The contractor shall ensure IT tools developed to automate SPAWARSYSCEN Atlantic business processes will be delivered with software documentation (CDRL A005) and source code (CDRL A004) to allow non-proprietary operation and maintenance by any source. The contractor shall ensure all programs are submitted with proof of completed DEV/MOD certification approval from the appropriate authority in accordance with DON policy prior to contract award. (DITPR-DON Update) *Note must be listed on Investment Review Board (IRB) approved list.
4.3 CYBERSECURITY SUPPORT
Cybersecurity (which replaced the term Information Assurance (IA)) is defined as prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation. Contractor personnel shall perform tasks to ensure applications, systems, and networks satisfy Federal/DoD/DoN/Navy Cybersecurity requirements.
4.3.1 Cyber IT and Cybersecurity Personnel
[Ver dtd 28 Dec 17] 4 of 13
4.3.1.1 The Cyberspace workforce elements addressed include contractors performing functions in designated Cyber IT positions and Cybersecurity positions. In accordance with DFARS Subpart 239.71, DoDD 8140.01, SECNAVINST 5239.20A, and SECNAV M-5239.2, contractor personnel performing cybersecurity functions shall meet all cybersecurity training, certification, and tracking requirements as cited in DoD 8570.01-M prior to accessing DoD information systems. Proposed contractor Cyber IT and cybersecurity personnel shall be appropriately qualified prior to the start of the contract performance period or before assignment to the contract during the course of the performance period.
4.3.1.2 Contractors that access Navy IT shall also follow guidelines and provisions documented in Navy Telecommunications Directive (NTD 10-11) and are required to complete a SAAR-N form as documented in Para 8.2.2.4(b).
4.3.1.3 Contractor personnel with privileged access shall acknowledge special responsibilities with a Privileged Access Agreement (PAA) IAW SECNAVINST 5239.20A.
4.3.2 Design, Integration, Configuration or Installation of Hardware and Software The contractor shall ensure any equipment/system installed or integrated into any platform will meet the cybersecurity requirements as specified under DoDI 8500.01. The contractor shall ensure that any design change, integration change, configuration change, or installation of hardware and software is in accordance with established DoD/DoN/Navy cyber directives and does not violate the terms and conditions of the accreditation/authorization issued by the appropriate Accreditation/Authorization official. Contractors that access Navy IT are also required to follow the provisions contained in DON CIO Memorandum: Acceptable Use of Department of the Navy Information Technology (IT). Use of blacklisted software is specifically prohibited and only software that is registered in DON Application and Database Management System (DADMS) and is Functional Area Manager (FAM) approved can be used as documented in Para 4.2.2. Procurement and installation of software governed by DON Enterprise License Agreements (ELAs) – Microsoft, Oracle, Cisco, Axway, Symantec, ActivIdentity, VMware, Red Hat, NetApp, and EMC shall be in accordance with DON CIO Policy and DON ELAs awarded.
4.3.3 Cybersecurity Workforce (CSWF) Report
In accordance with DFARS clause 252.239-7001 and DoD 8570.01-M, the contractor shall identify cybersecurity personnel, also known as CSWF and Cyber IT workforce personnel. The contractor shall develop, maintain, and submit a monthly CSWF Report (CDRL A006) identifying CSWF individuals who are IA trained and certified. Utilizing the format provided in CDRL A006 Attachment 1of Exhibit A, the prime contractor shall be responsible for collecting, integrating, and reporting all subcontractor personnel. See applicable DD Form 1423 for additional reporting details and distribution instructions. Although the minimum frequency of reporting is monthly, the Contracting Officer can require additional updates at any time. Contractor shall verify with the Contracting Officer or Government Representative the proper labor category CSWF designation and certification requirements. The primary point of contact (POC) for all related CSWF questions is the Command CSWF Program Manager (PM) in the office of the SPAWARSYSCEN Atlantic Information Systems Security Manager (ISSM).
4.5.4 Cybersecurity Workforce (CSWF) Designation
CSWF contractor personnel shall perform cybersecurity functions. In accordance with DoD 8570.01- M Information Assurance Workforce Improvement Program Manual, the CSWF is comprised of the following categories: IA Technical (IAT) and IA Management (IAM)); and specialties: Computer Network Defense Service Providers (CND-SPs) and IA System Architects and Engineers (IASAEs).
Based on the IA function provided by the individual, an IA designator is assigned that references an IA category or specialty. The following Labor Categories shall meet the IA Designator, IA Level/Position, and have the estimated Primary/Additional/Embedded hours performing IA duties:
Labor Category Quantity IA IA IA Duty Hours
[Ver dtd 28 Dec 17] 5 of 13
Personnel Designator (Note1)
Level/Position (Note2)
Primary (≥25 hrs)
Additional (15-24 hrs)
Embedded (1-14 hrs)
Computer Programmer (1) IAT Level 3 X
Computer Programmer (1) IAT Level 4 X
5.0 CONTRACT ADMINISTRATION
Administration of the work being performed is required; it provides the Government a means for contract management and monitoring. Regardless of the level of support, the ultimate objective of the contractor is ensuring the Government’s requirements are met, delivered on schedule, and performed within budget.
5.1 CONTRACTING OFFICER REPRESENTATIVE (COR) DESIGNATION
This SAP contract is not technically complex and does not require a COR. A Government Representative will report to the Contracting Officer that all products and/or service from the contractor have been delivered and accepted. The Government Representative for this contract is Lakeisha Williams, phone (843)218-5724 and email lakeisha.d.williams1@navy.mil.
5.2 CONTRACTOR MONITORING AND MAINTENANCE
The contractor shall have processes established in order to provide all necessary resources and documentation during various times throughout the day including business and non-business hours in order to facilitate a timely contract response or modification in particular during urgent requirements.
5.2.1 Contract Administration & Documentation
Various types of administration documents are required throughout the life of the contract. At a minimum, the contractor shall provide the following documentation:
5.2.1.1 Contract Status Report (CSR)
The contractor shall develop a Contract Status Report (CSR) (CDRL A007) and submit it monthly at least 30 days after contract award on the 5th of each month. Only one report is submitted per contract. The prime shall be responsible for collecting, integrating, and reporting all subcontractor reports. The contractor shall report on various contract functions: performance, schedule, financial, business relations, and staffing plan/key personnel. See applicable DD Form 1423 for additional reporting details and distribution instructions.
5.2.1.2 Enterprise-wide Contractor Manpower Reporting Application Pursuant to NMCARS 5237.102-90, the contractor shall report all contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the DoD via a secure data collection website – Enterprise-wide Contractor Manpower Reporting Application (eCMRA). The Product/Service Codes (PSC) for contracted services excluded from reporting are as follows:
(1) W, Lease/Rental of Equipment;
(2) X, Lease/Rental of Facilities;
(3) Y, Construction of Structures and Facilities;
(4) S, Utilities ONLY;
(5) V, Freight and Shipping ONLY.
The contractor shall completely fill-in all required data fields using the following web address:
https://www.ecmra.mil/. Reporting inputs consists of labor hours executed during the task order period of performance within each Government fiscal year (FY) which runs from October 1 through September 30. While inputs may be reported any time during the FY, the contractor shall report all https://www.ecmra.mil/
[Ver dtd 28 Dec 17] 6 of 13 data in the applicable FY no later than October 31 of each calendar year. The contractor shall send notice to the COR and Contracting Officer after the applicable eCMRA data has been successfully entered. For reporting questions, contractors may contact the help desk email accessible through the eCMRA login webpage.
5.2.1.3 WAWF Invoicing Notification and Support Documentation Pursuant to DFARS clause 252.232-7003 and 252.232-7006, the contractor shall submit payment requests and receiving reports using DoD Invoicing, Receipt, Acceptance, and Property Transfer (iRAPT) application (part of the Wide Area Work Flow (WAWF) e-Business Suite) which is a secure Government web-based system for electronic invoicing, receipt, and acceptance. The contractor shall provide e-mail notification to the Government Representative when payment requests are submitted to the iRAPT/WAWF and if requested, the contractor shall include cost back–up documentation (e.g., delivery receipts, time sheets, & material/travel costs, etc.) to the invoice in iRAPT/WAWF. When requested by the Government Representative, the contractor shall directly provide a soft copy of the invoice and any invoice supporting documentation (CDRL A008) directly to the Government Representative within 24 hours of request to assist in validating the invoiced amount against the products/services provided during the billing cycle.
5.3 CONTRACTOR PERFORMANCE MANAGEMENT
In support of tracking contractor performance, the contractor shall provide a Cost and Schedule Milestone Plan (CDRL A002) within 10 days after contract award.
6.0 DOCUMENTATION AND DELIVERABLES
The contractor shall screen all electronic deliverables or electronically provided information for malicious code using DoD approved anti-virus software prior to delivery to the Government.
6.1 CONTRACT DATA REQUIREMENTS LIST (CDRL)
The following listing identifies the data item deliverables required under this contract and the applicable paragraph of the PWS for which they are required. Section J includes the DD Form 1423s that itemize each Contract Data Requirements List (CDRL) required under the contract. The contractor shall establish a practical and cost-effective system for developing and tracking the required CDRLs generated under each task. The contractor shall not develop any CDRL classified TOP SECRET with SCI.
CDRL # Deliverable Title
PWS
Reference Para
Frequency Date Due
A001 Contract Work Breakdown Structure (CWBS)
3.1.1.2,
3.1.1.3 ONE/R
60 days after contract award
(DACA)
A002 Cost and Schedule Milestone Plan
3.1.1.4, 5.3
One time with revisions
(ONE/R)
NLT 10 DACA
revision NLT 7 days after receipt of Govt review
A003 Software Development Plan
(SDP) 3.2.1.1 ONE/R
30 days after contract award
(DACA)
A004 Source Code 3.2.2.1, 4.2
One time with revisions
14 days before completion of contract;
[Ver dtd 28 Dec 17] 7 of 13
CDRL # Deliverable Title
PWS
Reference Para
Frequency Date Due
(ONE/R) revision NLT 7 days after receipt of gov review
A005 Software Documentation 3.2.3.1, 3.2.3.2, 4.2
One time with revisions
(ONE/R)
14 days before completion of contract;
revision NLT 7 days after receipt of gov review
A006 Cybersecurity Workforce (CSWF) Report
4.3.3,
8.2.3.1 MTHLY
30 days after contract award (DACA) and monthly on the 10th
A007 Contract Status Report (CSR) 5.2.1.1,
8.2.3.1 MTHLY
DACA and on the 5th of the applicable month
A008 Invoice Supporting Documentation 5.2.1.3 ASREQ Within 24 hrs from request
6.2 ELECTRONIC FORMAT
At a minimum, the contractor shall provide deliverables electronically by e-mail; hard copies are only required if requested by the Government. To ensure information compatibility, the contractor shall guarantee all deliverables (i.e., CDRLs), data, correspondence, and etc., are provided in a format approved by the receiving Government Representative. The contractor shall provide all data in an editable format compatible with SPAWARSYSCEN Atlantic corporate standard software configuration as specified below. Contractor shall conform to SPAWARSYSCEN Atlantic corporate standards within 30 days of contract award. The initial or future upgrades costs of the listed computer programs are not chargeable as a direct cost to the Government.
Deliverable Software to be used
a. Word Processing Microsoft Word
b. Technical Publishing MS Publisher
c. Spreadsheet/Graphics Microsoft Excel
d. Presentations Microsoft PowerPoint
e. Scheduling Microsoft Word/Excel
7.0 QUALITY
7.1 QUALITY SYSTEM
Upon contract award, the prime contractor shall have and maintain a quality system that meets contract requirements and program objectives while ensuring customer satisfaction and defect-free products/process. The contractor shall have an adequately documented quality system which contains processes, procedures, planning, and all other documentation and data necessary to provide an efficient and effective quality system, which includes an internal auditing system.
[Ver dtd 28 Dec 17] 8 of 13
8.0 SECURITY
8.1 ORGANIZATION
8.1.1 Security Classification
All work performed under this contract is “unclassified.” A facility security clearance (FCL) is not required; therefore, DoD Contract Security Classification Specification, DD Form 254, does not exist.
Pursuant to DoDM 5200.01 – Volume 4, Controlled Unclassified Information (CUI), the contractor shall safeguard any sensitive Government information.
8.2 PERSONNEL
The contractor shall conform to the security provisions of DoDI 5220.22/DoD 5220.22-M – National Industrial Security Program Operating Manual (NISPOM), SECNAV M-5510.30, DoD 8570.01-M, and the Privacy Act of 1974. Prior to any labor hours being charged on contract, the contractor shall ensure all personnel (including administrative and subcontractor personnel) have obtained and can maintain favorable background investigations at the appropriate level(s) for access required for the contract, and if applicable, are certified/credentialed for the CSWF. A favorable background determination is determined by either a Tier 1 (T1) investigation, Tier 3 (T3) investigation, or Tier 5 (T5) investigation and favorable Federal Bureau of Investigation (FBI) fingerprint checks.
Investigations are not necessarily required for personnel performing unclassified work who do not require access to Government installations/facilities, Government IT systems and IT resources, or SPAWARSYSCEN Atlantic information. Cost to meet these security requirements is not directly chargeable to the contract.
NOTE: If a final determination is made that an individual does not meet or cannot maintain the minimum security fitness requirements, the contractor shall permanently remove the individual from SPAWARSYSCEN Atlantic facilities, projects, and/or programs. If an individual who has been submitted for a fitness determination or security clearance is "denied," receives an "Interim Declination," or unfavorable fingerprint, the contractor shall remove the individual from SPAWARSYSCEN Atlantic facilities, projects, and/or programs until such time as the investigation is fully adjudicated or the individual is resubmitted and is approved. All contractor and subcontractor personnel removed from facilities, projects, and/or programs shall cease charging labor hours directly or indirectly on the contract.
8.2.1 Access Control of Contractor Personnel
8.2.2.1 Identification and Disclosure Requirements
Regardless if a contractor is physically located on Government installation or not, the contractor and subcontractor employees shall take all means necessary to not represent themselves as Government employees. All contractor personnel shall follow the identification and Government facility disclosure requirement as specified in contract clause 5252.237-9602, Contractor Identification.
8.2.3 Mandatory Training
Contractor personnel (including subcontractors) shall complete all applicable required mandatory Government training in accordance with COMSPAWARSYSCOM Code 8.0.3.3.0 mandatory training webpage:
https://wiki.spawar.navy.mil/confluence/display/HQ/Employee+Mandatory+Training. Contractors without access to the SPAWAR webpage shall coordinate with the Government Representative concerning mandatory training as listed on the training webpage.
8.2.3.1 The contractor shall be responsible for verifying applicable personnel receive all required training. The contractor shall report individual contractor personnel training status by completing and https://wiki.spawar.navy.mil/confluence/display/HQ/Employee+Mandatory+Training
[Ver dtd 28 Dec 17] 9 of 13 updating the contract status report (CSR) (CDRL A007 Attachment 1 of Exhibit A), Training tab.
For Cybersecurity Workforce (CSWF) contractor personnel, all mandatory cybersecurity training and certifications shall be reported in the CSWF Report (CDRL A006).
8.3 OPERATIONS SECURITY (OPSEC) REQUIREMENTS
Security programs are oriented towards protection of classified information and material. Operations Security (OPSEC) is an operations function which involves the protection of any critical information
– focusing on unclassified information that may be susceptible to adversary exploitation. Pursuant to DoDD 5205.02E and SPAWARINST 3432.1, SPAWARSYSCEN Atlantic’s OPSEC program implements requirements in DoD 5205.02-M – OPSEC Program Manual and SPAWARSYSCENLANTINST 3070.1B. Note: OPSEC requirements are applicable when contract personnel have access to classified information or unclassified Critical Program Information (CPI)/sensitive information.
8.3.1 Local and Internal OPSEC Requirement
Contractor personnel, including subcontractors if applicable, shall adhere to the OPSEC program policies and practices as cited in the SPAWARINST 3432.1 and existing local site OPSEC procedures. The contractor shall develop their own internal OPSEC program specific to the contract and based on SPAWARSYSCEN Atlantic OPSEC requirements. At a minimum, the contractor’s program shall identify the current SPAWARSYSCEN Atlantic site OPSEC Officer/Coordinator.
8.3.2 OPSEC Training
Contractor shall track and ensure applicable personnel receive initial and annual OPSEC awareness training. In addition to online OPSEC training provided through the Total Workforce Management System (TWMS), training may be provided by the Government or a contractor’s OPSEC Manager.
Contractor training shall, as a minimum, cover OPSEC as it relates to contract work, discuss the Critical Information applicable in the contract, and review OPSEC requirements if working at Government facilities. The contractor shall ensure any training materials developed by the contractor shall be reviewed by the SPAWARSYSCEN Atlantic OPSEC Officer, who will ensure it is consistent with SPAWARSYSCEN Atlantic OPSEC policies. OPSEC training requirements are applicable for personnel during their entire term supporting this SPAWARSYSCEN Atlantic contract.
8.3.3 SPAWARSYSCEN Atlantic OPSEC Program
Contractor shall participate in SPAWARSYSCEN Atlantic OPSEC program briefings and working meetings, and the contractor shall complete any required OPSEC survey or data call within the timeframe specified.
8.4 INFORMATION SYSTEM SECURITY
8.4.1 Electronic Communication
The contractor shall have broadband Internet connectivity and an industry standard email system for communication with the Government. The contractor shall be capable of Public Key Infrastructure (PKI) client side authentication to DoD private web servers. Unless otherwise specified, all key personnel on task shall be accessible by e-mail through individual accounts during all hours.
8.4.2 Information Security
Pursuant to DoDM 5200.01, the contractor shall provide adequate security for all unclassified DoD information passing through non-DoD information system including all subcontractor information systems utilized on task. The contractor shall disseminate unclassified DoD information within the scope of assigned duties and with a clear expectation that confidentiality is preserved. Examples of such information include the following: non-public information provided to the contractor, information developed during the course of the contract, and privileged contract information (e.g., program schedules and contract-related tracking).
[Ver dtd 28 Dec 17] 10 of 13
8.4.2.1 Safeguards
The contractor shall protect Government information and shall provide compliance documentation validating they are meeting this requirement in accordance with DFARS clause 252.204-7012. The contractor and all subcontractors shall abide by the following safeguards:
(a) Do not process DoD information on public computers (e.g., those available for use by the general public in kiosks or hotel business centers) or computers that do not have access control.
(b) Protect information by at least one physical or electronic barrier (e.g., locked container or room, login and password) when not under direct individual control.
(c) Sanitize media (e.g., overwrite) before external release or disposal.
(d) Encrypt all information that has been identified as controlled unclassified information (CUI) when it is stored on mobile computing devices such as laptops and personal digital assistants, or removable storage media such as portable hard drives and digital optical disks, using DoD Authorized Data-at-Rest encryption technology. NOTE: Thumb drives are not authorized for DoD work, storage, or transfer. Use GSA Awarded DAR solutions (GSA # 10359) complying with ASD- NII/DOD-CIO Memorandum, “Encryption of Sensitive Unclassified Data-at-Rest on Mobile Computing Devices and Removable Storage.” The contractor shall ensure all solutions meet FIPS 140-2 compliance requirements.
(e) Limit information transfer to subcontractors or teaming partners with a need to know and a commitment to at least the same level of protection.
(f) Transmit e-mail, text messages, and similar communications using technology and processes that provide the best level of privacy available, given facilities, conditions, and environment.
Examples of recommended technologies or processes include closed networks, virtual private networks, public key-enabled encryption, and Transport Layer Security (TLS). Encrypt organizational wireless connections and use encrypted wireless connection where available when traveling. If encrypted wireless is not available, encrypt application files (e.g., spreadsheet and word processing files), using at least application-provided password protection level encryption.
(g) Transmit voice and fax transmissions only when there is a reasonable assurance that access is limited to authorized recipients.
(h) Do not post DoD information to Web site pages that are publicly available or have access limited only by domain or Internet protocol restriction. Such information may be posted to Web site pages that control access by user identification or password, user certificates, or other technical means and provide protection via use of TLS or other equivalent technologies. Access control may be provided by the intranet (vice the Web site itself or the application it hosts).
(i) Provide protection against computer network intrusions and data exfiltration, minimally including the following:
1. Current and regularly updated malware protection services, e.g., anti-virus, anti-spyware.
2. Monitoring and control of inbound and outbound network traffic as appropriate (e.g., at the external boundary, sub-networks, individual hosts) including blocking unauthorized ingress, egress, and exfiltration through technologies such as firewalls and router policies, intrusion prevention or detection services, and host-based security services.
3. Prompt application of security-relevant software patches, service packs, and hot fixes.
[Ver dtd 28 Dec 17] 11 of 13
(j) As applicable, comply with other current Federal and DoD information protection and reporting requirements for specified categories of information (e.g., medical, critical program information (CPI), personally identifiable information, export controlled).
(k) Report loss or unauthorized disclosure of information in accordance with contract requirements and mechanisms.
8.4.2.2 Compliance
Pursuant to DoDM 5200.01, the contractor shall include in their quality processes procedures that are compliant with information security requirements.
9.0 GOVERNMENT FURNISHED INFORMATION (GFI)
Government Furnished Information (GFI) is Government owned intellectual property provided to contractors for performance on a contract. For the purposes of this contract, GFI includes manuals, technical specifications, maps, building designs, schedules, drawings, test data, etc. Depending on information contained in a document, the contractor shall comply with additional controls (e.g., completion of a Non-Disclosure Agreements, etc.) for access and distribution.
GFI is not anticipated on this contract.
10.0 GOVERNMENT PROPERTY
As defined in FAR Part 45, Government property is property owned or leased by the Government which includes Government-furnished (GFP) and Contractor-acquired property (CAP); however, CAP is not applicable on fixed-priced contracts. GFP includes material, equipment, special tooling, and special test equipment.
GFP will not be provided on this contract.
10.1 CONTRACTOR-ACQUIRED PROPERTY (CAP)
As defined in FAR Part 45, CAP is property acquired, fabricated, or otherwise provided by the contractor for performing a contract and to which the Government has title but has not yet performed receipt and acceptance. CAP consists of Contractor-acquired equipment (CAE), Contractor-acquired material (CAM), ST, and STE. CAP is not anticipated on this contract.
11.0 TRAVEL
11.1 LOCATIONS
The contractor shall be prepared to travel to the following locations. Prior to any travel taken in support of this contract, the contractor shall obtain Government Representative or Contracting Officer concurrence.
# Trips # People # Days/Nights From (Location) To (Location) 2 2 5/4 Rockville, MD Panama City, FL 2 2 5/4 Rockville, MD Norfolk, VA
12.0 SAFETY ISSUES
12.1 OCCUPATIONAL SAFETY AND HEALTH REQUIREMENTS
The contractor shall be responsible for ensuring the safety of all company employees, other working personnel, and Government property. The contractor is solely responsible for compliance with the
[Ver dtd 28 Dec 17] 12 of 13
Occupational Safety and Health Act (OSHA) (Public Law 91-596) and the resulting applicable standards, OSHA Standard 29 CFR 1910 (general), 1915 (shipboard/submarine) and 1926 (shore), and for the protection, safety and health of their employees and any subcontractors assigned to the contracts. Without Government assistance, the contractor shall make certain that all safety requirements are met, safety equipment is provided, and safety procedures are documented as part of their quality management system. If performing within Government facilities, contractor shall immediately report any accidents involving Government or contractor personnel injuries or property/equipment damage to the Contracting Officer and Government Representative.
Additionally, the contractor is responsible for securing the scene and impounding evidence/wreckage until released by the Contracting Officer or on-site Government Representative.
13.0 SUBCONTRACTING REQUIREMENTS
The contractor shall identify the use of all subcontractors throughout the performance of the contract.
14.0 ACCEPTANCE PLAN
Inspection and acceptance is performed by the Government Representative on all services, data, and non-data deliverables who will report findings to the Contracting Officer.
15.0 OTHER CONDITIONS/REQUIREMENTS
“No other conditions or requirements are applicable.”
16.0 APPLICABLE DOCUMENTS
The contractor shall ensure all work accomplished utilizes the latest, relevant industry practices and standards when applicable unless otherwise indicated by text. In accordance with Defense Acquisition Policy, maximum utilization of non-Government standards will be made wherever practical.
16.1 REQUIRED DOCUMENTS
The contractor shall utilize the following mandatory documents in support of this contract. The documents referenced in this paragraph list the minimum version dates;
however, the contractor shall meet requirements for any referenced document including subsequent updates applicable at time the contract request for proposal is posted.
Document Number Title
a. DoDM 5200.01 DoD Manual – Information Security Program Manual dtd 24 Feb 12
b. DoDD 5205.02E DoD Directive – Operations Security (OPSEC) Program dtd 20 Jun 12
c. DoD 5205.02-M DoD Manual – Operations Security (OPSEC) Program Manual dtd 3 Nov 08
d. DoD 5220.22-M DoD Manual – National Industrial Security Program Operating Manual (NISPOM) dtd 28 Feb 06
e. DoDI 5220.22 DoD Instruction – National Industrial Security Program (NISP) dtd 18 Mar 11
f. DoDD 8140.01 DoD Directive – Cyberspace Workforce Management dtd 11 Aug 15
g. DoDI 8500.01 DoD Instruction – Cybersecurity dtd 14 Mar 14
h. DoDI 8510.01 DoD Instruction – Risk Management Framework
[Ver dtd 28 Dec 17] 13 of 13
Document Number Title (RMF) for DoD Information Technology (IT) dtd 12 Mar 14
i. DoD 8570.01-M
DoD Manual – Information Assurance Workforce Improvement Program dtd 19 Dec 05 with Change 3 dtd 24 Jan 12 and Change 4 dtd 10 Nov 15 (and subsequent replacement)
j. SECNAV M-5239.2 Secretary of the Navy Manual – DON Information Assurance Workforce Management Manual dtd May 2009 (and subsequent revisions)
k. SECNAVINST 5239.3C Secretary of the Navy Instruction – DoN Cybersecurity Policy dtd 2 May 16
l. SECNAVINST 5239.20A Secretary of the Navy Instruction – DoN Cyberspace IT and Cybersecurity Workforce Management and Qualification dtd 10 Feb 16
m. SPAWARINST 3432.1 Space and Naval Warfare Instruction – Operations Security (OPSEC) Policy dtd 2 Feb 05
n. SPAWARINST 5721.1B Space and Naval Warfare Instruction – Section 508 Implementation Policy dtd 17 Nov 09
o. SPAWARSYSCENLANT
INST 3070.1B
Space and Naval Warfare Systems Center Atlantic Instruction – Operations Security Policy dtd 20 Jan 17
p. Navy Telecommunications Directive (NTD 10-11) System Authorization Access Request (SAAR) - Navy
q. Privacy Act of 1974 United States federal law, Pub.L. 93–579, 88 Stat.
1896, dtd December 31, 1974, 5 U.S.C. § 552a
16.2 GUIDANCE DOCUMENTS
The contractor shall have knowledge and utilize the following guidance documents in support of this contract. The documents referenced in this paragraph list the minimum version dates;
however, the document’s effective date of issue is the contract’s request for proposal issue date.
16.3 SOURCE OF DOCUMENTS
The contractor shall obtain all applicable documents necessary for performance on this contract. Many documents are available from online sources. Specifications and commercial/industrial documents may be obtained from the following sources:
Copies of Federal Specifications may be obtained from General Services Administration Offices in Washington, DC, Seattle, San Francisco, Denver, Kansas City, MO., Chicago, Atlanta, New York, Boston, Dallas and Los Angeles.
Copies of military specifications may be obtained from the Commanding Officer, Naval Supply Depot, 3801 Tabor Avenue, Philadelphia, PA 19120-5099. Application for copies of other Military Documents should be addressed to Commanding Officer, Naval Publications and Forms Center, 5801 Tabor Ave., Philadelphia, PA 19120-5099.
All other commercial and industrial documents can be obtained through the respective organization’s website.
LIST OF EXHIBITS & ATTACHMENTS
Exhibit A -- CDRLs - DD FORM 1423 Attachment 1 – Quality Assurance Surveillance Plan (QASP)
File details come from the government source that posted it.