N65540-15-T-5128-0001.pdf
PDF 73 KB Posted
- Attached to
- Certification and Accreditation Packages Federal contract opportunity
- Solicitation number
- N65540-15-T-5128
About this file
This amendment is to answer questions from prospective offerors and extend the due date to 3/20/15.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions_from_Prospective_Offerors_2.pdf | ||
| DD_1423s_-_N65540-15-T-5128.pdf | ||
| N65540-15-T-5128.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print)
30-105-04EXCEPTION TO SF 30
APPROVED BY OIRM 11-84
STANDARD FORM 30 (Rev. 10-83) Prescribed by GSA
FAR (48 CFR) 53.243
The purpose of this amendment is to:
1) Answ er questions from Prospective Offerors
2) Delete SOW requirement to have experience w ith 50 C&A Packages in last tw o years
3) Add Notes on the submission and format of offers
4) Extend the due date for offers to 20 March 2015 at 2:00 PM EST
1. CONTRACT ID CODE PAGE OF PAGES
J 1 14
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)
16C. DATE SIGNED
BY 18-Mar-2015
16B. UNITED STATES OF AMERICA15C. DATE SIGNED15B. CONTRACTOR/OFFEROR
(Signature of Contracting Officer)(Signature of person authorized to sign)
8. NAME AND ADDRESS OF CONTRACTOR (No., Street, County, State and Zip Code) X N65540-15-T-5128
X 9B. DATED (SEE ITEM 11)
25-Feb-2015
10B. DATED (SEE ITEM 13)
9A. AMENDMENT OF SOLICITATION NO.
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offer X is extended, is not extended.
Offer must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended by one of the following methods:
(a) By completing Items 8 and 15, and returning copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;
or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN
REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.
IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE
CONTRACT ORDER NO. IN ITEM 10A.
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(B).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority)
E. IMPORTANT: Contractor is not, is required to sign this document and return copies to the issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
10A. MOD. OF CONTRACT/ORDER NO.
2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO.(If applicable)
6. ISSUED BY
3. EFFECTIVE DATE
18-Mar-2015
CODE
NAVAL SURFACE WARFARE CENTER CARDEROCK
CODE 02231, MICHAEL NOLAN
215-897-8914, MICHAEL.D.NOLAN@NAVY.MIL
5001 S BROAD STREET
PHILADELPHIA PA 19112-1403
N65540 7. ADMINISTERED BY (If other than item 6)
4. REQUISITION/PURCHASE REQ. NO.
CODE
See Item 6
FACILITY CODECODE
EMAIL:TEL:
N65540-15-T-5128
SECTION SF 30 BLOCK 14 CONTINUATION PAGE
SUMMARY OF CHANGES
SECTION SF 1449 - CONTINUATION SHEET
SOLICITATION/CONTRACT FORM
The required response date/time has changed from 18-Mar-2015 02:00 PM to 20-Mar-2015 02:00 PM.
The following have been added by full text:
PROSPECTIVE OFFEROR QUESTIONS
Questions from Prospective Offerors N65540-15-T-5128 (C&A Packages). Proposed questions are in black font and the Government’s answers are included in red font.
1. Is there an incumbent contractor for this work? Yes If so, please provide the name of the contractor and the contract number? The work is currently being performed by CSC
(N00178-04-D-4030-EH02)
2. Are all systems included under the scope of this SOW co-located within the same geographic location? (i.e., same military installation, same building, same operational space) Yes, same installation.
3. Would the contractor be able to leverage reciprocity among the various systems? (i.e., physical security, continuity of operations, configuration management) Physical Security
– Yes, physical security should be the same across all packages. Continuity of operations and configuration management, no. 65 % of the systems are stand-alone enclaves so continuity of operations and configuration management are typically system specific.
4. Is the contractor responsible for development of systems processes and procedures or will this information be provided as part of the C&A package development? Yes. There will be cases when the systems need assistance with process development, ie: configuration management, contingency planning, back up process, etc. The contractor must be cognizant of current DOD/DON policies for requirements required for DIACAP/RMF.
5. Are the system administrators currently maintaining the information systems under the scope of this SOW, including but not limited to vulnerability management, patch management, incident response, media protection, account management? Some system administrators execute these functions effectively and some need assistance.
6. Are the systems under the scope of the SOW only RTD&E systems? No. A small percentage is considered operational/ODAA systems or PIT.
7. Are there any platform IT or Platform IT interconnections as part of the scope of the SOW? Yes. A small percentage are considered PIT packages.
8. Does the command have preferred templates for C&A packages? Yes. Templates are either official templates from the ODAA/NAVSEA or Command developed.
9. Will all C&A packages be included in eMass? Yes If so, who is responsible for eMass population? The awardee is responsible for performing ISSE functions within eMass.
This would include working with system POCs to test all IA control assessment procedures, artifact upload and mapping, DIP population, POAM population and additional tasks as defined in FLTCYBERCOM’s eMass user guide for Information System Security Engineer (ISSE).
10. Who is responsible for scheduling the IV&V for certification prior to accreditation decision? NSWC Philadelphia Division’s head of risk and policy section will coordinate and schedule with the contractor when IV&V will be performed for any given package.
11. If excessive non-compliant controls/configurations/policies/procedures are discovered in the development of C&A packages that might prevent the issuance of an ATO, is the contractor responsible for remediation of non-compliant controls as part of the development of C&A documents? The contractor will work with system POCs to test all IACs and document all deficiencies. If an excessive amount of non-compliance is found, the contractor will work with the POCs, IAM and the Validator to mitigate/remediate to the fullest extent possible. Keep in mind, the C&A effort is a snap shot in time so certain things can be fixed at that time and some cannot. The contractor will be responsible for documenting all ongoing deficiencies in the POAM.
12. When are questions due? No More questions will be accepted after 3/18 at 4:00 PM EST.
13. Can the Government provide details around proposal preparation and format instructions, specifically regarding the following:
a. How does the Government want volumes separated? Volumes should be separated by Cost and Corporate Experience.
b. Will Past performance be a separate volume? Past Performance is not an evaluation factor for this procurement.
c. What are the minimum and maximum numbers of Past Performances a Contractor may submit? Past Performance is not an evaluation factor for this procurement.
d. Can the prime use a major teaming partner’s past performance? Past Performance is not an evaluation factor for this procurement.
e. What is the page limit per volume? Cost volume should be no more than 5 pages and Corporate Experience Volume should be no more than 25 pages. (30 Pages total)
f. Does the Government have any formatting requirements (i.e., font size and type, margins, spacing, single-sided v. double-sided pages, etc.)? Please see the notes section that includes formatting information.
g. Are any items excluded in the page count (i.e., résumés, compliance matrices, lists of figures, etc.)? All items are included in the page count.
h. Are there any other requirements/instructions not addressed in the above questions that the Contractor should be aware of? No.
14. The DD1423 (CDRL list) has a column 16 (remarks) that refers to an SOW and page numbers. It does not appear to line up with the solicitation document names N65540-15-T-5128.pdf. Is there an SOW that aligns back to the references made in the DD1423? The SOW is included on pages 77-85 of Solicitation N65540-15-T-5128.
15. Is there an incumbent performing this work currently? Yes Are they eligible to compete for this work? All small businesses which meet the small business set aside requirements for this procurement are eligible to compete for this work.
16. What level of clearance is required for personnel? Secret clearance
17. What are certification requirements for 8570 levels? At a minimum, IAT I to work on desktops, IAT II to perform work on servers.
18. What is a small package quantified as? Dependent on level of effort, typically 1-5 assets, containing only one operating system. There are currently no small packages identified in the
SOW.
19. What is a medium package quantified as? Dependent on level of effort, typically 6 - 19 assets, potentially containing multiple operating systems.
20. What is a large package quantified as? Dependent on level of effort, typically 20+ assets, potentially containing multiple operating systems.
21. Where are the packages currently at in the accreditation/authorization cycle? Various stages;
most are in the certification process.
22. Are identified roles from RMF filled? In process, will transition current roles under DIACAP to
RMF roles once directed to do so.
23. How many packages have been transitioned to RMF? None. The Command has not yet been directed to use RMF.
24. How many packages are expiring in the next six months? None.
25. What tool(s) is/are currently used to document DIACAP packages? eMass and various document templates.
26. What tool(s) is/are currently used to document RMF packages? The Command has not yet been directed to use RMF. Will use eMass when directed to do so.
27. What tool(s) is/are used for network interrogation and scanning compliance? Alloy Navigator, ACAS, SCAP SCC, STIGs (manual checks), IA control testing.
28. What baselines are used for OS, applications for documentation? Most environments mock ship configurations so they build their own baselines/images within their environments.
29. Is there a Change Configuration Board that is currently in place? Some packages have a formal CCB in place, some have informal change management.
30. Are these systems stand-alone systems or located on the DREN? 8 packages are GIG connected, the rest are stand-alone.
31. Are any of these systems on NIPR? 8 packages are GIG connected, the rest are stand-alone.
32. Is there an ATO in place? Yes, a percentage of the systems have an ATO in place When do they expire? December 2015 Type or enclave accreditation? There are no type accreditations
33. Transition to RMF or all new RMF packages? Currently the Command has been directed to use DIACAP, not RMF.
34. We understand the government’s requirement that the contractor shall have current experience and expertise in completing 50 C&A Packages in the last 2 years. Please confirm that this requirement can be met by the contractor and it’s first tier sub-contractors experience. This requirement is hereby removed from the Statement of Work.
Please refer to 52.212-2 Evaluation – Commercial Items for information on Corporate Experience.
35. Page 79 Section 3. Specific Requirements - The contractor shall furnish personnel, material, computer equipment (laptops), services and facilities required to perform defined tasks. The following are descriptions of the specific areas of performance under this contract.
i. Can the Government please clarify this statement? Statement is clear on its face.
j. Will the equipment once provided (purchased for the project) be considered
Government Furnished Equipment (GFE) and an ODC cost to the contract since it is assumed they will connect to Government networks? Contractors may use their own laptops, however laptops must be scanned and review pre and post processing to ensure compliance. Also, no data may be stored or processed on contractor servers/systems not reviewed and approved by Command IAM.
k. How much of the C&A work would be conducted off-site, since it is assumed all documentation is to be stored on Government networks and systems in Government facilities? All artifacts must be stored in eMASS which can be accessed offsite, but all data must be stored and process on reviewed and approved devices. Some test information may be restricted to on-site access as well. Physical and logical access to the systems under certification will be restricted to on-site personnel.
36. Has a contract type been determined for this acquisition? The resultant contract will be a Firm Fixed Price contract.
37. Is there a page limit on the proposal? There should be no more than 5 pages in the cost volume and no more than 25 pages for the Corporate Experience volume. This equates to a total of 30 pages maximum.
38. How many volumes are required? Technical Volume? Cost Proposal? There are two volumes required. 1) Cost proposal 2) Corporate Experience.
39. Is this open market? Or is a contract vehicle required? If so, which one? A contract will result from this solicitation.
The following have been modified:
NOTES
In addition to pricing, prospective offerors should submit proposals that include Corporate Experience in providing C&A Packages as stated in RFQ provision 52.212-2. Offerors should pay close attention to RFQ provision 52.212-2 when submitting offers. Offerors may be considered non-responsive for failure to submit offers in accordance with RFQ provision 52.212-2.
Submission of Offers All offers are due by Friday March 20, 2015 at 02:00 PM EST either electronically or by mail. Electronic offers can be sent to Mr. Mike Nolan at michael.d.nolan@navy.mil. Offers submitted by mail should be sent to:
Mike Nolan (Code 02321) Naval Surface Warfare Center, Carderock Division 5001 S. Broad Street Philadelphia, PA 19112 Any offer received after the aforementioned due date shall be considered non-responsive.
Format of Offers Offers should be submitted in two (2) volumes: 1) Cost 2) Corporate Experience. The cost volume should not exceed five (5) pages and the Corporate Experience volume should not exceed 25 pages. The overall offer should not exceed 30 pages in total. The narrative material in the proposal shall be single spaced, typed on one side of the page only with type no smaller than 12 point characters and 1 inch margins. A page is defined as one side of a sheet 8 1/2 inches by 11 inches.
STATEMENT OF WORK
STATEMENT OF WORK
DOD INFORMATION ASSURANCE CERTIFICATION & ACCREDITATION
PROCESS (DIACAP) SERVICES/ RISK MANAGEMENT FRAMEWORK (RMF)
1. INTRODUCTION
The purpose of this Task Order is to provide support for DOD Information Assurance Certification & Accreditation Process (DIACAP)/Risk Management Framework (RMF) activities at the Naval Surface Warfare Center (NSWC), Philadelphia, PA.
This Statement of Work requires the contractor to create and deliver 21 C&A packages for Naval Surface Warfare Center, Philadelphia, PA. Optional quantities of 10 C&A packages (8 Medium; 2 large) may be added upon completion of the first 21 packages.
The details provided below are presented to give the contractor an overview of the requirements associated with providing required support.
The creation of the C&A packages fall into two categories: medium size (complexity) and large size (complexity). Medium size (complexity) packages are typically comprised of one operating system.
Large size (complexity) packages are typically comprised of two or more operating systems and contain a mix of workstations and servers.
The estimated number of C&A packages and complexity are:
Medium C&A Packages = 16 Large C&A Packages = 5 Total C&A Packages = 21
2. APPLICABLE DOCUMENTS
Current acquisition regulations, business practices, and DIACAP document requirements, contained in relevant DoD/DoN instructions apply. The following documents form a part of this SOW to the extent specified, herein.
In addition to DIACAP C&A requirements, the DoD Instruction 8510.01, Subj: Risk Management Framework (RMF) for DoD Information Technology (IT) dated 12 March 2014 takes effect per NAVSEA guidance.
• Certification and Accreditation (C&A) Requirements for DoD-wide Managed Enterprise Services Procurements, DoD Chief Information Officer memorandum dated Jun 22, 2006
• DON CIO Memo 01-09, Information Assurance Policy for Platform Information Technology dated 30 Jan 2009
• NAVSEAINST 9400.2, Implementation of Naval Sea Systems Command (NAVSEA) Afloat Information Assurance (IA) Governance and Guidance dated 18 Aug 10
• DoDD 8500.01x, Information Assurance
• DoDI 8500.2x, Information Assurance Implementation
• DODI 8510.01, DoD Information Assurance Certification and Accreditation Process (DIACAP) dated 28 Nov 2007
• DODD 8570.01, Information Assurance Training, Certification, and Workforce Management
• DoD 8570.01-M, Information Assurance Workforce Improvement Program
• NIST 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems, May 2004
• Navy Certification Agent Qualification Standards and Registration Guidebook, v.
• OPNAV 5239.3B, DON IA Policy dated 17 June 2009
• CARDEROCKDIVINST 5239.6B, Use of portable electronic devices (PEDs) at the Naval Surface
Warfare Center, Carderock Division (NSWCCD) dated 9 Jul7 2010
• NAVSEA 5239.2A, NAVSEA IA Program dated 15 Dec 2008
• DoD Instruction 8510.01, Subj: Risk Management Framework (RMF) for DoD Information Technology (IT) dated 12 March 2014
3. SPECIFIC REQUIREMENTS
The contractor shall furnish personnel, material, computer equipment (laptops), services and facilities required to perform defined tasks. The following are descriptions of the specific areas of performance under this contract.
CDRL A001 and A002 – Status Reports and Progress Briefings
Status Reports - The contractor shall submit monthly status reports. The report shall include, at a minimum, an assessment of technical status, schedule status, completion status, any travel conducted and any contractor concerns or recommendations for the previous month’s period.
Progress Briefings -The contractor shall provide progress briefings monthly to the CIO and upper management. Briefings shall be in Power Point and provide monthly progress reports, scheduling, program reviews, proposals, and/or issues.
CDRL A003 – Plan of Actions and Milestones (POA&M)
The contractor shall submit a Plan of Action and Milestones to the CIO and TPOC. The POAM shall include project goals and objectives, work breakdown structure, description of milestones and deliverables, schedule for deliverables including interim and formal reviews, and project risks and mitigation strategies.
CDRL A004 – Complete C&A Packages
The contractor shall provide the necessary labor for DIACAP and RMF support to create and deliver 21 C&A packages at Philadelphia, PA. Optional quantities of C&A packages may be added upon completion of the first 21 packages. DIACAP and RMF establish a certification and accreditation process to manage the implementation of information assurance capabilities and services and provide visibility of accreditation decisions regarding the operation of Department of Defense (DoD) information systems.
The intended result is obtaining Authorization to Operate (ATO). C&A is required for connection to DoD, and other Federal systems, networks, and applications.
DIACAP and RMF are processes that include numerous supporting technologies. IA personnel shall adhere to DoDD 8570.01 and the Navy Certification Agent Qualification Standards and Registration Guidebook in performing these tasks.
In addition, to DIACAP C&A requirements, the DoD Instruction 8510.01, Subj: Risk Management Framework (RMF) for DoD Information Technology (IT) dated 12 March 2014 takes effect per NAVSEA guidance.
Creation of C&A Packages includes:
1. Review RDT&E and Business IT Systems Inventory at Philadelphia, PA for possible consolidation. The contractor shall review RDT&E and Business IT Systems at Philadelphia against DIACAP and the Naval Sea Systems Command (NAVSEA) IA Boundary requirements to recommend any possible consolidation of DIACAP packages prior to C&A package development and submission to NAVSEA.
2. Generate C&A Documentation to achieve ATO for each C&A Package. The contractor shall generate the C&A documentation required to meet DIACAP requirements, submit the C&A required documentation to the relevant Designated Navy Validator / IAM and gain ATO. The contractor shall perform the following (but are not limited to the following to achieve ATO):
a. Generate the C&A Plan – develop documents for the DIACAP documentation packages that meet all DoD / Defense Information Systems Agency (DISA) / Department of the Navy (DoN) requirements tailored to a specific associated system. This includes all supporting DIACAP documentation such as: contingency plan, incident response plan, IAVM plan, etc. Also, combine all artifacts and prepare/deliver project management documents for supporting project with timelines and POAMs.
b. Generate Risk Assessments.
c. Generate DIACAP components and artifacts required for the various aspects of the C&A process. These components include, but are not limited to, DIACAP Implementation Plans (DIP), System Identification Plan (SIP), drawings, and Plans of Action and Milestones (POA&M).
3. Assist in Certification Test and Evaluation (CT&E). The contractor will work with system administrators to accomplish CT&E activities. The contractor shall assist the CT&E activities required for IT assets for all C&A packages, including but not limited to the following:
a. Generate Security Certification Test and Evaluation (CT&E) Plan – to test the capability of the associated system implementation to eliminate or mitigate the potential security vulnerabilities. The CT&E Plan must meet all DIACAP requirements and must ensure that all system security measures are demonstrated.
b. Conduct Certification Analyses – perform detailed certification analysis of the software/hardware associated with the system and component. The analysis shall include system architecture analysis, software design analysis, network connection rule compliance analysis, integrity analysis of integrated products, life-cycle management analysis, and vulnerability assessment. Based on this analysis, the contractor shall identify, remediate and mitigate security vulnerabilities resulting from the software development tools used, operating system deficiencies, and the actual software implementation. The contractor shall create and maintain a vulnerability Navy eMASS POAM for systems. The contractor shall have access to the Navy eMASS system classified and unclassified.
4. Provide training on scanning tools and checklists. The contractor shall provide training to Philadelphia System Administrators and Information Assurance Officers on scanning tools, such as: Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP), DISA Security Technical Implementation Guide (STIG) tools and checklists currently being utilized at Philadelphia for all Research Development Test and Evaluation (RDT&E) IT Systems in Philadelphia labs. The contractor shall demonstrate tools, including those scripts the contractor utilizes, used for development of C&A DIACAP packages. The Government shall retain ownership of the checklists and vulnerabilities.
Submit Completed C&A Packages to Navy Validator
The contractor shall work with the Government appointed Navy Validator consistently throughout the C&A package creation and process. The contractor shall inform the Navy Validator when artifacts are produced. The contractor shall submit completed C&A Packages to the Government appointed Navy Validator to validate all C&A Packages. During Validation, the Government appointed Navy Validator shall return C&A package to the contractor for any changes, if necessary, or to submit to NAVSEA for ATO. In addition, the contractor shall participate in all Collaboration meetings with SMEs/TPOC/ and government points of contact.
CDRL A005 – Formal Out-Brief
The contractor shall present and submit a formal out-brief to the CIO, TPOC, IAM and SME government stakeholders. During the formal out-brief, the contractor shall be prepared to present and address any findings/mitigation reports, POAMs, and any recommendations.
4. Travel/CAC/Equipment
Contractor travel maybe required. The contractor shall supply all necessary qualified personnel, technical services, materials, and necessary travel in support of the requirements. The contractor shall perform work in support of this contract at Naval Surface Warfare Center, Philadelphia, PA with travel as needed.
The contractor shall provide sufficient management and technical support staff to develop required plans and implement and execute project/task activities. The contractor must obtain Common Access Cards (CACs) for all employees.
The contractor shall provide hardware, equipment and laptops/computers to perform required tasks. The contractor shall follow NSWC Philadelphia, PA IAM approval process for any hardware that maybe connected to the network. The government shall provide the software such as SCAP, etc.
5. CYBER SECURITY/IAWF PROGRAM
The contractor shall abide by the DoD 8570.01-M, Information Assurance Workforce Improvement Program, and SECNAV 5239.2, DON IAWF Management Manual to support the Cybersecurity/IAWF Program. Contractors performing IA functions must be meet all qualification requirements for their duties, which may include both an IA baseline certification and operating system (OS)/Computing Environment (CE) certification requirements.
CDRL A006 – Proof of Certification.
The contractor shall provide proof of IAM/IAT Level I-III certification for each contractor personnel assigned. The Contractor shall ensure that personnel have the proper and current information assurance certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. The contractor shall ensure that cybersecurity/IA contractor personnel are appropriately certified and maintain current Continuing Professional Education (CPE) requirements as a condition of employment.
Upon hire all contractor personnel assigned the IAM/IAT Level I-III position shall sign the Information System Privileged Access Agreement and Acknowledgement of Responsibilities statement.
Contractor personnel who do not have proper and current certifications shall be denied access to DoD/DON information systems for the purpose of performing information assurance functions.
The contractor shall employ as direct labor in the performance of work only personnel fully qualified and competent to perform the assigned duties. The contractor shall employ as direct labor in the performance of work personnel fully qualified as Validators. Employed Validators will eliminate C&A Package re-work and will expedite the C&A Package creation and delivery to the SME/TPOC.
Cybersecurity/IAWF Certification requirements must be met as a condition of hire and must be maintained over the course of this contract. Cybersecurity/IAWF Certifications, CE and CPE requirements must be kept current and in accordance with Navy and DoD policies and is the responsibility of the contractor.
5. TRAINING, SECURITY AND SAFETY REQUIREMENTS
Security Clearances Due to the possible sensitive work and areas in which work may be performed, all contractor personnel shall be required to have a SECRET security clearance at time of hire. The contractor shall comply with all Command Occupational Safety and Health regulations.
IT Security Training The Contractor shall ensure that its employees performing under this contract fulfill all requirements for mandatory IT security awareness and any other applicable DON security training in accordance with OMB Circular A-130, DON requirements, and sign all applicable statements of responsibilities.
Dissemination of Information/Publishing The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The Contractor shall also protect all unclassified Government data, equipment, etc., by treating information as sensitive business, confidential information, controlling and limiting access to the information, and ensuring the data and equipment are secured within the facility.
To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor will afford the Government access to the Contractor's documentation, records, and databases. The Contractor will cooperate with Federal agencies and their officially credentialed representatives during official inspections or investigations concerning the protection of IT/C&A information. Cooperation may include providing relevant documentation showing proof of compliance with federal and agency requirements, and rendering other assistance as deemed necessary.
Marking and Destruction of Information
Marking - For preliminary or working draft technical C&A documents, the Government will determine if a distribution statement is needed. If so, the Government shall provide specific instructions on the distribution statement to be marked on the C&A technical documents before primary distribution.
Otherwise, the official marking for all C&A documents shall contain: "FOR OFFICIAL USE ONLY (FOUO)" as a header and footer contained in the document.
Destruction - For classified documents, follow the procedures per DOD 5200.1-R, Information Security Program Regulation. For unclassified documents, destroy by all-shred policy that will prevent disclosure of contents or reconstruction of the document.
Identification of Contractor Employees/Badges All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such. Contractor personnel may be required to attend meetings to meet order requirements. Contractor personnel shall wear Government provided contractor badges in Government spaces during the performance of this order.
The contractor shall strictly adhere to Federal Occupational Safety and Health (OSHA) regulations, Environmental Protection Agency (EPA) Regulations, and all applicable state and local requirements.
6. DELIVERABLES
All documentation developed under this contract shall be the exclusive property of the government and shall be delivered to the government in MS Office products or Visio formats.
The contractor shall provide the government access (at no charge to the government), to any such tools or solutions that are used to automate or generate documentation, artifacts or any supporting information created or resulting from any action identified or contained in this SOW.
The contractor shall submit all C&A packages, C&A correspondence and any other related C&A documents to TPOC and/or Designated Navy Validator. Any changes required by the Designated Navy Validator and/or TPOC are the responsibility of the contractor to fix.
Time of delivery: Monthly.
The Contractor shall provide sufficient program management to ensure that these tasks are performed efficiently, accurately, on time, and in compliance with the requirements of this document. The Contractor shall ensure that a monthly performance and progress/status report is submitted to the Technical Point of Contact (TPOC) outlining the billings, progress, status, and any problems/issues encountered in the performance of these tasks. Invoices shall be submitted for recurring services performed.
MONTHLY STATUS REPORT: The monthly status report shall be in a format acceptable to the Technical Point of Contact (TPOC) and shall include summaries of the accomplishments of the reporting period, technical problems encountered and solutions provided, as well as, any significant tasks expected to be addressed in the next reporting period. Each status report shall cover one month’s performance under the task order and shall be due not later than 15 days after the end of the month that is the subject of the report.
Invoices/Costs Report is a report that captures a summary of all costs incurred to date. This report shall be attached in Wide Area Workflow Receipts and Acceptance (WAWF-RA), beginning 30 days after award and every 30 days thereafter.
7. BADGES/BUILDING ACCESS
Contractor personnel may be required to lead and attend meetings to meet order requirements. Contractor personnel shall wear Government provided contractor badges in Government spaces during the performance of this order.
Place of Performance: Work shall be accomplished on-site at Philadelphia, PA and at the contractor’s site. Travel may be required, as necessary.
NSWC Philadelphia, PA site available for contractor personnel for building access is as follows:
- Workdays are Monday to Friday.
- Building Security access is arrival no earlier than 0600 and departure is no later than 1800.
Arrangements for and costs of all travel, transportation, meals, lodging, and incidentals are the responsibility of the Contractor.
8. SNOW AND HOLIDAYS
Contractor personnel shall observe only Government holidays. During snow or other emergencies, contractor personnel shall adhere to the policy of the site of performance. Personnel may be directed to report to an alternate work site.
9. PERIOD OF PERFORMANCE is 1 year from the date of award. Option Quantities will have a period of performance of 5 months from the date of option exercise.
(End of Summary of Changes)
File details come from the government source that posted it. Updated .