N66001-18-R-0351.pdf

PDF 690 KB Posted

Attached to
Cybersecurity, Cryptographic Modernization and Key Management Engineering Services Federal contract opportunity
Solicitation number
N66001-18-R-0351
Issued by
Department of the Navy Information Warfare Systems Command

About this file

This is a synopsis for solicitation number N66001-18-R-0351 for Cybersecurity, Cryptographic Modernization and Key Management Engineering Services. The Space and Naval Warfare Systems Center Pacific (SSC Pacific) intends to issue this solicitation for follow-on services currently provided under two task orders with the incumbent, Nathan Kunes, Inc. SSC Pacific plans to award a single Indefinite Delivery/Indefinite Quantity cost-plus-fixed-fee contract with a two-year base period and one three-year option period. The estimated level of effort is 364,800 labor hours. The NAICS code is 541512 with a size standard of $27.5 million. Work will require top secret clearance with incidental SCI access. The solicitation will be available electronically on the Space and Naval Warfare Systems Command E-Commerce website in October 2018.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity, Cryptographic Modernization and Key Management Engineering Services, newest first.
File Type Posted
Att 1 - DD254.pdf PDF
Att 7 - Written Test Guidelines.docx DOCX document
Att 6 - Past Performance Questionnaire.pdf PDF
Att 4 - Organizational Experience Matrix.doc DOC document
Att 3 - Desired Personnel Qualifications.docx DOCX document
Att 5 - Reference Information Sheet.docx DOCX document
Att 2 - Rate Sheet.xlsx XLSX spreadsheet
SOW_18-R-0351_Crypto Key Management.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CODE

(Hour)

PAGE(S)

until 02:00 PM local t ime 15 Nov 2018

X

A X B X C X D

EX

X

G F 66 - 76

77 - 90 X H 91 - 95

RATING PAGE OF PAGES

7. ISSUED BY

(Date)

IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.

Previous Edition is Unusable 33-134 STANDARD FORM 33 (REV. 9-97)

Prescribed by GSA FAR (48 CFR) 53.214(c)

1 95

(If other than Item 7) N66001

15A. NAME 16. NAME AND TITLE OF PERSON AUTHORIZED TO

AND

ADDRESS SIGN OFFER (Type or print)

OF

OFFEROR

AMENDMENT NO. DATE

15B. TELEPHONE NO (Include area code) 17. SIGNATURE15C. CHECK IF REMITTANCE ADDRESS

IS DIFFERENT FROM ABOVE - ENTER

SUCH ADDRESS IN SCHEDULE.

18. OFFER DATE

1. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 700)

2. CONTRACT NO.

N66001 8. ADDRESS OFFER TO

9. Sealed offers in original and 1 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in

CAUTION - LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and

L-TXT-38

conditions contained in this solicitation.

10. FOR INFORMATION

CALL:

A. NAME (NO COLLECT CALLS)

11. TABLE OF CONTENTS

SOLICITATION/ CONTRACT FORM

SUPPLIES OR SERVICES AND PRICES/ COSTS

2 - 5

X I CONTRACT CLAUSES

DESCRIPTION/ SPECS./ WORK STATEMENT X

PACKAGING AND MARKING

6 - 24

J LIST OF ATTACHMENTS

INSPECTION AND ACCEPTANCE

DELIVERIES OR PERFORMANCE

27 X K REPRESENTATIONS, CERTIFICATIONS AND

OTHER STATEMENTS OF OFFERORS

CONTRACT ADMINISTRATION DATA 28 - 34 X

SPECIAL CONTRACT REQUIREMENTS

OFFER (Must be fully completed by offeror) 35 - 45 X M

L INSTRS., CONDS., AND NOTICES TO OFFERORS

EVALUATION FACTORS FOR AWARD

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause No. 52.232-8)

14. ACKNOWLEDGMENT OF AMENDMENTS

(The offeror acknowledges receipt of amendments

AMENDMENT NO. DATE

to the SOLICITATION for offerors and related documents numbered and dated):

FACILITY

12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period

SOLICITATION, OFFER AND AWARD

X

(X) SEC. DESCRIPTION (X) SEC. DESCRIPTION PAGE(S)

PART I - THE SCHEDULE

26. NAME OF CONTRACTING OFFICER (Type or print) 27. UNITED STATES OF AMERICA 28. AWARD DATE

EMAIL:TEL: (Signature of Contracting Officer)

CODE CODE

B. TELEPHONE (Include area code) C. E-MAIL ADDRESS

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( ) (4 copies unless otherwise specified)

23. SUBMIT INVOICES TO ADDRESS SHOWN IN ITEM

24. ADMINISTERED BY (If other than Item 7) CODE 25. PAYMENT WILL BE MADE BY CODE

PART IV - REPRESENTATIO NS AND INSTRUCTIO NS

PART III - LIST O F DO CUMENTS, EXHIBITS AND O THER ATTACHMENTS

46 - 64

PART II - CO NTRACT CLAUSES

SPAWAR SYSTEMS CENTER PACIFIC

SUZANNE M. MCLAUGHLIN, CODE 22710

SUZANNE.M.MCLAUGHLIN@NAVY.MIL

53560 HULL STREET

SAN DIEGO CA 92152-5001

SEE SECTION L

ELECTRONIC SUBMISSION

HTTPS://E-COMMERCE.SSCNO.NMCI.NAVY.MIL/

CA 619-553-2556

FAX:

TEL:

FAX:

TEL:

NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".

SOLICITATION

6. REQUISITION/PURCHASE NO.5. DATE ISSUED

15 Oct 2018

4. TYPE OF SOLICITATION

SEALED BID (IFB)

NEGOTIATED (RFP)

[ X ]

3. SOLICITATION NO.

N6600118R0351

Section B - Supplies or Services and Prices

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 1 Lot Cryptographic Key Management Services

CPFF

Base Period (2 Years). Provide services in accordance with the Statement of Work, Section C, as specified in individual task orders.

FOB: Destination

ESTIMATED COST

FIXED FEE

TOTAL EST COST + FEE

0002 Lot Data (Not Separately Priced)

1001 1 Lot OPTION Cryptographic Key Management Services

CPFF

Option Period (3 Years). Provide services in accordance with the Statement of Work, Section C, as specified in individual task orders.

FOB: Destination

ESTIMATED COST

FIXED FEE

TOTAL EST COST + FEE

1002 Lot OPTION Data (Not Separately Priced)

CLAUSES INCORPORATED BY FULL TEXT

B-TXT-01 PAYMENT OF FIXED FEE (COMPLETION TYPE) (JUN 2017)

FIXED FEE: $*. The Government shall make payment to the Contractor when requested as work progresses, but no more frequently than biweekly, on account of the fixed fee, equal to ** percent of the amounts invoiced by the Contractor under the “Allowable Cost and Payment” clause hereof for the related period, subject to the withholding provisions of paragraph (b) of the “Fixed Fee” clause. In the event of discontinuance of the work in accordance with clause of this contract entitled “Limitation of *** the fixed fee shall be redetermined by mutual agreement equitably to reflect the diminution of the work performed; the amount by which such fixed fee is less than, or exceeds payments previously made on account of fee, shall be paid, or repaid by, the Contractor, as the case may be.

*To be completed upon award of the contract.

**To be determined at the Task Order level. The allowable fee percentage will be negotiated at the Task Order level, and shall not exceed the percentage proposed at the basic contract level.

*** To be determined at the Task Order level.

(End of clause)

B-TXT-04 LEVEL OF EFFORT--FEE ADJUSTMENT FORMULA (JUN 2017)

(a) Subject to the provisions of the “Limitation of Cost” or “Limitation of Funds” clause (whichever is applicable to this contract), it is hereby understood and agreed that the fixed fee is based upon the Contractor providing the below listed number of staff-hours of direct labor, hereinafter referred to as X, at the estimated cost and during the term of this contract specified elsewhere herein:

CLIN Total Staff-hours of Direct Labor (X)

0001 TBD at the Task Order Level.

1001 TBD at the Task Order Level.

The Contractor agrees to provide the total level of effort specified above in performance of work described in Sections “B” and “C” of this contract. The total staff-hours of direct labor shall include subcontractor direct labor hours for those subcontractors identified in the Contractor’s proposal as having hours included in the proposed level of effort.

(b) Of the total staff-hours of direct labor set forth above, it is estimated that 0 staff-hours are competitive time (uncompensated overtime). Competitive time (uncompensated overtime) is defined as hours provided by personnel in excess of 40 hours per week without additional compensation for such excess work. All other effort is defined as compensated effort. If no amount is indicated in the first sentence of this paragraph, competitive time (uncompensated overtime) effort performed by the contractor shall not be counted in fulfillment of the level of effort obligations under this contract.

(c) Effort performed in fulfilling the total level of effort obligations specified above shall only include effort performed in direct support of this contract and shall not include time and effort expended on such things as local travel from an employee’s residence to their usual work location, uncompensated effort while on travel status, truncated lunch periods, or other time and effort which does not have a specific and direct contribution to the tasks described in Section B.

(d) It is understood and agreed that various conditions may exist prior to or upon expiration of the term of the contract, with regard to the expenditure of labor staff-hours and/or costs thereunder which may require adjustment to the aggregate fixed fee. The following actions shall be dictated by the existence of said conditions:

(1) If the Contractor has provided not more than 105 % of X or not less than 95 % of X, within the estimated cost, and at the term of the contract, then the fee shall remain as set forth in Section B.

(2) If the Contractor has provided X-staff-hours, within the term, and has not exceeded the estimated cost then the Contracting Officer may require the Contractor to continue performance until the expiration of the term, or until the expenditure of the estimated cost of the contract except that, in the case of any items or tasks funded with O&MN funds, performance shall not extend beyond 30 September. In no event shall the Contractor be required to provide more than 105 % of X within the term and estimated cost of this contract. The fee shall remain as set forth in Section B.

(3) If the Contractor expends the estimated cost of the contract, during the term of the contract and has provided less than X staff-hours, the Government may require the Contractor to continue performance, by providing cost growth funding, without adjusting the fixed fee, until such time as the Contractor has provided X staff-hours.

(4) If the Contracting Officer does not elect to exercise the Government’s rights as set forth in paragraph (d)(2) and (d)(3) above, and the Contractor has not expended more than 95 % of X staff-hours, the fixed fee shall be equitably adjusted downward to reflect the diminution of work.

(5) Nothing herein contained shall, in any way, abrogate the Contractor’s responsibilities, and/or the Government’s rights within the terms of the contract provision entitled “Limitation of Cost” or “Limitation of Funds” as they shall apply throughout the term of the contract, based upon the total amount of funding allotted to the contract during its specified term.

(e) Within 45 days after completion of the work under each separately identified period of performance hereunder, the Contractor shall submit the following information in writing to the Contracting Officer with copies to the cognizant Contract Administration Office and DCAA office to which vouchers are submitted:

(1) The total number of staff-hours of direct labor expended during the applicable period.

(2) A breakdown of this total showing the number of staff-hours expended in each direct labor classification and associated direct and indirect costs.

(3) A breakdown of other costs incurred.

(4) The Contractor’s estimate of the total allowable cost incurred under the contract for the period.

In the case of a cost under-run, the Contractor shall submit the following information in addition to that required above:

(5) The amount by which the estimated cost of this contract may be reduced to recover excess funds and the total amount of staff-hours not expended, if any.

(6) A calculation of the appropriate fee reduction in accordance with this clause.

All submissions required by this paragraph shall include subcontractor information, if any.

(f) SPECIAL INSTRUCTION TO THE PAYING OFFICE REGARDING WITHHELD FEE

Fees withheld pursuant to the provisions of this contract, such as the withholding provided by the “Allowable Cost and Payment” and “Fixed Fee” clauses, shall not be paid until the contract has been modified to reduce the fixed fee in accordance with paragraph (d) above, except that no such action is required if the total level of effort provided falls within the limits established in paragraph (d) above.

B-TXT-08 MINIMUM AND MAXIMUM QUANTITIES (JUN 2017)

As referred to in paragraph (b) of the “Indefinite Quantity” clause of this contract, the contract minimum quantity is a total of $20,000.00 worth of orders. The maximum quantity is the total estimated amount of the contract. The maximum quantity is not to be exceeded without prior approval of the Procuring Contracting Officer.

Section C - Descriptions and Specifications

STATEMENT OF WORK (SOW)

STATEMENT OF WORK

FOR

CYBERSECURITY, CRYPTOGRAPHIC MODERNIZATION AND KEY MANAGEMENT

ENGINEERING SERVICES

1.0 INTRODUCTION

The Space and Naval Warfare Systems Center Pacific (SSC Pacific) Information Assurance (IA) and Engineering Division, Code 58000, hereafter referred to as 58, provides support for the broad business area related to cyber and the development establishment, and maintenance of assured computer and network operations for Department of Defense (DoD) and other national level systems and networks. Inherent in this are a broad spectrum of activities including research, development, test and evaluation, the liberal application of science and technology practices and techniques to develop solutions, and developing, implementing and executing all aspects of life-cycle support (LCS) and lifecycle management (LCM) for the fielded systems, networks and security products as directed by our sponsors and customers. 58 provides IA and engineering services in the growing business area related to Cyber, Cryptographic systems and solutions, the closely aligned area of Cryptographic Key Management architectures and information systems, and the secure configuration management of software artifacts such as software waveforms.

1.1 SCOPE

Individual task orders will be issued to provide sufficient detail to define the scope of work, requirements, desired outcomes and deliverables for each task. Task orders may entail liaison with Fleet Commands, Services, Agencies, Homeland Security agencies and groups, and other activities as well as attendance at conferences, meetings, and symposia.

The technical discipline areas historically required to provide the requested services are: software and hardware related skill sets including journeyman and senior level general and security engineering, familiarity with the National Security Agency (NSA) engineering processes, procedures and security practices for Type 1, 2 and 3 devices, and for currently fielded cryptographic key management systems and products; code analysis, design, development, system and product integration, testing and installation; research, development and the application of evolving scientific and technological practices and procedures to develop security solutions; mid to senior engineering level expertise and experience with NSA cryptographic key management practices, procedures and guidelines; the analysis, development and testing of secure architecture solutions for key and certificate management; developing, reviewing and updating many defined forms of both technical and programmatic documentation; acquisition support including engineering, research and document development; general and technical project/product related logistics services including configuration management (software and hardware), engineering, research, training, system/product documentation development and updating; engineering and related technical support to respond to new or existing problems which threaten the security posture of DOD and national level information systems, networks and the connecting infrastructure.

The flow-down technical performance areas incident to this work area historically include: developing, implementing and testing computer network defense measures; developing and improving wireless computing security; developing, implementing and maintaining cross domain solutions; the development and execution of risk and vulnerability assessments; system and security engineering to evaluate commercial IA products; Joint and Service level acquisition research and engineering; and developing, updating and performing IA associated training;

security engineering support to Navy Cyber Technical Authority. This work is to be performed in an environment which fosters process improvement.

1.2 SYSTEMS TO BE SUPPORTED

58 is designated as the Navy lead system security engineering activity for: Crypto Modernization Program, Public Key Infrastructure (PKI), Key Management Infrastructure (KMI) Cyber Technical Authority, identity management and Joint Cross Domain eXchange (JCDX) programs. Other related tasking includes engineering and technical support for a variety of security architecture tasks including ONEnet, NGEN, BLII Piers, Consolidated Afloat

Network Enterprise Services (CANES), the Joint Tactical Network Center (JTNC), the Unmanned/Unattended Information Assurance Services (UIAS), the Consolidated Electronic Key Management Tier 3 Test Infrastructure (CETTI), the Joint Information Environment (JIE), the Information Dominance Enterprise Architecture (IDEA), and the Navy/Marine Corp Intranet (NMCI). Additionally, the NSA, JTNC, other DOD and federal offices rely on the subject matter expertise assembled by 58 for Cybersecurity services, and software/hardware configuration management expertise in areas such as the NSA Crypto Modernization Program, the JTRS Information Repository (IR) and IA lead, and in the development and implementation of advanced concepts in secure wireless networks.

NSA has also directly assigned 58 program managers and other technical staff significant oversight, testing, management, security engineering and related supporting technical roles in the: High Assurance Internet Protocol Encryption (HAIPE), Key Management System and Key Management Infrastructure (KMI) programs.

1.3 CODE 58 EXTERNAL ROLES TO BE SUPPORTED

The Navy Program Executive Office (PEO) for Command, Control, Communications, Computers, and Intelligence (PEO C4I) is responsible for the program management and technical control over the development, test and evaluation, system and equipment acquisition, and Life Cycle Management (LCM) for all information assurance programs within the Navy. The IA Program Manager (SPAWAR PMW 130) is responsible for the planning, direction, control and integration relating to the acquisition and fielding of information assurance systems, products, and devices within the Navy and Marine Corps.

The Navy IA Program Manager (PEO C4I - PMW 130) has designated 58, as the Navy system security engineering activity for the NSA Crypto Modernization Program and as the Cryptographic Key Management lead engineering activity for the NSA Key Management Infrastructure (KMI) evolutionary development, testing and implementation.

In support of these programs 58 will be involved in the engineering and monitoring of cryptographic and key management solutions designed to replace aging Navy cryptographic and key management systems.

Additionally, the NSA, other DOD and federal offices rely on the subject matter expertise assembled by 58 in the area of assured computer and network engineering to include High Assurance Internet Protocol Encryption

(HAIPE).

As a US Navy security engineering center for C4I systems, 58 supports PEO C4I- PMW 130, the NSA, Navy IA Technical Authority (SPAWAR), JTNC and coordinates closely with other organizations such as SSC LANT, Naval Network Warfare Command and OPNAV. All coordination, security and system engineering will be done as directed by SPAWAR.

2.0 APPLICABLE DOCUMENTS

The following list of documents is provided for reference and guidance only. In the event of conflict between the requirements of these specifications and the SOW, the requirements of the SOW shall govern. Any additional MIL Documents, used in the individual task orders, shall have been reviewed IAW DOD 4120.24-M, Defense Standardization Program (DSP) Policies and Procedures, and USD Policy Memo 05-3.

2.1 MIL-SPECIFICATIONS

MIL-STD-1472F Human Engineering Design Criteria for Military Systems

MIL-STD-810F Environmental Test Methods and Engineering Guidelines

MIL-STD-961E Defense Specifications

2.2 MIL-HDBK PUBLICATIONS

The following documents are referenced for guidance only nothing in this document of listed reference documents supersedes applicable laws and regulations, unless a specific exemption has been obtained from the government.

MIL-HDBK-881A Work Breakdown Structures

MIL-HDBK-29612/1A Guidance for Acquisition of Training Data Products and Services (Part 1 of 5 Parts)

MIL-HDBK-29612/2A Instructional Systems Development/Systems Approach to Training and Education (Part 2 of 5 Parts)

MIL-HDBK-29612/3A Development of Interactive Multimedia Instruction (IMI) (Part 3 of 5 Parts)

MIL-HDBK-29612/4A Glossary for Training (Part 4 of 5 Parts)

MIL-HDBK-29612/5 Advanced Distributed Learning (ADL) Products and Systems (Part 5 of 5 Parts)

MIL-HDBK-46855A Human Engineering Program Process & Procedures

2.3 OTHER GOVERNMENT PUBLICATIONS

The following documents are referenced for guidance only. Nothing in the listed reference documents supersedes applicable laws and regulations, unless a specific exemption has been obtained from the government. Additionally, the contractor is to recommend appropriate standards and deliverables for systems engineering, process improvement, software development and lifecycle support.

MIL-PRF-29612B Training Data Products

MIL-DTL-31000C Technical Data Packages

DOD-5220-22M Industrial Security Manual for Safeguarding Classified Information

DOD-5220-22-S COMSEC Supplement to Industrial Security Manual for Safeguarding Classified

Information.

DOD 8500.1 Information Assurance

DOD 8500.2 Information Assurance (IA) Implementation

DOD-I-5200.40 Information Technology Security Certification and Accreditation Process

DODI 8510.01 DOD IA Certification and Accreditation Process (DIACAP), 12 December 2007

DON CIO DIACAP Handbook, 23 January 2008

DoDI 8510.01 RMF Risk Management Framework (RMF) for DoD Information Technology (IT)

DOD 8570.0 1-M “Information Assurance (IA) Workforce Improvement Program," Incorporating Change 2 issued 20 April 2010

PR-OPD-29 V1.2 SSC San Diego Project Management Guide

CNSS Inst. # 4009 National Information Assurance (IA) Glossary, Committee on National Security

Systems (Series)

CJCSI 3170.01H Chairman of the Joint Chiefs of Staff Instruction, Joint Capabilities Integration and

Development System, January 2012

CJCSM 3170.01C Chairman of the Joint Chiefs of Staff Manual, Joint Capabilities Integration and

Development System, January 2012

2.4 OTHER DOCUMENTS

The following list of documents is provided for reference and guidance only. In the event of conflict between the requirements of these standards or documents and the SOW, the requirements of the SOW shall govern.

CNSS Inst. # 4009 National Information Assurance (IA) Glossary, Committee on National Security

Systems (Series)

ISO 9000/ IEEE 1498 International Standards Organization Family of Standards Management

ANS/PMI 99-001-2000 A Guide to the Project Management Body of Knowledge

SSC-PAC Software Engineering Program Office (SEPO) Program Manager's Guide (SSCSD SEPO

PMG)

NIST 800-53 Recommended Security Controls for Federal Information Systems & Organizations

Naval SEG, Volume 1 Systems Engineering Guidebook, December 12, 2006

NSA Central Security Service Classification Guide for Quantum Defense 3-17

Additional documents will be referenced in individual task orders as required.

3.0 TECHNICAL REQUIREMENTS

3.1 CRYPTOGRAPHIC AND KEY MANAGEMENT ENGINEERING / CYBERSECURITY

ENGINEERING

The contractor shall perform security related engineering; technical, managerial and logistics support functions.

This broad program area will require specialized security engineering services to perform architecture design, analysis, test, user training, certification, COTS / GOTS security product analysis and evaluation, product integration and implementation, specialized network configuration and sustainment support functions including those for the current and follow-on generation of security devices/products used in Naval networks.

Typical of the type of services that may be required follow; this is not an all-inclusive list:

3.1.1 Review existing technical and program management documentation. Participate in meetings, conferences and symposia.

3.1.2 Develop and/or analyze security architectures with particular emphasis on cryptographic and key management issues (component, system, systems of systems, etc.).

3.1.3 Support the planning and execution of research and development, test and evaluation through proof of concept opportunities related to cryptographic equipment (including key management aspects); make recommendations for implementation. Support may include live laboratory demonstrations as well as fleet experiments and demonstrations.

3.1.4 Provide engineering analysis in support of the Crypto Modernization effort to ensure that the military services are successful in modernizing their cryptographic inventory and meet the NSA Crypto Modernization tenets.

3.1.5 Provide engineering analysis in support of the Key Management Infrastructure (KMI) effort to ensure that the modernization effort within the military services is successful.

3.1.6 Conduct cryptographic or key management product trade-off analyses and security prototyping and modeling and provide test report documentation.

3.1.7 Provide security engineering analysis, systems engineering, consultation and guidance in areas of new and emerging programs and technology requirements related to cryptographic or key management issues.

3.1.8 Provide cryptographic and key management support for the development of test laboratories including system and software configuration, fault and error isolation, and maintenance and repair.

3.1.9 Provide services in the preparation and coordination of documentation necessary for the proper operation of cryptographic or key management systems or equipment in accordance with DOD and national regulations.

3.1.10 Support security engineering analysis and system engineering related to the introduction of cryptographic or key management systems into developmental and operational networks. Analysis and system engineering efforts may include consideration of the classification of the data, security requirements, and the threats and vulnerabilities to determine the robustness of the solutions.

3.1.11 Support Operational Security (OPSEC) efforts such as the identification of critical information, the analysis of threats and vulnerabilities, the assessment of risks and the application of countermeasures.

3.1.12 Develop, implement and perform life cycle management of cryptographic and key management systems.

3.1.13 Work with NSA Research (R2) for the HAIPE implementation of the Advanced Algorithm Suites (AAS).

The contractor shall investigate and provide technical reports/comments on the alternatives for implementing these algorithms for HAIPE Confidentiality, Authentication, and Denial of Service issues.

3.1.14 Collect all applicable requirements documented in the HAIPE Specifications and continue to develop and maintain the requirements for implementing High Assurance Internet Protocol Encryption devices. Collect requirements and threat data from key stakeholders such as ADNS, Defense Information Systems Agency (DISA), NSA Technical Operations Center (NTOC), Department of Homeland Security (DHS), the Armed Services, and Five-Eyes partners to ensure HAIPE devices meet the security and interoperability requirements for US and Five Eyes networks up to the TS//SCI level.

3.1.15 Provide HAIPE software engineering support for the HAIPE program which includes developing software test tools and emulators for the HAIPE protocols and algorithms.

3.1.16 Provide HAIPE testing support to NSA encryption programs which includes performing formal testing of the protocols and algorithms as implemented in certified HAIPE devices.

3.1.17 Development and maintenance of HAIPE CONOPs, HAIPE White Papers, Interoperability Specifications, Management Information Bases (MIB), and Implementation Guides. Responsible for the briefing at HAIPE Implementers' Working Groups which are anticipated to occur twice per year.

3.2 RELATED PROGRAM AND PROJECT LEVEL MANAGEMENT IN SUPPORT OF

CRYPTOGRAPHIC AND KEY MANAGEMENT SYSTEMS

The contractor shall provide security engineering related management support. Typical, but not all-inclusive types of services that may be required are:

M

3.2.1 Assess current and future system and software project requirements to include upgrades of current product baselines. Recommend tentative approaches and solutions using a variety of tools, techniques, or processes.

3.2.2 Analyze, identify, specify and track current and emerging business opportunities.

3.2.3 Analyze requirements and prepare presentation and briefing material and program, system and business development documents.

3.2.4 Attend technical meetings, conferences, and reviews. Support shall include participation and review of technical packages, and providing after action minutes and reports.

3.2.5 Provide program/project planning and programmatic support including the definition and recommendation of approaches for the research, development, testing, training and evaluation for cryptographic and key management related systems and products. These efforts may involve defining the scope, cost /schedule requirements for all project phases, assess capabilities / requirements, milestones, IV&V requirements / approaches, security accreditation plan, and risk assessments.

3.2.6 Participate in and provide technical guidance during reviews, walk-throughs, requirements tractability analyses, and defined verification and validation processes. Requirements will be traceable, consistent, complete, and testable throughout the development process. This may involve coordination with the appropriate activities, agencies, and development personnel to ensure complete preparation for the review.

3.2.7 Develop network security documents, e.g. Trusted Facility Manual and Security Features User's Guide in accordance with DOD Trusted Computer System Evaluation Criteria, DITSCAP, DIACAP, RMF, etc.

3.2.8 Support/conduct/attend meetings as scheduled to facilitate the exchange of technical information and enhance effective communication.

3.2.9 Develop and present program management reviews as specified in individual task orders to designated government representatives. This may include a summary of technical achievements, schedule status, and cost performance. These reviews shall emphasize progress and problems since the last meeting, plans for the future and establish the date and place for the next meeting.

3.2.10 May develop and conduct formal oral and visual presentations to invited government and industry representative's reviews as specified in individual task orders.

3.3 ENGINEERING AND MANAGEMENT SUPPORT

The contractor shall establish an effective and efficient organization for the security engineering and management support that compliments the working structure of 58 and ensures that a quick response capability is provided.

Typical of the type of services that may be required are:

3.3.1 Assess current and future system and software project requirements to include upgrades of current product baselines. Recommend approaches and solutions using a variety of tools, techniques, or processes.

3.3.2 Analyze, identify, specify and track current and emerging business opportunities related to assured computer and networking as well as integrated circuit design.

3.3.3 Analyze requirements and prepare presentation and briefing material and program, system and business development documents.

3.3.4 Attend technical meetings, conferences, and reviews. Support shall include participation and review of technical packages, and providing reports. The reports shall include description of the meeting, issues, action items, and recommended solutions to issues impacting the program.

3.3.5 Provide milestone support for major division efforts, facilitate and document project team activities, and provide input to the business process modeling and re-engineering.

3.3.6 Participate in and provide technical guidance and assistance during reviews, walk-throughs, requirements tractability analyses, and defined verification and validation processes. Requirements will be traceable, consistent, complete, and testable throughout the development process. For each review, coordination with the appropriate activities, agencies, and development personnel will be conducted to ensure complete preparation for the review.

4.0 CYBERSECURITY COMPLIANCE

Cybersecurity (which replaced the term Information Assurance (IA)) is defined as prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation. Contractor personnel shall perform tasks to ensure Navy applications, systems, and networks satisfy Federal/DoD/DON/Navy cybersecurity requirements.

4.1 CYBER IT AND CYBERSECURITY PERSONNEL

(a) The Cyberspace workforce elements addressed include contractors performing functions in designated Cyber IT positions and Cybersecurity positions. In accordance with DFARS Subpart 239.71, DoDD 8140.01, SECNAVINST 5239.20A, and SECNAV M-5239.2, contractor personnel performing cybersecurity functions shall meet all cybersecurity training, certification, and tracking requirements as cited in DoD 8570.01-M prior to accessing DoD information systems. Proposed contractor Cyber IT and cybersecurity personnel shall be appropriately qualified prior to the start of the contract performance period or before assignment to the contract during the course of the performance period.

(b) The contractor shall be responsible for identifying, tracking and reporting cybersecurity personnel, also known as Cybersecurity Workforce (CSWF) and Cyber IT workforce personnel. Although the minimum frequency of reporting is monthly, the task order can require additional updates at any time.

(c ) Contractors that access Navy IT shall also follow guidelines and provisions documented in Navy Telecommunications Directive (NTD 10-11) and are required to complete a System Authorization Access Request (SAAR) – Navy form as documented in para 8.2.2.4(b).

When a contractor requires logical access to a government IT system or resource (directly or indirectly), the required CAC will have a Public Key Infrastructure (PKI). A hardware solution and software (e.g., ActiveGold) is required to securely read the card via a personal computer. Pursuant to DoDM 1000.13-M-V1, CAC PKI certificates will be associated with an official government issued e-mail address (e.g. .mil, .gov, .edu). Prior to receipt of a CAC with PKI, contractor personnel shall complete the mandatory Cybersecurity Awareness training and submit a signed System Authorization Access Request Navy (SAAR-N) form to the contract’s specified COR. Note: In order for personnel to maintain a CAC with PKI, each contractor employee shall complete annual cybersecurity training. The following guidance for training and form submittal is provided; however, contractors shall seek latest guidance from their appointed company Security Officer and the SSC Pacific Information Assurance Management (IAM) office:

For annual DoD Cybersecurity/IA Awareness training, contractors shall use this site: https://twms.nmci.navy.mil/.

For those contractors requiring initial training and do not have a CAC, contact the SSC Pacific IAM office at phone number [insert applicable contract information] (843)218-6152 or e-mail questions to ssc_lant_iam_office.fcm@navy.mil for additional instructions. Training can be taken at the IAM office or online at http://iase.disa.mil/index2.html.

For SAAR-N form, the contractor shall use OPNAV 5239/14 (Rev 9/2011). Contractors can obtain a form from the SSC Pacific IAM office at or from the website: https://navalforms.documentservices.dla.mil/. [insert applicable contract information] Digitally signed forms will be routed to the IAM office via encrypted e-mail to ssclant_it_secmtg@navy.mil.

(d) Contractor personnel with privileged access will be required to acknowledge special responsibilities with a Privileged Access Agreement (PAA) IAW SECNAVINST 5239.20A.

DESIGN, INTEGRATION, CONFIGURATION OR INSTALLATION OF HARDWARE AND

SOFTWARE

http://iase.disa.mil/index2.html

The contractor shall ensure any equipment/system installed or integrated into Navy platform will meet the cybersecurity requirements as specified under DoDI 8500.01. The contractor shall ensure that any design change, integration change, configuration change, or installation of hardware and software is in accordance with established DoD/DON/Navy cyber directives and does not violate the terms and conditions of the accreditation/authorization issued by the appropriate Accreditation/Authorization official. Contractors that access Navy IT are also required to follow the provisions contained in DON CIO Memorandum: Acceptable Use of Department of the Navy Information Technology (IT) dtd 12 Feb 16. Use of blacklisted software is specifically prohibited and only software that is registered in DON Application and Database Management System (DADMS) and is Functional Area Manager (FAM) approved can be used as documented in para 5.2.2. Procurement and installation of software governed by DON Enterprise License Agreements (ELAs) – Microsoft, Oracle, Cisco, Axway, Symantec, ActivIdentity, VMware, Red Hat, NetApp, and EMC shall be in accordance with DON CIO Policy and DON ELAs awarded.

CYBERSECURITY WORKFORCE (CSWF) REPORT

DoD 8570.01-M and DFARS PGI 239.7102-3 have promulgated that contractor personnel shall have documented current cybersecurity certification status within their contract. The contractor shall develop, maintain, and submit a CSWF Report as applicable at the task order level. IAW clause DFARS 252.239-7001, if cybersecurity support is provided, the contractor shall provide a Cybersecurity Workforce (CSWF) list that identifies those individuals who are IA trained and certified. Utilizing the format provided at the task order level, the prime contractor shall be responsible for collecting, integrating, and reporting all subcontractor personnel. See applicable DD Form 1423 for additional reporting details and distribution instructions. Contractor shall verify with the COR or other government representative the proper labor category cybersecurity designation and certification requirements.

INFORMATION TECHNOLOGY (IT) SERVICES REQUIREMENTS

This paragraph only applies to IT contracts. Information Technology (IT) is defined as any equipment or interconnected system(s) or subsystem(s) of equipment that is used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data of information by the agency. IT includes computers, ancillary equipment, peripherals, input, output, and storage devices necessary for security and surveillance. Electronic and Information technology (EIT) is IT that is used in the creation, conversion, or duplication of data or information. EIT includes: telecommunication products, such as telephones; information kiosks; transaction machines; World Wide Web sites; multimedia (including videotapes); and office equipment, such as copiers and fax machines.

INFORMATION TECHNOLOGY (IT) GENERAL REQUIREMENTS

When applicable, the contractor shall be responsible for the following:

• Ensure that no production systems are operational on any RDT&E network.

• Follow DoDI 8510.01 of 12 Mar 2014 when deploying, integrating, and implementing IT capabilities.

• Migrate all Navy Ashore production systems to the NMCI environment where available.

• Work with government personnel to ensure compliance with all current Navy IT & cybersecurity policies, including those pertaining to Cyber Asset Reduction and Security (CARS).

• Follow SECNAVINST 5239.3B of 17 June 2009 & DoDI 8510.01 of 12 Mar 2014 prior to integration and implementation of IT solutions or systems.

• Register any contractor-owned or contractor-maintained IT systems utilized on contract in the Department of Defense IT Portfolio Registry (DITPR)-DON.

• Only perform work specified within the limitations of the task order.

ACQUISITION OF COMMERCIAL SOFTWARE PRODUCTS, HARDWARE, AND RELATED

SERVICES

This paragraph only applies to the purchasing/hosting of commercial software. Contractors recommending or purchasing commercial software products, hardware, and related services supporting Navy programs and projects shall ensure they recommend or procure items from approved sources in accordance with the latest DoN and DoD policies.

DON ENTERPRISE LICENSING AGREEMENT/DOD ENTERPRISE SOFTWARE INITIATIVE

PROGRAM

Pursuant to DoN Memorandum – Mandatory use of DoN Enterprise Licensing Agreement (ELA) dtd 22 Feb 12, contractors that are authorized to use Government supply sources per FAR 51.101 shall verify if the product is attainable through DoN ELAs and if so, procure that item in accordance with appropriate ELA procedures. If an item is not attainable through the DoN ELA program, contractors shall then utilize DoD Enterprise Software Initiative (ESI) program (see DFARS 208.74) and government-wide SmartBuy program (see DoD memo dtd 22 Dec 05). The contractor shall ensure any items purchased outside these programs have the required approved waivers as applicable to the program. Software requirements will be specified at the task order level.

DON APPLICATION AND DATABASE MANAGEMENT SYSTEM (DADMS)

The contractor shall ensure that no Functional Area Manager (FAM) disapproved applications are integrated, installed or operational on Navy networks. The contractor shall ensure that all databases that use database management systems (DBMS) designed, implemented, and/or hosted on servers and/or mainframes supporting Navy applications and systems be registered in DoN Application and Database Management System (DADMS) and are FAM approved. All integrated, installed, or operational applications hosted on Navy networks must also be registered in DADMS and approved by the FAM. No operational systems or applications will be integrated, installed, or operational on the RDT&E network.

SECTION 508 COMPLIANCE

This paragraph only applies to IT contracts. The contractor shall ensure that all software recommended, procured, and/or developed is compliant with Section 508 of the Rehabilitation Act of 1973, 26 CFR Part 1194 and pursuant to SPAWARINST 5721.1B of 17 Nov 2009. In accordance with FAR 39.204, this requirement does not apply to contractor acquired software that is incidental to the task, software procured/developed to support a program or system designated as a National Security System (NSS) or if the product is located in spaces frequented only by service personnel for maintenance, repair or occasional monitoring of equipment.

SOFTWARE DEVELOPMENT/MODERNIZATION AND HOSTING

This paragraph only applies to software development and modernization. The contractor shall ensure all programs utilizing this contract for software development/ modernization (DEV/MOD), including the development of IT tools to automate SSC Pacific business processes are compliant with DON Information Management/Information Technology (DON IM/IT) Investment Review Process Guidance requirements. Contractors shall neither host nor develop IT tools to automate SSC Pacific business processes unless specifically tasked within the task order or contract. The contractor shall ensure IT tools developed to automate SSC Pacific business processes will be delivered with full documentation and source code, as specified at the task order level, to allow non-proprietary operation and maintenance by any source. The contractor shall ensure all programs are submitted with proof of completed DEV/MOD certification approval from the appropriate authority in accordance with DON policy prior to task order award. *Note must be listed on Investment Review Board (IRB) approved list.

INFORMATION SECURITY

Pursuant to DoDM 5200.01, the contractor shall provide adequate security for all unclassified DoD information passing through non-DoD information system including all subcontractor information systems utilized on contract.

The contractor shall disseminate unclassified DoD information within the scope of assigned duties and with a clear expectation that confidentiality is preserved. Examples of such information include the following: non-public information provided to the contractor, information developed during the course of the contract, and privileged contract information (e.g., program schedules, contract-related tracking).

IT POSITION CATEGORIES

Pursuant to DoDI 8500.01, DoD 8570.01-M, SECNAVINST 5510.30, SECNAV M-5239.2, and applicable to unclassified DoD information systems, a designator is assigned to certain individuals that indicates the level of IT access required to execute the responsibilities of the position based on the potential for an individual assigned to the position to adversely impact DoD missions or functions. As defined in DoD 5200.2-R, SECNAVINST 5510.30 and SECNAV M-5510.30, three basic DoN IT levels/Position categories exist:

• IT-I (Privileged access)

• IT-II (Limited Privileged, sensitive information)

Note: The term IT Position is synonymous with the older term Automated Data Processing (ADP) Position (as used in DoD 5200.2-R, Appendix 10). Investigative requirements for each category vary, depending on the role and whether the individual is a U.S. civilian contractor or a foreign national. The Contractor PM shall assist the Government Project Manager or COR in determining the appropriate IT Position Category assignment for all contractor personnel. All required Single-Scope Background Investigation (SSBI)/Tier 5, SSBI Periodic Reinvestigation (SSBI-PR)/Tier 5R, and National Agency Check (NAC)/Tier 3R adjudication will be performed Pursuant to DoDI 8500.01 and SECNAVINST 5510.30. Requests for investigation of contractor personnel for fitness determinations or IT eligibility without classified access are submitted by SPAWAR/SSC Atlantic/SSC Pacific Security Office, processed by the OPM, and adjudicated by DOD CAF. IT Position Categories are determined based on the following criteria:

IT-I Level (Privileged) - Positions in which the incumbent is responsible for the planning, direction, and implementation of a computer security program; major responsibility for the direction, planning and design of a computer system, including the hardware and software; or, can access a system during the operation or maintenance in such a way, and with a relatively high risk for causing grave damage, or realize a significant personal gain.

Personnel whose duties meet the criteria for IT-I Position designation require a favorably adjudication of Single Scope Background Investigation (SSBI)/Tier 5 or SSBI-PR/Tier 5R. The SSBI/Tier 5 or SSBI-PR/Tier 5R is updated a minimum of every 5 years. Assignment to designated IT-I positions requires U.S. citizenship unless a waiver request is approved by CNO.

IT-II Level (Limited Privileged) - Positions in which the incumbent is responsible for the-direction, planning, design, operation, or maintenance of a computer system, and whose work is technically reviewed by a higher authority at the IT-II Position level to insure the integrity of the system. Personnel whose duties meet the criteria for an IT-II Position require a favorably adjudication of a Position of Trust National Agency Check with Law and Credit (PT/NACLC)/Tier 3R. Assignment to designated IT-II positions requires U.S. citizenship unless a waiver request is approved by CNO.

IT-III Level (Non-privileged) - All other positions involved in computer activities. Incumbent in this position has non-privileged access to one or more DoD information systems/applications or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III Position designation require a favorably adjudication of a Position of Trust National Agency Check with Written Inquiries (PT/NACI).

5.0 TRAVEL

Travel will be required in the execution of task orders for the purpose of participation in research efforts, defining system security requirements, security evaluation and testing, installation and installation planning, testing and troubleshooting, attending planning conferences, program audits and reviews, management reviews, and other areas of program support and field activity coordination. Specific travel requirements will be identified in the individual task orders.

6.0 GOVERNMENT FURNISHED EQUIPMENT/INFORMATION (GFE/GFI)

If required GFE/GFI will be identified under individual task orders.

7.0 OTHER

7.1 SECURITY

The nature of this task requires access to Secret information. The work performed by the Contractor will include access to unclassified and up to Secret data, information, spaces, and have access to Communications Security (COMSEC). The Contractor will be required to attend meetings classified up to Secret level. However, there may be exceptions at the task order level where Top Secret (TS)/Sensitive Compartmented Information (SCI) will be required.

Contractor personnel assigned to this effort who require access to SCI data and spaces must possess a current SSBI with ICD 704 eligibility (which replaced DCID 6/4 eligibility).

Although there is no requirement for the contractor to access NATO on this contract per Naval Intelligence Security Policy Directive 17-008 those contractors that have SCI access and those cleared SCI with Joint Worldwide Intelligence Communications System (JWICS) or Secure Internet Protocol Router Network (SIPRNet accounts shall be North Atlantic Treaty Organization (NATO) read-on and complete the derivative classification training prior to being granted access to JWICS/SIPRnet; training is provided by the facility security officer. Specific requirements provided in the Department of Defense Contract Security Classification Specification, DD Form 254.

Contractors performing tasks at the TS or below level without SCI access shall only receive the NATO awareness brief and complete the derivative classification training prior to being granted access to SIPRnet; training is provided by the facility security officer.

As required by National Industrial Security Program Operating Manual (NISPOM) Chapter 1, Section 3, contractors are required to report certain events that have an impact on: 1) the status of the facility clearance (FCL); 2) the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .