SOW_18-R-0351_Crypto Key Management.docx
DOCX document 31 KB Posted
- Attached to
- Cybersecurity, Cryptographic Modernization and Key Management Engineering Services Federal contract opportunity
- Solicitation number
- N66001-18-R-0351
About this file
This statement of work outlines engineering services required for cryptographic modernization and key management. The Space and Naval Warfare Systems Center Pacific intends to issue a solicitation for these services, with an estimated value of 364,800 labor hours. The services include security engineering, architecture design, analysis, testing, documentation development and sustainment support. Specific tasks involve reviewing documentation, developing and analyzing security architectures, supporting research and testing, and providing engineering analysis to modernize cryptographic systems and key management infrastructure. The incumbent contractors are Nathan Kunes, Inc. under task orders N00178-14-D-4849-7N01 and 7N02. The solicitation will be a single-award IDIQ CPFF contract with a two-year base period and one three-year option. Security requirements are at the Top Secret level with potential SCI access. The solicitation is expected to release in October 2018 and will be available electronically on the Space and Naval Warfare Systems Command website.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Att 7 - Written Test Guidelines.docx | DOCX document | |
| Att 1 - DD254.pdf | ||
| Att 4 - Organizational Experience Matrix.doc | DOC document | |
| Att 3 - Desired Personnel Qualifications.docx | DOCX document | |
| Att 5 - Reference Information Sheet.docx | DOCX document | |
| Att 2 - Rate Sheet.xlsx | XLSX spreadsheet | |
| N66001-18-R-0351.pdf | ||
| Att 6 - Past Performance Questionnaire.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
FOR
CYBERSECURITY, CRYPTOGRAPHIC MODERNIZATION AND KEY MANAGEMENT ENGINEERING SERVICES
1.0 INTRODUCTION
The Space and Naval Warfare Systems Center Pacific (SSC Pacific) Information Assurance (IA) and Engineering Division, Code 58000, hereafter referred to as 58, provides support for the broad business area related to cyber and the development establishment, and maintenance of assured computer and network operations for Department of Defense (DoD) and other national level systems and networks. Inherent in this are a broad spectrum of activities including research, development, test and evaluation, the liberal application of science and technology practices and techniques to develop solutions, and developing, implementing and executing all aspects of life-cycle support (LCS) and lifecycle management (LCM) for the fielded systems, networks and security products as directed by our sponsors and customers. 58 provides IA and engineering services in the growing business area related to Cyber, Cryptographic systems and solutions, the closely aligned area of Cryptographic Key Management architectures and information systems, and the secure configuration management of software artifacts such as software waveforms.
1.1 SCOPE
Individual task orders will be issued to provide sufficient detail to define the scope of work, requirements, desired outcomes and deliverables for each task. Task orders may entail liaison with Fleet Commands, Services, Agencies, Homeland Security agencies and groups, and other activities as well as attendance at conferences, meetings, and symposia.
The technical discipline areas historically required to provide the requested services are: software and hardware related skill sets including journeyman and senior level general and security engineering, familiarity with the National Security Agency (NSA) engineering processes, procedures and security practices for Type 1, 2 and 3 devices, and for currently fielded cryptographic key management systems and products; code analysis, design, development, system and product integration, testing and installation; research, development and the application of evolving scientific and technological practices and procedures to develop security solutions; mid to senior engineering level expertise and experience with NSA cryptographic key management practices, procedures and guidelines; the analysis, development and testing of secure architecture solutions for key and certificate management; developing, reviewing and updating many defined forms of both technical and programmatic documentation; acquisition support including engineering, research and document development; general and technical project/product related logistics services including configuration management (software and hardware), engineering, research, training, system/product documentation development and updating; engineering and related technical support to respond to new or existing problems which threaten the security posture of DOD and national level information systems, networks and the connecting infrastructure.
The flow-down technical performance areas incident to this work area historically include: developing, implementing and testing computer network defense measures; developing and improving wireless computing security; developing, implementing and maintaining cross domain solutions; the development and execution of risk and vulnerability assessments; system and security engineering to evaluate commercial IA products; Joint and Service level acquisition research and engineering; and developing, updating and performing IA associated training; security engineering support to Navy Cyber Technical Authority. This work is to be performed in an environment which fosters process improvement.
1.2 SYSTEMS TO BE SUPPORTED
58 is designated as the Navy lead system security engineering activity for: Crypto Modernization Program, Public Key Infrastructure (PKI), Key Management Infrastructure (KMI) Cyber Technical Authority, identity management and Joint Cross Domain eXchange (JCDX) programs. Other related tasking includes engineering and technical support for a variety of security architecture tasks including ONEnet, NGEN, BLII Piers, Consolidated Afloat Network Enterprise Services (CANES), the Joint Tactical Network Center (JTNC), the Unmanned/Unattended Information Assurance Services (UIAS), the Consolidated Electronic Key Management Tier 3 Test Infrastructure (CETTI), the Joint Information Environment (JIE), the Information Dominance Enterprise Architecture (IDEA), and the Navy/Marine Corp Intranet (NMCI). Additionally, the NSA, JTNC, other DOD and federal offices rely on the subject matter expertise assembled by 58 for Cybersecurity services, and software/hardware configuration management expertise in areas such as the NSA Crypto Modernization Program, the JTRS Information Repository (IR) and IA lead, and in the development and implementation of advanced concepts in secure wireless networks. NSA has also directly assigned 58 program managers and other technical staff significant oversight, testing, management, security engineering and related supporting technical roles in the: High Assurance Internet Protocol Encryption (HAIPE), Key Management System and Key Management Infrastructure (KMI) programs.
1.3 CODE 58 EXTERNAL ROLES TO BE SUPPORTED
The Navy Program Executive Office (PEO) for Command, Control, Communications, Computers, and Intelligence (PEO C4I) is responsible for the program management and technical control over the development, test and evaluation, system and equipment acquisition, and Life Cycle Management (LCM) for all information assurance programs within the Navy. The IA Program Manager (SPAWAR PMW 130) is responsible for the planning, direction, control and integration relating to the acquisition and fielding of information assurance systems, products, and devices within the Navy and Marine Corps.
The Navy IA Program Manager (PEO C4I - PMW 130) has designated 58, as the Navy system security engineering activity for the NSA Crypto Modernization Program and as the Cryptographic Key Management lead engineering activity for the NSA Key Management Infrastructure (KMI) evolutionary development, testing and implementation. In support of these programs 58 will be involved in the engineering and monitoring of cryptographic and key management solutions designed to replace aging Navy cryptographic and key management systems.
Additionally, the NSA, other DOD and federal offices rely on the subject matter expertise assembled by 58 in the area of assured computer and network engineering to include High Assurance Internet Protocol Encryption (HAIPE).
As a US Navy security engineering center for C4I systems, 58 supports PEO C4I- PMW 130, the NSA, Navy IA Technical Authority (SPAWAR), JTNC and coordinates closely with other organizations such as SSC LANT, Naval Network Warfare Command and OPNAV. All coordination, security and system engineering will be done as directed by SPAWAR.
2.0 APPLICABLE DOCUMENTS
The following list of documents is provided for reference and guidance only. In the event of conflict between the requirements of these specifications and the SOW, the requirements of the SOW shall govern. Any additional MIL Documents, used in the individual task orders, shall have been reviewed IAW DOD 4120.24-M, Defense Standardization Program (DSP) Policies and Procedures, and USD Policy Memo 05-3.
2.1 MIL-SPECIFICATIONS
MIL-STD-1472F Human Engineering Design Criteria for Military Systems
MIL-STD-810F Environmental Test Methods and Engineering Guidelines
MIL-STD-961E Defense Specifications
2.2 MIL-HDBK PUBLICATIONS
The following documents are referenced for guidance only nothing in this document of listed reference documents supersedes applicable laws and regulations, unless a specific exemption has been obtained from the government.
MIL-HDBK-881A Work Breakdown Structures
MIL-HDBK-29612/1A Guidance for Acquisition of Training Data Products and Services (Part 1 of 5 Parts)
MIL-HDBK-29612/2A Instructional Systems Development/Systems Approach to Training and Education (Part 2 of 5 Parts)
MIL-HDBK-29612/3A Development of Interactive Multimedia Instruction (IMI) (Part 3 of 5 Parts)
MIL-HDBK-29612/4A Glossary for Training (Part 4 of 5 Parts)
MIL-HDBK-29612/5 Advanced Distributed Learning (ADL) Products and Systems (Part 5 of 5 Parts)
MIL-HDBK-46855A Human Engineering Program Process & Procedures
2.3 OTHER GOVERNMENT PUBLICATIONS
The following documents are referenced for guidance only. Nothing in the listed reference documents supersedes applicable laws and regulations, unless a specific exemption has been obtained from the government. Additionally, the contractor is to recommend appropriate standards and deliverables for systems engineering, process improvement, software development and lifecycle support.
MIL-PRF-29612B Training Data Products
MIL-DTL-31000C Technical Data Packages
DOD-5220-22M Industrial Security Manual for Safeguarding Classified Information
DOD-5220-22-S COMSEC Supplement to Industrial Security Manual for Safeguarding Classified Information.
DOD 8500.1 Information Assurance
DOD 8500.2 Information Assurance (IA) Implementation
DOD-I-5200.40 Information Technology Security Certification and Accreditation Process
DODI 8510.01 DOD IA Certification and Accreditation Process (DIACAP), 12 December 2007
DON CIO DIACAP Handbook, 23 January 2008
DoDI 8510.01 RMF Risk Management Framework (RMF) for DoD Information Technology (IT)
DOD 8570.0 1-M “Information Assurance (IA) Workforce Improvement Program," Incorporating Change 2 issued 20 April 2010
PR-OPD-29 V1.2 SSC San Diego Project Management Guide
CNSS Inst. # 4009 National Information Assurance (IA) Glossary, Committee on National Security Systems (Series)
CJCSI 3170.01H Chairman of the Joint Chiefs of Staff Instruction, Joint Capabilities Integration and Development System, January 2012
CJCSM 3170.01C Chairman of the Joint Chiefs of Staff Manual, Joint Capabilities Integration and Development System, January 2012
2.4 OTHER DOCUMENTS
The following list of documents is provided for reference and guidance only. In the event of conflict between the requirements of these standards or documents and the SOW, the requirements of the SOW shall govern.
CNSS Inst. # 4009 National Information Assurance (IA) Glossary, Committee on National Security Systems (Series)
ISO 9000/ IEEE 1498 International Standards Organization Family of Standards Management
ANS/PMI 99-001-2000 A Guide to the Project Management Body of Knowledge
SSC-PAC Software Engineering Program Office (SEPO) Program Manager's Guide (SSCSD SEPO PMG)
NIST 800-53 Recommended Security Controls for Federal Information Systems & Organizations
Naval SEG, Volume 1 Systems Engineering Guidebook, December 12, 2006
NSA Central Security Service Classification Guide for Quantum Defense 3-17
Additional documents will be referenced in individual task orders as required.
3.0 TECHNICAL REQUIREMENTS
3.1 CRYPTOGRAPHIC AND KEY MANAGEMENT ENGINEERING / CYBERSECURITY ENGINEERING
The contractor shall perform security related engineering; technical, managerial and logistics support functions. This broad program area will require specialized security engineering services to perform architecture design, analysis, test, user training, certification, COTS / GOTS security product analysis and evaluation, product integration and implementation, specialized network configuration and sustainment support functions including those for the current and follow-on generation of security devices/products used in Naval networks.
Typical of the type of services that may be required follow; this is not an all-inclusive list:
3.1.1 Review existing technical and program management documentation. Participate in meetings, conferences and symposia.
3.1.2 Develop and/or analyze security architectures with particular emphasis on cryptographic and key management issues (component, system, systems of systems, etc.).
3.1.3 Support the planning and execution of research and development, test and evaluation through proof of concept opportunities related to cryptographic equipment (including key management aspects); make recommendations for implementation. Support may include live laboratory demonstrations as well as fleet experiments and demonstrations.
3.1.4 Provide engineering analysis in support of the Crypto Modernization effort to ensure that the military services are successful in modernizing their cryptographic inventory and meet the NSA Crypto Modernization tenets.
3.1.5 Provide engineering analysis in support of the Key Management Infrastructure (KMI) effort to ensure that the modernization effort within the military services is successful.
3.1.6 Conduct cryptographic or key management product trade-off analyses and security prototyping and modeling and provide test report documentation.
3.1.7 Provide security engineering analysis, systems engineering, consultation and guidance in areas of new and emerging programs and technology requirements related to cryptographic or key management issues.
3.1.8 Provide cryptographic and key management support for the development of test laboratories including system and software configuration, fault and error isolation, and maintenance and repair.
3.1.9 Provide services in the preparation and coordination of documentation necessary for the proper operation of cryptographic or key management systems or equipment in accordance with DOD and national regulations.
3.1.10 Support security engineering analysis and system engineering related to the introduction of cryptographic or key management systems into developmental and operational networks. Analysis and system engineering efforts may include consideration of the classification of the data, security requirements, and the threats and vulnerabilities to determine the robustness of the solutions.
3.1.11 Support Operational Security (OPSEC) efforts such as the identification of critical information, the analysis of threats and vulnerabilities, the assessment of risks and the application of countermeasures.
3.1.12 Develop, implement and perform life cycle management of cryptographic and key management systems.
3.1.13 Work with NSA Research (R2) for the HAIPE implementation of the Advanced Algorithm Suites (AAS). The contractor shall investigate and provide technical reports/comments on the alternatives for implementing these algorithms for HAIPE Confidentiality, Authentication, and Denial of Service issues.
3.1.14 Collect all applicable requirements documented in the HAIPE Specifications and continue to develop and maintain the requirements for implementing High Assurance Internet Protocol Encryption devices. Collect requirements and threat data from key stakeholders such as ADNS, Defense Information Systems Agency (DISA), NSA Technical Operations Center (NTOC), Department of Homeland Security (DHS), the Armed Services, and Five-Eyes partners to ensure HAIPE devices meet the security and interoperability requirements for US and Five Eyes networks up to the TS//SCI level.
3.1.15 Provide HAIPE software engineering support for the HAIPE program which includes developing software test tools and emulators for the HAIPE protocols and algorithms.
3.1.16 Provide HAIPE testing support to NSA encryption programs which includes performing formal testing of the protocols and algorithms as implemented in certified HAIPE devices.
3.1.17 Development and maintenance of HAIPE CONOPs, HAIPE White Papers, Interoperability Specifications, Management Information Bases (MIB), and Implementation Guides. Responsible for the briefing at HAIPE Implementers' Working Groups which are anticipated to occur twice per year.
3.2 RELATED PROGRAM AND PROJECT LEVEL MANAGEMENT IN SUPPORT OF CRYPTOGRAPHIC AND KEY MANAGEMENT SYSTEMS The contractor shall provide security engineering related management support. Typical, but not all-inclusive types of services that may be required are:
M
3.2.1 Assess current and future system and software project requirements to include upgrades of current product baselines. Recommend tentative approaches and solutions using a variety of tools, techniques, or processes.
3.2.2 Analyze, identify, specify and track current and emerging business opportunities.
3.2.3 Analyze requirements and prepare presentation and briefing material and program, system and business development documents.
3.2.4 Attend technical meetings, conferences, and reviews. Support shall include participation and review of technical packages, and providing after action minutes and reports.
3.2.5 Provide program/project planning and programmatic support including the definition and recommendation of approaches for the research, development, testing, training and evaluation for cryptographic and key management related systems and products. These efforts may involve defining the scope, cost /schedule requirements for all project phases, assess capabilities / requirements, milestones, IV&V requirements / approaches, security accreditation plan, and risk assessments.
3.2.6 Participate in and provide technical guidance during reviews, walk-throughs, requirements tractability analyses, and defined verification and validation processes. Requirements will be traceable, consistent, complete, and testable throughout the development process. This may involve coordination with the appropriate activities, agencies, and development personnel to ensure complete preparation for the review.
3.2.7 Develop network security documents, e.g. Trusted Facility Manual and Security Features User's Guide in accordance with DOD Trusted Computer System Evaluation Criteria, DITSCAP, DIACAP, RMF, etc.
3.2.8 Support/conduct/attend meetings as scheduled to facilitate the exchange of technical information and enhance effective communication.
3.2.9 Develop and present program management reviews as specified in individual task orders to designated government representatives. This may include a summary of technical achievements, schedule status, and cost performance. These reviews shall emphasize progress and problems since the last meeting, plans for the future and establish the date and place for the next meeting.
3.2.10 May develop and conduct formal oral and visual presentations to invited government and industry representative's reviews as specified in individual task orders.
3.3 ENGINEERING AND MANAGEMENT SUPPORT
The contractor shall establish an effective and efficient organization for the security engineering and management support that compliments the working structure of 58 and ensures that a quick response capability is provided.
Typical of the type of services that may be required are:
3.3.1 Assess current and future system and software project requirements to include upgrades of current product baselines. Recommend approaches and solutions using a variety of tools, techniques, or processes.
3.3.2 Analyze, identify, specify and track current and emerging business opportunities related to assured computer and networking as well as integrated circuit design.
3.3.3 Analyze requirements and prepare presentation and briefing material and program, system and business development documents.
3.3.4 Attend technical meetings, conferences, and reviews. Support shall include participation and review of technical packages, and providing reports. The reports shall include description of the meeting, issues, action items, and recommended solutions to issues impacting the program.
3.3.5 Provide milestone support for major division efforts, facilitate and document project team activities, and provide input to the business process modeling and re-engineering.
3.3.6 Participate in and provide technical guidance and assistance during reviews, walk-throughs, requirements tractability analyses, and defined verification and validation processes. Requirements will be traceable, consistent, complete, and testable throughout the development process. For each review, coordination with the appropriate activities, agencies, and development personnel will be conducted to ensure complete preparation for the review.
4.0 CYBERSECURITY COMPLIANCE
Cybersecurity (which replaced the term Information Assurance (IA)) is defined as prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation. Contractor personnel shall perform tasks to ensure Navy applications, systems, and networks satisfy Federal/DoD/DON/Navy cybersecurity requirements.
4.1 CYBER IT AND CYBERSECURITY PERSONNEL
(a) The Cyberspace workforce elements addressed include contractors performing functions in designated Cyber IT positions and Cybersecurity positions. In accordance with DFARS Subpart 239.71, DoDD 8140.01, SECNAVINST 5239.20A, and SECNAV M-5239.2, contractor personnel performing cybersecurity functions shall meet all cybersecurity training, certification, and tracking requirements as cited in DoD 8570.01-M prior to accessing DoD information systems. Proposed contractor Cyber IT and cybersecurity personnel shall be appropriately qualified prior to the start of the contract performance period or before assignment to the contract during the course of the performance period.
(b) The contractor shall be responsible for identifying, tracking and reporting cybersecurity personnel, also known as Cybersecurity Workforce (CSWF) and Cyber IT workforce personnel. Although the minimum frequency of reporting is monthly, the task order can require additional updates at any time.
(c ) Contractors that access Navy IT shall also follow guidelines and provisions documented in Navy Telecommunications Directive (NTD 10-11) and are required to complete a System Authorization Access Request (SAAR) – Navy form as documented in para 8.2.2.4(b).
When a contractor requires logical access to a government IT system or resource (directly or indirectly), the required CAC will have a Public Key Infrastructure (PKI). A hardware solution and software (e.g., ActiveGold) is required to securely read the card via a personal computer. Pursuant to DoDM 1000.13-M-V1, CAC PKI certificates will be associated with an official government issued e-mail address (e.g. .mil, .gov, .edu). Prior to receipt of a CAC with PKI, contractor personnel shall complete the mandatory Cybersecurity Awareness training and submit a signed System Authorization Access Request Navy (SAAR-N) form to the contract’s specified COR. Note: In order for personnel to maintain a CAC with PKI, each contractor employee shall complete annual cybersecurity training. The following guidance for training and form submittal is provided; however, contractors shall seek latest guidance from their appointed company Security Officer and the SSC Pacific Information Assurance Management (IAM) office:
For annual DoD Cybersecurity/IA Awareness training, contractors shall use this site: https://twms.nmci.navy.mil/. For those contractors requiring initial training and do not have a CAC, contact the SSC Pacific IAM office at phone number [insert applicable contract information] (843)218-6152 or e-mail questions to ssc_lant_iam_office.fcm@navy.mil for additional instructions. Training can be taken at the IAM office or online at http://iase.disa.mil/index2.html.
For SAAR-N form, the contractor shall use OPNAV 5239/14 (Rev 9/2011). Contractors can obtain a form from the SSC Pacific IAM office at or from the website: https://navalforms.documentservices.dla.mil/. [insert applicable contract information] Digitally signed forms will be routed to the IAM office via encrypted e-mail to ssclant_it_secmtg@navy.mil.
(d) Contractor personnel with privileged access will be required to acknowledge special responsibilities with a Privileged Access Agreement (PAA) IAW SECNAVINST 5239.20A.
DESIGN, INTEGRATION, CONFIGURATION OR INSTALLATION OF HARDWARE AND
SOFTWARE
The contractor shall ensure any equipment/system installed or integrated into Navy platform will meet the cybersecurity requirements as specified under DoDI 8500.01. The contractor shall ensure that any design change, integration change, configuration change, or installation of hardware and software is in accordance with established DoD/DON/Navy cyber directives and does not violate the terms and conditions of the accreditation/authorization issued by the appropriate Accreditation/Authorization official. Contractors that access Navy IT are also required to follow the provisions contained in DON CIO Memorandum: Acceptable Use of Department of the Navy Information Technology (IT) dtd 12 Feb 16. Use of blacklisted software is specifically prohibited and only software that is registered in DON Application and Database Management System (DADMS) and is Functional Area Manager (FAM) approved can be used as documented in para 5.2.2. Procurement and installation of software governed by DON Enterprise License Agreements (ELAs) – Microsoft, Oracle, Cisco, Axway, Symantec, ActivIdentity, VMware, Red Hat, NetApp, and EMC shall be in accordance with DON CIO Policy and DON ELAs awarded.
CYBERSECURITY WORKFORCE (CSWF) REPORT
DoD 8570.01-M and DFARS PGI 239.7102-3 have promulgated that contractor personnel shall have documented current cybersecurity certification status within their contract. The contractor shall develop, maintain, and submit a CSWF Report as applicable at the task order level. IAW clause DFARS 252.239-7001, if cybersecurity support is provided, the contractor shall provide a Cybersecurity Workforce (CSWF) list that identifies those individuals who are IA trained and certified. Utilizing the format provided at the task order level, the prime contractor shall be responsible for collecting, integrating, and reporting all subcontractor personnel. See applicable DD Form 1423 for additional reporting details and distribution instructions. Contractor shall verify with the COR or other government representative the proper labor category cybersecurity designation and certification requirements.
INFORMATION TECHNOLOGY (IT) SERVICES REQUIREMENTS
This paragraph only applies to IT contracts. Information Technology (IT) is defined as any equipment or interconnected system(s) or subsystem(s) of equipment that is used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data of information by the agency. IT includes computers, ancillary equipment, peripherals, input, output, and storage devices necessary for security and surveillance. Electronic and Information technology (EIT) is IT that is used in the creation, conversion, or duplication of data or information. EIT includes: telecommunication products, such as telephones; information kiosks; transaction machines; World Wide Web sites; multimedia (including videotapes); and office equipment, such as copiers and fax machines.
INFORMATION TECHNOLOGY (IT) GENERAL REQUIREMENTS
When applicable, the contractor shall be responsible for the following:
• Ensure that no production systems are operational on any RDT&E network.
• Follow DoDI 8510.01 of 12 Mar 2014 when deploying, integrating, and implementing IT capabilities.
• Migrate all Navy Ashore production systems to the NMCI environment where available.
• Work with government personnel to ensure compliance with all current Navy IT & cybersecurity policies, including those pertaining to Cyber Asset Reduction and Security (CARS).
• Follow SECNAVINST 5239.3B of 17 June 2009 & DoDI 8510.01 of 12 Mar 2014 prior to integration and implementation of IT solutions or systems.
• Register any contractor-owned or contractor-maintained IT systems utilized on contract in the Department of Defense IT Portfolio Registry (DITPR)-DON.
• Only perform work specified within the limitations of the task order.
ACQUISITION OF COMMERCIAL SOFTWARE PRODUCTS, HARDWARE, AND RELATED
SERVICES
This paragraph only applies to the purchasing/hosting of commercial software. Contractors recommending or purchasing commercial software products, hardware, and related services supporting Navy programs and projects shall ensure they recommend or procure items from approved sources in accordance with the latest DoN and DoD policies.
DON ENTERPRISE LICENSING AGREEMENT/DOD ENTERPRISE SOFTWARE INITIATIVE
PROGRAM
Pursuant to DoN Memorandum – Mandatory use of DoN Enterprise Licensing Agreement (ELA) dtd 22 Feb 12, contractors that are authorized to use Government supply sources per FAR 51.101 shall verify if the product is attainable through DoN ELAs and if so, procure that item in accordance with appropriate ELA procedures. If an item is not attainable through the DoN ELA program, contractors shall then utilize DoD Enterprise Software Initiative (ESI) program (see DFARS 208.74) and government-wide SmartBuy program (see DoD memo dtd 22 Dec 05). The contractor shall ensure any items purchased outside these programs have the required approved waivers as applicable to the program. Software requirements will be specified at the task order level.
DON APPLICATION AND DATABASE MANAGEMENT SYSTEM (DADMS)
The contractor shall ensure that no Functional Area Manager (FAM) disapproved applications are integrated, installed or operational on Navy networks. The contractor shall ensure that all databases that use database management systems (DBMS) designed, implemented, and/or hosted on servers and/or mainframes supporting Navy applications and systems be registered in DoN Application and Database Management System (DADMS) and are FAM approved. All integrated, installed, or operational applications hosted on Navy networks must also be registered in DADMS and approved by the FAM. No operational systems or applications will be integrated, installed, or operational on the RDT&E network.
SECTION 508 COMPLIANCE
This paragraph only applies to IT contracts. The contractor shall ensure that all software recommended, procured, and/or developed is compliant with Section 508 of the Rehabilitation Act of 1973, 26 CFR Part 1194 and pursuant to SPAWARINST 5721.1B of 17 Nov 2009. In accordance with FAR 39.204, this requirement does not apply to contractor acquired software that is incidental to the task, software procured/developed to support a program or system designated as a National Security System (NSS) or if the product is located in spaces frequented only by service personnel for maintenance, repair or occasional monitoring of equipment.
SOFTWARE DEVELOPMENT/MODERNIZATION AND HOSTING
This paragraph only applies to software development and modernization. The contractor shall ensure all programs utilizing this contract for software development/ modernization (DEV/MOD), including the development of IT tools to automate SSC Pacific business processes are compliant with DON Information Management/Information Technology (DON IM/IT) Investment Review Process Guidance requirements. Contractors shall neither host nor develop IT tools to automate SSC Pacific business processes unless specifically tasked within the task order or contract. The contractor shall ensure IT tools developed to automate SSC Pacific business processes will be delivered with full documentation and source code, as specified at the task order level, to allow non-proprietary operation and maintenance by any source. The contractor shall ensure all programs are submitted with proof of completed DEV/MOD certification approval from the appropriate authority in accordance with DON policy prior to task order award. *Note must be listed on Investment Review Board (IRB) approved list.
INFORMATION SECURITY
Pursuant to DoDM 5200.01, the contractor shall provide adequate security for all unclassified DoD information passing through non-DoD information system including all subcontractor information systems utilized on contract. The contractor shall disseminate unclassified DoD information within the scope of assigned duties and with a clear expectation that confidentiality is preserved. Examples of such information include the following: non-public information provided to the contractor, information developed during the course of the contract, and privileged contract information (e.g., program schedules, contract-related tracking).
IT POSITION CATEGORIES
Pursuant to DoDI 8500.01, DoD 8570.01-M, SECNAVINST 5510.30, SECNAV M-5239.2, and applicable to unclassified DoD information systems, a designator is assigned to certain individuals that indicates the level of IT access required to execute the responsibilities of the position based on the potential for an individual assigned to the position to adversely impact DoD missions or functions. As defined in DoD 5200.2-R, SECNAVINST 5510.30 and SECNAV M-5510.30, three basic DoN IT levels/Position categories exist:
• IT-I (Privileged access)
• IT-II (Limited Privileged, sensitive information)
Note: The term IT Position is synonymous with the older term Automated Data Processing (ADP) Position (as used in DoD 5200.2-R, Appendix 10). Investigative requirements for each category vary, depending on the role and whether the individual is a U.S. civilian contractor or a foreign national. The Contractor PM shall assist the Government Project Manager or COR in determining the appropriate IT Position Category assignment for all contractor personnel. All required Single-Scope Background Investigation (SSBI)/Tier 5, SSBI Periodic Reinvestigation (SSBI-PR)/Tier 5R, and National Agency Check (NAC)/Tier 3R adjudication will be performed Pursuant to DoDI 8500.01 and SECNAVINST 5510.30. Requests for investigation of contractor personnel for fitness determinations or IT eligibility without classified access are submitted by SPAWAR/SSC Atlantic/SSC Pacific Security Office, processed by the OPM, and adjudicated by DOD CAF. IT Position Categories are determined based on the following criteria:
IT-I Level (Privileged) - Positions in which the incumbent is responsible for the planning, direction, and implementation of a computer security program; major responsibility for the direction, planning and design of a computer system, including the hardware and software; or, can access a system during the operation or maintenance in such a way, and with a relatively high risk for causing grave damage, or realize a significant personal gain. Personnel whose duties meet the criteria for IT-I Position designation require a favorably adjudication of Single Scope Background Investigation (SSBI)/Tier 5 or SSBI-PR/Tier 5R. The SSBI/Tier 5 or SSBI-PR/Tier 5R is updated a minimum of every 5 years. Assignment to designated IT-I positions requires U.S. citizenship unless a waiver request is approved by CNO.
IT-II Level (Limited Privileged) - Positions in which the incumbent is responsible for the-direction, planning, design, operation, or maintenance of a computer system, and whose work is technically reviewed by a higher authority at the IT-II Position level to insure the integrity of the system. Personnel whose duties meet the criteria for an IT-II Position require a favorably adjudication of a Position of Trust National Agency Check with Law and Credit (PT/NACLC)/Tier 3R. Assignment to designated IT-II positions requires U.S. citizenship unless a waiver request is approved by CNO.
IT-III Level (Non-privileged) - All other positions involved in computer activities. Incumbent in this position has non-privileged access to one or more DoD information systems/applications or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III Position designation require a favorably adjudication of a Position of Trust National Agency Check with Written Inquiries (PT/NACI).
5.0 TRAVEL
Travel will be required in the execution of task orders for the purpose of participation in research efforts, defining system security requirements, security evaluation and testing, installation and installation planning, testing and troubleshooting, attending planning conferences, program audits and reviews, management reviews, and other areas of program support and field activity coordination. Specific travel requirements will be identified in the individual task orders.
6.0 GOVERNMENT FURNISHED EQUIPMENT/INFORMATION (GFE/GFI)
If required GFE/GFI will be identified under individual task orders.
7.0 OTHER
7.1 SECURITY
The nature of this task requires access to Secret information. The work performed by the Contractor will include access to unclassified and up to Secret data, information, spaces, and have access to Communications Security (COMSEC). The Contractor will be required to attend meetings classified up to Secret level. However, there may be exceptions at the task order level where Top Secret (TS)/Sensitive Compartmented Information (SCI) will be required.
Contractor personnel assigned to this effort who require access to SCI data and spaces must possess a current SSBI with ICD 704 eligibility (which replaced DCID 6/4 eligibility).
Although there is no requirement for the contractor to access NATO on this contract per Naval Intelligence Security Policy Directive 17-008 those contractors that have SCI access and those cleared SCI with Joint Worldwide Intelligence Communications System (JWICS) or Secure Internet Protocol Router Network (SIPRNet accounts shall be North Atlantic Treaty Organization (NATO) read-on and complete the derivative classification training prior to being granted access to JWICS/SIPRnet; training is provided by the facility security officer. Specific requirements provided in the Department of Defense Contract Security Classification Specification, DD Form 254.
Contractors performing tasks at the TS or below level without SCI access shall only receive the NATO awareness brief and complete the derivative classification training prior to being granted access to SIPRnet; training is provided by the facility security officer.
As required by National Industrial Security Program Operating Manual (NISPOM) Chapter 1, Section 3, contractors are required to report certain events that have an impact on: 1) the status of the facility clearance (FCL); 2) the status of an employee's personnel clearance (PCL); 3) the proper safeguarding of classified information; 4) or an indication that classified information has been lost or compromised. Contractors working under SSC Pacific contracts will ensure information pertaining to assigned contractor personnel are reported to the Contracting Officer Representative (COR)/Technical Point of Contact (TPOC), the Contracting Specialist, and the Security's COR in addition to notifying appropriate agencies such as Cognizant Security Agency (CSA), Cognizant Security Office (CSO), or Department Of Defense Central Adjudication Facility (DODCAF) when that information relates to the denial, suspension, or revocation of a security clearance of any assigned personnel; any adverse information on an assigned employee's continued suitability for continued access to classified access; any instance of loss or compromise, or suspected loss or compromise, of classified information; actual, probable or possible espionage, sabotage, or subversive information; or any other circumstances of a security nature that would affect the contractor's operation while working under SSC Pacific contracts.
If foreign travel is required, all outgoing Country/Theater clearance message requests shall be submitted to Commanding Officer, Attn: Foreign Travel Team, Space and Naval Warfare Systems Center Pacific, 53560 Hull Street, Building 27, 2nd Floor -Room 206, San Diego, CA 92152 for action. A Request for Foreign Travel form shall be submitted for each traveler, in advance of the travel, to initiate the release of a clearance message at least 30 days in advance of departure. Each Traveler must also submit a Personal Protection Plan and have a Level 1 Antiterrorism/Force Protection briefing within one year of departure and a country specific briefing within 90 days of departure.
Anti-Terrorism/Force Protection (AT/FP) briefings are required for all personnel (Military, DOD Civilian, and contractor) per OPNAVINST F3300.53C. Contractor employees must receive the AT/FP briefing annually. The briefing is available at Joint Knowledge Online (JKO): https://jkodirect.jten.mil (prefix): course number: US007; title: Level 1 Anti-terrorism Awareness Training, if experiencing problems accessing this website contact ssc_fortrav@navy.mil. Forward a copy of the training certificate to the previous email address or fax to (619) 553-6863. Sere 100.2 Level A code of conduct training is also required prior to Oconus travel for all personnel. Sere 100.2 Level A training can be accessed at http://jko.jfcom.mil (recommended), https://jkodirect.jten.mil/atlas2/faces/page/login/login.seam, recommended course: prefix: J3T: course #: A-US1329, for civilian, military, and contractors. Personnel utilizing this site must have a CAC. A Sere 100.2 Level A training disk can be borrowed at the SSC Pacific Point Loma Office or Old Town Campus Office. Specialized training for specific locations, such as SOUTHCOM human rights, or U.S. forces Korea entry training, may also be required; SSC Pacific security personnel will inform you if there are additional training requirements.
Finally, EUCOM has mandated that all personnel going on official travel to the EUCOM AOR must now register with the Smart Traveler Enrollment Program (STEP). When you sign up, you will automatically receive the most current information the State Department compiles about your destination country. You will also receive updates, including Travel Warnings and Travel Alerts. Sign up is one-time only, after you have established your STEP account, you can easily add official or personal travel to anywhere in the world, not just EUCOM. http://travel.state.gov/content/passports/en/go/step.html
Operations Security (OPSEC). OPSEC is a five step analytical process (identify critical information; analyze the threat; analyze vulnerabilities; assess risk; develop countermeasures) that is used as a means to identify, control, and protect unclassified and unclassified sensitive information associated with U.S. national security related programs and activities. All personnel working under this task will at some time handle, produce or process Critical Information or Critical Program Information, and therefore all Contractor personnel must practice OPSEC. All work is to be performed in accordance with DoD OPSEC requirements, and in accordance with the OPSEC attachment to the DD254.
Applicable documents are as follows OPNAVINST F3300.53C (Series), Navy Antiterrorism Program SECNAV Manual 5510.30 (Series), Department of Navy Personnel Security Program, SECNAV Manual 5510.36 (Series), Department of Navy Information Security Program, DOD 5200.01 Volumes 1 through 4 (Series), DOD Security Program, and DOD 5220.22-M (Series), National Industrial Security Program Operating Manual (NISPOM), National Security Decision Directive 298 (Series), National Operations Security Program (NSDD) 298, DOD 5205.02-M, DOD Operations Security (OPSEC) Program, OPNAVINST 3432.1A, DON Operations Security, and SPAWARINST 3432.1A, Operations Security Policy.
6.2 PLACE OF PERFORMANCE
It is anticipated that 95% of the tasking will be performed on Government Site and 5% on Contractor Site.
6.3 CYBER SECURITY WORKFORCE (CSWF) IMPROVEMENT PROGRAM
The technical performer(s) assigned the services will require both logical and physical access to sensitive Government information systems (IS). The work will require privileged access to Government IS at both the computer network (CN) and the computing element (CE) level in the Microsoft Windows environment. Performer will require CSWF certification appropriate to the level of access needed to perform the requirements outlined in the task statements. In addition, these levels of qualification shall be achieved at the time of award. The contractor will be required to submit an IAWF performer roster not later than date of award plus twenty (20) working days.
7.0 ACCEPTABLE QUALITY LEVELS
Each task order performance work statement will have quality levels specifically tailored for those tasks.
8.0 ENTERPRISE CONTACTOR MANPOWER REPORTING APPLICATION (ECMRA)
The contractor shall report contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for SSC Pacific via a secure data collection site. Contracted services excluded from reporting are based on Product Service Codes (PSCs). The excluded PSCs are:
(1) W, Lease/Rental of Equipment;
(2) X, Lease/Rental of Facilities;
(3) Y, Construction of Structures and Facilities;
(4) D, Automatic Data Processing and Telecommunications, IT and Telecom- Telecommunications Transmission (D304) and Internet (D322) ONLY;
(5) S, Utilities ONLY;
(6) V, Freight and Shipping ONLY.
For purposes of ECMRA reporting, the Product Service Code applicable to each task order will be specified at the task order level.
The contractor is required to completely fill in all required data fields using the following web address: https://www.ecmra.mil.
Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. Contractors may direct questions to the help desk, linked at https://www.ecmra.mil.
9.0 REPORTS, DATA AND DELIVERABLES
The deliverables associated with each individual task order may be data in the form of plans, specifications, drawings, procedures, reports, technical documentation, or training materials. These deliverables shall be provided in accordance with the Contract Data Requirements List, DD Form 1423, as specified in individual task orders. All deliverables are subject to SSC PAC review and approval before final acceptance.
File details come from the government source that posted it. Updated .