PERFORMANCE WORK STATEMENT-_CVDD_FINAL_03072024.pdf
PDF 330 KB Posted
- Attached to
- DC3 Crowdsourced Vulnerability Discovery and Disclosure (CVDD) - Bug Bounty Federal contract opportunity
- Solicitation number
- FA701424RXXXX
About this file
This document is a Performance Work Statement (PWS) for the Department of Defense (DoD) Crowdsourced Vulnerability Discovery and Disclosure (CVDD) program, also known as a "bug bounty" program. The objective is to leverage commercial crowdsourcing expertise to support the DoD Vulnerability Disclosure Program and enhance its information security.
The PWS outlines the requirements for the contractor to host a secure portal and facilitate crowdsourced vulnerability discovery and disclosure activities against DoD networks, systems, and information. Key tasks include vetting and managing a pool of security researchers, triaging and validating vulnerability reports, facilitating communication with DoD remediation teams, and securely storing and transferring vulnerability information. The contractor must also provide transition activities, deliverables, and comply with various security and administrative requirements. The resulting contract will be an Indefinite Delivery Indefinite Quantity (IDIQ) vehicle, with individual task orders issued to execute the CVDD services.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CUI FA7014‐XX-X-XXXX
CUI
PERFORMANCE WORK STATEMENT
FOR
Crowdsourced Vulnerability Discovery and Disclosure (CVDD)
AT
Department of Defense Cyber Crime Center (DC3)
7 March 2024
Controlled by: AFDW/PK CUI Categories: PROCURE Distribution/Dissemination Controls:
FEDCON AFTER AWARD
POC: CO NAME (240-612-xxx)
Table of Contents
SECTION I
DESCRIPTION OF SERVICES
1.1 General
1.1.1 Scope
1.1.2 Background
SECTION II
2.0 TASK DESCRIPTIONS
2.1 TRANSITION ACTIVITIES
SECTION III
3.0 SERVICE SUMMARY
3.1 Purpose
3.2 Components
3.3 Right to Surveil
3.4 Task Scope
SECTION IV
4.0 DELIVERABLES
SECTION V
5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,
INFORMATION, OR SERVICES
5.1 Contractor Acquired Property .............................................. Error! Bookmark not defined.
SECTION VI
6.0 GENERAL INFORMATION
6.1 Scheduling Concerns
6.1.1 Duty Hours
6.1.2 Core Duty Hours and Base Shutdown/Inclement Weather
6.2 Kickoff Meeting/Orientation Meeting
6.2.2 Agenda
6.2.3 Kickoff Meeting Location
6.3 Emergency Operations/Mission Essential Personnel
6.3.1 Continuation of Essential Contractor Services During Crisis
6.4 System for Award Management (formerly CMRA)
6.4.1 Subcontractor Input in SAM
6.5 Security Instructions
6.5.1 Physical Security
6.5.2 Access Control
6.5.3 Pass and Identification Items
6.5.4 Retrieving Identification Media
6.5.5 Traffic Laws
6.5.6 Weapons, Firearms, and Ammunition
6.5.7 Communications Security (COMSEC)
6.5.8 Contractor Identification
6.5.9 Drug, Tobacco, and Alcohol Use Policy
6.6 Travel
6.6.1 Local Travel
6.6.2 CONUS Travel
6.6.4 Trip Reports
6.7 Employee Accountability & Turnover
6.7.1 Staffing of Contractor Personnel
6.7.2 List of Employees
6.7.3 Contractor Professionalism
6.8 Miscellaneous Paragraphs
6.8.1 Freedom of Information Act (FOIA)
6.8.2 Controlled Unclassified Information (CUI)
6.8.3 Privacy Act
6.8.4 Records
6.8.5 Safety Concerns
6.8.6 Project Policy
6.8.7 Inherently Governmental Functions
6.8.8 Ethics
6.8.9 Professional Appearance of Workspace
6.8.10 Non-Personal Services
SECTION VII
APPENDIX 1
1.0 DEFINITIONS, ABBREVIATIONS, AND ACRONYMS
2.0 ACRONYMS
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 GENERAL
The Government intends to use existing commercial crowdsourcing expertise with the assistance of the private sector to support the Department of Defense (“DoD”) Vulnerability Disclosure Program (VDP) in the application of the crowdsourcing methodology to enhance its information security. In support of this objective, the DoD intends to partner with a commercial firm(s) that has experience with administering Crowdsourced Vulnerability Discovery and Disclosure (“CVDD”) Services. Under resulting task orders, firm(s) awarded and Indefinite Delivery Indefinite Quantity (IDIQ) for this requirement will host crowdsourced security activities.
1.2 SCOPE
The Department of Defense (DoD) will execute a critical bounty (hacker-cyber) program, IAW with Public Law 115-390, “SECURE Technology Act” across the full range of networks, systems, and information, including web applications, software, source code, software-embedded devices and other technologies as solicited across the whole Department of Defense including Industrial Control Systems (ICS), as part of those network assets.
System Platform(s): The Contractor must own and maintain a platform to facilitate crowdsourced vulnerability discovery and disclosure activities.
The System Platform requirements are as follows:
1.2.1 The capability to accept vulnerability reports from managing researchers.
1.2.2 The capability to apply tools and processes, automated and manual, to triage reports for the Government. This includes de-duplication of reports within 48 hours of receipt.
1.2.3 The capability to ensure that vulnerability reports, transmitted to Government remediators, are clear and of high quality. This will ensure that Government personnel can immediately remediate identified vulnerabilities.
1.2.4 The capability to facilitate effective communication between the triage team and managing researchers and between the triage team and Government System Owner remediators. This may include corresponding, separately, with multiple teams.
1.2.5 The capability to facilitate the secure transmission and storage, of vulnerability information, and adhere to ISO standards.
1.2.6 The capability to implement continuous monitoring as well as auditing tools, to monitor and assess, researcher behavior.
1.2.7 The capability to capture and inspect encrypted researcher traffic, such as through a Transport Layer Security (TLS) interception proxy.
1.2.8 The capability to function as a secure portal capable of continuous monitoring and auditing of researcher activities, such as those logs collected through simple proxy logging, as identified at the task order level.
1.2.9 Accounts using login/password and emailed Multifactor Authentication (MFA) will be provided to the managing researchers. The managing researchers will be set up with accounts that have the least privileges in the system, as the primary goal is to assess access controls.
1.2.10 The system does allow for data submission via forms, but managing researchers will not have access to this by default.
1.2.11 The system will be in scope, 24/7 for twenty-one (21) business days. There may be a period where the system needs to go offline for maintenance. If this downtime is longer than eight (8) hours, the Government will extend the duration of the event by one (1) day with an additional day for each day the outage extends into.
1.2.12 Ensure reports submitted are done so in accordance with best practices for safe testing and disclosure not to cause harm to the systems in question.
1.2.13 The Contractor must ensure that any bounties paid to managing researchers are in accordance with current US Government sanctions and policies regarding payments to foreign nationals. Managing Researchers must be diverse in skillset, and able to conduct source code analysis, reverse engineering, and network and system exploitation.
1.2.14 The bounty execution itself is expected to last for a period of 28 days business days.
1.2.15 All findings will be sent to the DC3 CVDD program office for triaging, validation, and remediation processing to be included in the Vulnerability Report Management Network (VRMN) pronounced “vərmən”.
1.3 BACKGROUND
Crowdsourcing is a modem business practice that, as of 2010, the Federal government has employed to obtain needed services, ideas, or content by soliciting contributions from a large group of people rather than from traditional employees or suppliers. Crowdsourcing incentivizes innovation in solving mission-centric problems. Remaining ahead of present and emerging cyber threats is a significant responsibility in any environment. For DoD the responsibility is amplified as the repercussions associated with security failure are severe.
1.3.1 In 2016, Department of Defense Cyber Crime Center (C3) DoD VDP was launched to serve as an enduring program for all crowdsourced vulnerability disclosure reporting and remediation for Joint Force Headquarters DoD Information Networks (JFHQ-DODIN) and U.S.
Cyber Command (USCC). For the last 4+ years DDS has been at various stages of transferring all or a portion of the HTP duties to DOD VDP. In 2022 DDS was included into the new Chief Data and Artificial Intelligence Office (CDAO) and now wishes to “partner” with DC3 so the VDP program can take over the running and operation of some standardized bug bounty events to allow them to forge new trails on “pathfinder” bug bounties that have not been conducted before. (See Glossary to terminology definitions).
1.3.2 The DoD’s computer networks and systems support the nation’s defense and are critical both for daily business operations and mission- critical activities. Maintaining the security and integrity of the DoD’s networks and systems is a matter of national security and requires the continuous identification and remediation of vulnerabilities that can be exploited by malicious cyber actors. As part of its responsibility to the public at large, DoD is constantly considering innovative and diverse approaches to meet this goal.
1.3.3 To support DoD’s continual efforts to remain at the forefront of rapidly evolving technologies, and to maintain the highest levels of integrity and security required of its IT infrastructure, DoD has identified an emerging need to leverage a diverse pool of innovative information security researchers (herein referred to as “researcher” or “managing researcher”), via crowdsourcing, for crowdsourced vulnerability discovery, coordination, and disclosure activities.
SECTION II
2.0 TASK DESCRIPTIONS
2.1. All UNCLASSIFIED vulnerability assessments for the specific asset relative to this effort will be provided to the Contractor by the DoD. Access to the asset and the asset owners will be provided to the contractor upon task order award. This requirement involves enabling researchers to conduct auditable crowdsourced vulnerability discovery and disclosure activities through a secure portal on the contractor’s platform against sensitive, but internet connected assets, and non-internet connected assets.
2.1.1. Each challenge will be divided between three (3) distinct phases. The phases, PREPARATION, CHALLENGE, and POST-CHALLENGE, will vary in length and depends on the scope of the challenge. Further details, specific to each phase, are listed in this section of the
PWS.
2.1.2. The PREPARATION PHASE in which the contractor conducts activities to tailor their existing platform for the challenge, invite and vet researchers is not to exceed 14 calendar days.
The platform must include a secure portal for full packet capture capabilities to enable auditability and continuous monitoring of researcher activities.
PREPARATION PHASE. The Contractor must:
2.1.2.1 Conduct criminal background checks on all researchers before granting them access to any DoD information.
2.1.2.2 Provide comprehensive vulnerability report triaging, validation, and prioritization within 48 hours of submission, and reporting to the DoD Remediation Teams to ensure it can patch the vulnerability as soon as possible.
2.1.2.3 Provide the secure portal through which all testing occurs with full packet capture capabilities to enable continuous monitoring and auditability.
2.1.2.4 Provide and submit all crowdsourced vulnerability reports.
2.1.2.5 Strategically recruit the best-suited researchers based on their proven experience, and their known skillset, given the challenge (source code, operational functionality). Conduct all management and coordination with researcher community and project management and coordination with DoD Remediation Teams.
2.1.2.6. Coordinating the disclosure of vulnerabilities affecting third party organizations/vendors. This requirement will be limited to U.S., Five Eyes (FVEY - Australia, Canada, New Zealand, UK and US) and North Atlantic Treaty Organization (NATO --Albania, Belgium, Bulgaria, Canada, Croatia, Czech Republic, Denmark, Estonia, France, Germany, Greece, Hungary, Iceland, Italia, Latvia, Lithuania, Luxembourg, Montenegro, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Turkey, the United Kingdom, the United States) citizens who have passed criminal background checks. No participant may be a dual citizen of a non-FVEY or non- NATO nation. It is the sole responsibility of the contractor to communicate and coordinate with the researchers. It is expected that researcher capacity will be limited to approximately 70-100 of the most highly skilled researchers. The Contractor is expected to recruit managing researchers with experience against these types of assets (e.g., static and dynamic testing and computer network exploitation).
2.1.3. CHALLENGE PHASE. The Contractor must:
2.1.3.1 Communicate vulnerability discovery and disclosure rules of engagement and legal parameters to managing researchers.
2.1.3.2 Communicate vulnerability reporting standards and requirements to managing researchers.
2.1.3.3 Conduct full packet capture of all researcher activities.
2.1.3.4 Integrate appropriate controls over researcher traffic, include a secure portal for full packet capture capabilities to enable auditability and continuous monitoring of researcher activities.
2.1.3.5 Flag improper, suspicious, or out-of-scope testing conducted by managing researchers for DoD.
2.1.3.6 Use existing platform to receive and aggregate vulnerabilities identified by managing researchers, and ensure vulnerability reports are of high-qualify enabling efficient remediation efforts.
2.1.3.7 Complement researcher efforts with automated testing tools for source code analysis, host and application scanning, and vulnerability analysis, if applicable.
2.1.3.8 Ensure subcontractors and security researchers adhere to rules and restrictions as consented to prior to registration and throughout the whole challenge.
2.1.3.9 Triage incoming vulnerability reports through both automated and manual techniques based on severity to identify submissions most impactful to the DoD asset owner and communicate and assign those vulnerabilities to the DoD Remediation Team based upon mutually agreed upon escalation policies.
2.1.3.10 Identify duplicate vulnerability reports, and filter out other reports that are ineligible or out of scope, preferably utilizing existing automation tools.
2.1.3.11 Ensure submitted vulnerability reports are complete, and contain a severity assessment, description, detailed reproductive steps, and recommended remediation fix so DoD can remediate the vulnerability when it is reported.
2.1.4 POST CHALLENGE PHASE. The Contractor must:
2.1.4.1 Coordinate with researchers and the designated DoD Remediation Team to ensure open vulnerability reports are adjudicated and closed out to the level of satisfaction of DoD personnel.
2.1.4.2 As appropriate, provide packet capture and other logs to DoD.
2.1.4.3 Write a final report.
2.1.4.4 Manage and facilitate the secure, legal payment of monetary and non-monetary awards to managing researchers for validated and qualifying vulnerability reports.
2.1.4.5 The Contractor will effectively communicate and coordinate with prospective as well as current researchers to ensure smooth user experience.
2.1.5 DURATION OF ALL PHASES. The Contractor must:
2.1.5.1 During the whole period of performance, the Contractor will effectively communicate and coordinate with prospective researchers to ensure smooth user experience;
2.1.5.2 Communicate electronically with researchers at each stage of the vulnerability life cycle, including initial receipt, remediation, and acknowledgement/reward,
2.1.5.3 Securely manage the storage and distribution of credentials to researchers to enable remote vulnerability discovery and disclosure activities against assets that require trusted relationships/connections,
2.1.5.4 Ensure that the vulnerability discovery and disclosure process can adhere to common international standards for handling vulnerability data, such as ISO 29147 and ISO 30111, and
2.1.5.5 Deliver status reports at the end of the PREPARATION, CHALLENGE, and POST- CHALLENGE phases. Deliver final report at the end of the task order.
2.1.5.6 Notify DoD within 12 hours if a researcher violates the rules of engagement of restrictions. Contractor will be required to submit additional information requested about such action.
2.2 TRANSITION ACTIVITIES
2.2.1 Transition (in and out) activities will be specified at the task order level. They will consist of activities that the Contractor is expected to do to prepare for beginning work in the PREPARATION PHASE and activities that the Contractor is expected to do before ending performance under a task order.
2.2.1.1. Transition-In: At the commencement of the period of performance, the contractor is responsible during the PREPARATION PHASE of the process, for the following transition-in activities:
2.2.1.2 Identify appropriate triage team, and technical lead for the designated challenge.
2.2.1.3 Identify researchers that may be best suited with an adequate skill set, especially for source code challenge, to recruit.
2.2.2 Transition-Out: At the end of the task order period of performance, the contractor is responsible for the following transition-out activities:
2.2.2.1 Deliver a final report that rolls up all data from end of each phase status reports, including activity metrics and coverage analytics, researcher vulnerability discovery and remediation metrics, vulnerability submission volume, triage speed, signal-to-noise ratio, and patch effectiveness and lessons learned from the challenge.
2.2.2.2 Transfer all vulnerability reports from Contractor’s platform to DC3 VDP Vulnerability Report Management Network (VRMN) prior to removal from Contractor platform.
2.2.2.3 Delete all vulnerability reports from the platform on the last day of each task order’s period of performance.
SECTION III
3.0 SERVICE SUMMARY
The Contractor service requirements are summarized into performance objectives that relate directly to mission essential items. The performance threshold briefly describes the minimum acceptable levels of service required for each requirement and will be assessed on an “ACCEPTABLE” or “UNACCEPTABLE” basis. These thresholds are critical to mission success.
3.1 Purpose. The Services Summary (SS), Table 1 Services Summary Table, lists performance objectives for the required services the Government will surveil. The absence of any contract requirement from the SS shall not detract from its enforceability nor limit the rights or remedies of the Government under any other provision of the contract including the clauses entitled “Inspection of Services” or “Inspection” or “Default” in Section E and Section I of the contract.
3.2 Components. The SS states the performance objective (required service), and threshold (performance standard, accept and reject points (if applicable)) in either a qualitative or quantitative fashion for each critical success factor.
3.3 Right to Surveil. The Government reserves the right to surveil all services and requirements called for in this PWS IAW FAR Part 52.246-4 to determine whether the Contractor is meeting performance objectives and goals. The SS reflects the objectives and thresholds used to track Contractor performance for the contract.
Performance Objective
PWS
Refere
Performance Threshold Method of Surveillance
SS – 1 Duration of All Phases
2.1.5.4 Performance is ACCEPTABLE when the
researchers can adhere to common international standards for handling vulnerability data, such as ISO 29147 and ISO 30111. The Contractor shall provide written confirmation that researchers meet metric.
100% Surveillance
SS – 2 Non- Disclosure Agreement
6.5 Performance is ACCEPTABLE when:
NDAs are submitted to the COR to ensure all candidates meet the minimum requirements five (5) business days after contract award.
100% Surveillance
3.4 Task Scope. The Contractor will operate and manage each of the three assessments: pre-assessment, assessment, and post-assessment. The allowed time to complete the three phases to operate and manage the research operations is twelve (12) weeks from contract award.
The Contractor shall not exceed 12 weeks to operate and manage each of the assessments without coordinating with the COR or CO. The Contractor shall obtain written approval from the Government to exceed the twelve (12) weeks.
Furthermore, the Contractor shall complete the pre-assessment, assessment, and post-assessment to operate and manage each event within two (2) months and the Government will issue the task order.
The Government reserves the right to determine the exact start date and end date for the Contractor to perform the three phases, PREPARATION, CHALLENGE and POST- CHALLENGE to operate and manage each of the assessments: pre-assessment, assessment, and post-assessment. The Government will coordinate these two dates with the Contractor to ensure the Contractor operates and manages each of the assessments (PREPARATION, CHALLENGE, and POST-CHALLENGE) within twelve (12) weeks. The Government and Contractor shall coordinate the start and date to operate and manage each of the assessments via email or other suitable, mutually agreed-upon method.
The start and end dates to operate and manage each of the assessments.
SECTION IV
4.0 DELIVERABLES
The Contractor shall provide deliverable(s) using Microsoft Office suite of tools (e.g., MS Word, MS Excel, MS PowerPoint), or Adobe PDF format, unless otherwise specified by the Contracting Officer’s Representative (COR). Electronic submission shall be made via email, unless otherwise agreed to by the COR. The COR has the right to reject to reject or require correction of any deficiencies found in the deliverables. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection.
The following enumerated deliverables are not expected to change. Due Date intervals are not expected to change but actual dates may need to be revised depending on actual contract start date.
DELIVERABLE PWS
PARA
DUE DATE DELIVERY
DD – 1 Final Report 2.2.2.1 Performance is ACCEPTABLE when the Final Report is delivered within 5 days post-assessment. The report shall include:
· An executive summary of findings.
· Impact of findings to the DC3 mission
· Conclusions based on the Contractor’s experience with bounties
· Lessons learned
Within five (5) calendar days of contract execution
DD - 2 Transfer Vulnerability Reports
1.2.15 Performance is ACCEPTABLE when
the Contractor provides written confirmation that all vulnerability reports have been transferred from Contractor’s platform to DC3 VDP Vulnerability Report Management Network (VRMN) prior to removal from Contractor platform.
Within 24 hours to COR via MS Word Document
DD – 3 Delete Vulnerability Reports
2.2.2.3 Performance is ACCEPTABLE when
The Contractor removes vulnerability reports from the platform on the last day of each task order’s period of performance within five (5) business days of the post-assessment.
Within 24 hours to the COR via MS Word Document confirming deletion
SECTION V
5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,
INFORMATION, OR SERVICES
The Government will provide technical information, material, and forms unique to the Government for supporting the task. The DoD will provide the results of the most recent penetration test or security assessment to the Contractor prior to the Challenge Phase.
Government unique information, including software, system configuration files, IP ranges, and other Government unique information related to this requirement, which is necessary for Contractor performance, will be made available to the Contractor. If access to services on any DoD internal networks (i.e., NIPRNet) is required, the Government will ensure any access is remotely available to the Contractor in order to make the challenge successful. The COR will be the point of contact for identification of any required information to be supplied by the Government. Government Furnished Materials also includes any information received during the challenge from Government employees.
SECTION VI
6.0 GENERAL INFORMATION
6.1 Scheduling Concerns
6.1.1 Duty Hours
The Contractor shall have access to Government facility five (5) business days per week, Monday through Friday, eight hours a day, except when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings, unless otherwise approved. Contractor personnel are expected to conform to customer agency normal operating hours; however, the Contractor may be required access to Government facility outside of duty hours based on the customer agency’s needs. As a baseline, Contractor personnel shall work 8 hours per day, 40 hours per week. Compensatory time arrangements are permissible for temporary spikes in worktime; but overtime pay is prohibited without COR and CO approval. Federal Holidays shall be observed in accordance with Office of Personnel Management policy. The following Federal holidays are observed under this contract:
Holiday Date New Year’s Day 01 January Martin Luther King’s Birthday Third Monday in January President’s Day Third Monday in February Memorial Day Last Monday in May Juneteenth 19 June (or observed date) Independence Day 4 July Labor Day First Monday in September Columbus Day Second Monday in October Veteran’s Day 11 November Thanksgiving Day Fourth Thursday in November Christmas Day 25 December Inauguration Day 20 January (NCR only)
6.1.2 Core Duty Hours and Base Shutdown/Inclement Weather
Core duty hours are 0800 – 1600, Monday through Friday (excluding federal holidays). The Contractor shall follow guidance of the installation containing their place of performance to determine reporting schedules whether due to a base closure or inclement weather. The website for guidance regarding status of performance for work to be performed in the National Capital Region (NCR) is http://www.opm.gov/status/.
6.2 Kickoff Meeting/Orientation Meeting
The Contractor shall schedule and coordinate a Project kick-off Meeting no later than (NLT) five
(5) calendar days after contract award at the location approved by the Government. The meeting will provide an introduction between the Contractor personnel and Government personnel who will be involved with the contract. The meeting will provide the opportunity to discuss technical, management, and logistic issues; travel authorization; communication process between Government and Contractor; and reporting procedures. At a minimum, the attendees shall include key Contractor personnel, OFFICE (SAF/# or AF/#), key Government representatives, and the COR.
The Contractor shall provide a Kick-Off Meeting Agenda that will include, but not be limited to, the following:
6.2.1 Introduction of personnel
6.2.2 Overview of project tasks
6.2.3 Review of organization (complexity)
6.2.4 Schedule (shows major tasks, milestones, and deliverables; planned and actual start and completion dates for each)
6.2.5 Communication Plan/lines of communication overview (between both Contractor and
Government)
6.2.6 Discussion of draft Program Management Plan (PMP)
6.2.7 Travel notification and processes
6.2.8 Government-furnished information (GFI)
6.2.9 Security requirements (Building access, badges, Common Access Cards (CAC)
6.2.10 Analytical Support Status Accreditation (ASSA) Documentation
6.2.11 Invoice procedures
6.2.12 Monthly meeting dates
6.2.13 Reporting Requirements, e.g., Monthly Status Report (MSR)
6.2.14 Point of Contacts (POCs)
6.2.15 Roles and Responsibilities
6.2.16 Overview of incoming Transition Plan to include process, timeframes, and status.
6.2.17 Prioritization of Contractor activities
6.2.18 Any initial deliverables
6.2.19 Other logistic issues
6.2.20 Quality Control Plan (QCP)
6.2.21 Sensitivity and protection of information
6.2.22 Additional issues of concern (Leave/back-up support)
6.2.2 Agenda
The Contractor shall provide a draft copy of the agenda NLT three (3) days after contract award for review and approval by the COR prior to finalizing. The Government will provide the http://www.opm.gov/status/
Contractor with the number of participants for the kick-off meeting and the Contractor shall provide sufficient copies of the presentation for all present.
6.2.3 Kickoff Meeting Location
The location of the Kickoff Meeting will be held at the (Government's or Contractor’s) facility or another designated location and the date and time will be mutually agreed upon by both parties.
6.3 Emergency Operations/Mission Essential Personnel
6.3.1 Continuation of Essential Contractor Services During Crisis
All services in this PWS HAVE NOT been defined or designated as essential services for performance during crisis IAW DFARs 252.237-7023, “Continuation of Essential Contractor Services.”
6.4 System for Award Management (formerly CMRA)
The Contractor shall report ALL labor hours (including subcontractor labor hours) required for performance of services provided under this contract via the System for Award Management (SAM) data collection site. The Contractor is required to completely fill in all required data fields at http://www.SAM.gov. Reporting inputs shall be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September. The UIC for AFDW is FF16M0. While inputs may be reported anytime during the FY, all data shall be reported not later than 31 October of each calendar year. The Contractor may direct questions to the System for Award Management help desk.
6.4.1 Subcontractor Input in SAM
Prime Contractors are responsible to ensure all subcontractor data is reported. Subcontractors will not be able to enter any data into SAM but will enter their information into a Bulk Loader spreadsheet available from the SAM helpdesk. Subcontractor shall fill in columns A-C then return it to the SAM helpdesk after it's completed, and a technician team will enter the information into SAM.
6.5 Security
The researchers will have escorted access and will complete Non-Disclosure Agreements (“NDAs”) for all contractor and subcontractor employees with access to vulnerability information. NDAs must be submitted to the COR five (5) business days after contract award to ensure all candidates meet the requirements.
http://www.sam.gov/
6.5.1 Physical Security
The Contractor shall safeguard all Government property, documents and controlled forms provided for Contractor use and adhere to the Government property requirements contained in this contract. At the end of each workday, all Government facilities, equipment, and materials shall be secured by a Government POC. Contractors are not allowed to secure Government facilities, equipment, and materials.
6.5.2 Access Control
The Contractor shall establish and implement methods of ensuring that no building access instruments issued by the Government are lost, misplaced, or used by unauthorized persons.
Access codes shall not be shared with any person(s) outside the organization. The Contractor shall control access to all Government provided lock combinations to preclude unauthorized entry. The Contractor is not authorized to record lock combinations without written approval by the Government COR. Records with written combinations to authorized secure storage containers, secure storage rooms, or certified vaults, shall be marked and safeguarded at the highest classification level as the classified material maintained inside the approved containers.
6.5.3 Pass and Identification Items
The Contractor shall ensure the pass and identification items required for contract performance are obtained for employees and non-government owned vehicles.
6.5.4 Retrieving Identification Media
The Contractor shall retrieve all identification media, including vehicle passes, from employees who depart for any reason before the contract expires.
6.5.5 Traffic Laws
The Contractor and its employees shall comply with base traffic regulations.
6.5.6 Weapons, Firearms, and Ammunition
Contractor employees are prohibited from possessing weapons, firearms, or ammunition, on themselves or within their Contractor-owned vehicle or privately-owned vehicle while on the premises of any military installation or military facility.
6.5.7 Communications Security (COMSEC)
Contractors may require access to COMSEC information on Air Force installations. The Contractor shall not require a COMSEC account. Access shall be controlled by the sponsoring agency. Access to COMSEC material by personnel is restricted to US citizens holding final US
Government clearances. Such information is not releasable to personnel holding only reciprocal clearances. If it is determined the Contractor is required to access COMSEC information, the necessary training information and courses shall be provided by the COR. The DD Form 254 shall give further instructions on safeguarding and managing COMSEC material.
6.5.8 Contractor Identification
All Contractor personnel shall always wear the Air Force issued CAC when away from their immediate work area to distinguish themselves from Government employees. When conversing with Government personnel during business meetings, over the telephone or via electronic mail, Contractor personnel shall identify themselves as a Contractor to avoid situations arising where sensitive topics might be better discussed solely between Government employees. Contractors shall identify themselves on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify their company affiliation. Where practicable, Contractors occupying collocated space with their government program customer should identify their workspace area with their name and company affiliation or as a minimum “Contractor” after name.
6.5.9 Drug, Tobacco, and Alcohol Use Policy
The consumption of alcoholic beverages or illegal drugs by Contractor personnel, while on duty, is strictly forbidden. Contractor shall immediately remove any employee who is under the influence of alcohol or drugs.
6.6 TRAVEL
6.6.1 Local Travel
Local travel to attend meetings or events may be required at no cost to the Government. Travel within the National Capital Region commuting vicinity is considered a cost of doing business and shall not be separately reimbursed.
6.6.2 CONUS Travel
Prior to travel, the Contractor shall coordinate with, and receive approval from, the COR at least 10 business days prior to trip.
6.6.3 OCONUS Travel: (e.g., to EUCOM and/or PACOM Area of Responsibility)
Prior to travel, the Contractor shall coordinate with, and receive approval from, the COR at least 20 business days prior to trip. Theater Business Clearances shall be obtained, as necessary, prior to travel. Further guidance for Contractor travel can be found at https://www.defensetravel.dod.mil/site/faqctr.cfm.
https://www.defensetravel.dod.mil/site/faqctr.cfm
6.6.4 Trip Reports
Following each trip, the Contractor shall prepare and deliver Trip/After Action Reports to the COR IAW AFH 33-337. The trip report shall be completed in accordance with OFFICE (SAF/# or AF/#) guidance.
6.7 Employee Accountability & Turnover
6.7.1 Staffing of Contractor Personnel
Contractor shall provide a stable workforce, throughout the duration of the contract, by maintaining a 1% or less employee turnover rate. No positions shall remain vacant for more than one (1) calendar days. The government shall not be billed for positions left vacant over zero (0) working days unless the vacancy is due to government delay and otherwise approved by the CO.
6.7.2 List of Employees
The Contractor shall maintain a current listing of employees assigned under this contract and define who are key personnel. The list shall include the employee's name, social security number and level of security clearance. The list shall be validated and signed by the company Facility Security Officer (FSO) and provided to the Contracting Officer, Program Manager, and Servicing Security Activity. An updated listing shall be provided upon request.
6.7.3 Contractor Professionalism
The Contractor shall:
• Present a professional appearance, maintain professional demeanor, and always conduct.
• Conduct their work assignments IAW project schedules.
• Function effectively and efficiently during extended periods of high pressure and stress.
• Function as an integral member of a team of highly trained professionals responsible for the safety and security of USAF personnel and resources.
6.8 Miscellaneous Paragraphs
6.8.1 Freedom of Information Act (FOIA)
All official Government records affected by this contract are subject to the provisions of the FOIA (5 U.S.C. 552/DoD 5400.7-R/AF Supplement). Any request received by the Contractor for access/release of information from these records to the public (including Government/Contractor employees acting as private citizens), whether oral or in writing, shall be immediately brought to the attention of the CO for forwarding to the FOIA Manager to ensure proper processing and compliance with the Act.
6.8.2 Controlled Unclassified Information (CUI)
All DoD CUI must be controlled until authorized for public release in accordance with DoD Instructions (DoDIs) 5230.09, 5230.29, and 5400.04, or DoD Manual (DoDM) 5400.07. These regulations set policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding of CUI material.
6.8.3 Privacy Act
Work on this contract may require that personnel have access to information protected by the Privacy Act. Contractor personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations when managing such information.
6.8.4 Records
All records created and received by the Contractor in the performance of this contract shall be maintained and readily accessible. Records shall remain the property of the Government.
6.8.5 Safety Concerns
The Contractor is solely responsible for compliance with OSHA standards for the protection of their employees. The Government is not responsible for ensuring that Contractors comply with “personal” safety requirements that do not present the potential to damage Government resources.
6.8.6 Project Policy
The Contractor shall comply with all industry standards. All work shall be done in accordance with all federal, local, and state laws and regulations.
6.8.7 Inherently Governmental Functions
The Contractor shall not perform inherently Governmental functions as defined in the Federal Acquisition Regulation (FAR) Subpart 7.5 in relation to this PWS.
6.8.8 Ethics
The Contractor shall not employ any person who is an employee of the US Government if employing that person would create a conflict of interest. Additionally, the Contractor shall not employ any person who is an employee of the Department of the Air Force, either military or civilian, unless such person seeks and receives approval according to DoDD 5500-7, Joint Ethics Regulation.
6.8.9 Professional Appearance of Workspace
The Contractor shall keep workspace areas neat and orderly and avoid conditions leading to safety violations.
6.8.10 Non-Personal Services
The Government shall not supervise or task Contractor employees in any manner that generates actions of the nature of personal services, or that creates the perception of personal services. It is the responsibility of the Contractor to manage its employees directly and to guard against any actions that are of the nature of personal services or give the perception of personal services to the Government or to Government personnel. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it is the Contractor’s responsibility to notify the CO immediately. Non-personal Contractor services shall not be used to perform work of a policy/decision making or management nature.
SECTION VII
APPENDIX 1
1.0 DEFINITIONS, ABBREVIATIONS, AND ACRONYMS
Contracting Officer (CO): The duly appointed Government agent authorized to award or administer contracts. The contracting officer is the only person authorized to contractually obligate the Government.
Defective Service: A service output that does not meet the standard of performance specified in the contract for that service.
Government Furnished Property (GFP): Facilities, equipment, tools, supplies, parts, or any other items furnished for the concessionaire's use by the Government. A full list, if applicable, is in Section V.
Performance Threshold: The minimum performance level of a performance objective required by the Government.
2.0 ACRONYMS
Analytical Support Status Accreditation (ASSA) Chief Data and Artificial Intelligence Office (CDAO) Common Access Cards (CAC) Communications Security (COMSEC) Contracting Officer’s Representative (COR) Controlled Unclassified Information (CUI) Crowdsourced Vulnerability Discovery and Disclosure (CVDD) Department of Defense Cyber Crime Center (DC3)
Department of Defense (DoD) Facility Security Officer (FSO) Federal Acquisition Regulation (FAR) Freedom of Information Act (FOIA) Government-furnished information (GFI) Indefinite Delivery Indefinite Quantity (IDIQ) Industrial Control Systems (ICS) Joint Force Headquarters DOD Information Networks (JFHQ-DODIN) Monthly Status Report (MSR) Multifactor Authentication (MFA) National Capital Region (NCR) no later than (NLT) Point of Contact (POC) Quality Control Plan (QCP) System for Award Management (SAM) Transport Layer Security (TLS) U.S. Cyber Command (USCC) Vulnerability Disclosure Program (VDP)
| SECTION I |
| 1.0 DESCRIPTION OF SERVICES |
| 1.2 SCOPE |
| 1.3 BACKGROUND |
| SECTION II |
| 2.0 TASK DESCRIPTIONS |
| SECTION III |
| 3.0 SERVICE SUMMARY |
| SECTION IV |
| 4.0 DELIVERABLES |
| SECTION V |
| 5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL, INFORMATION, OR SERVICES |
| SECTION VI |
| 6.0 GENERAL INFORMATION |
| 6.1 Scheduling Concerns |
| 6.1.1 Duty Hours |
| 6.1.2 Core Duty Hours and Base Shutdown/Inclement Weather |
| 6.2 Kickoff Meeting/Orientation Meeting |
| 6.2.2 Agenda |
| 6.2.3 Kickoff Meeting Location |
| 6.3 Emergency Operations/Mission Essential Personnel |
| 6.3.1 Continuation of Essential Contractor Services During Crisis |
| 6.4 System for Award Management (formerly CMRA) |
| 6.4.1 Subcontractor Input in SAM |
| 6.5 Security |
| 6.5.1 Physical Security |
| 6.5.2 Access Control |
| 6.5.3 Pass and Identification Items |
| 6.5.4 Retrieving Identification Media |
| 6.5.5 Traffic Laws |
| 6.5.6 Weapons, Firearms, and Ammunition |
| 6.5.7 Communications Security (COMSEC) |
| 6.5.8 Contractor Identification |
| 6.5.9 Drug, Tobacco, and Alcohol Use Policy |
| 6.6 TRAVEL |
| 6.6.1 Local Travel |
| 6.6.2 CONUS Travel |
| 6.6.3 OCONUS Travel: (e.g., to EUCOM and/or PACOM Area of Responsibility) |
| 6.6.4 Trip Reports |
| 6.7 Employee Accountability & Turnover |
| 6.7.1 Staffing of Contractor Personnel |
| 6.7.2 List of Employees |
| 6.7.3 Contractor Professionalism |
| 6.8 Miscellaneous Paragraphs |
| 6.8.1 Freedom of Information Act (FOIA) |
| 6.8.2 Controlled Unclassified Information (CUI) |
| 6.8.3 Privacy Act |
| 6.8.4 Records |
| 6.8.5 Safety Concerns |
| 6.8.6 Project Policy |
| 6.8.7 Inherently Governmental Functions |
| 6.8.8 Ethics |
| 6.8.9 Professional Appearance of Workspace |
| 6.8.10 Non-Personal Services |
| SECTION VII |
| APPENDIX 1 |
| 1.0 DEFINITIONS, ABBREVIATIONS, AND ACRONYMS |
| 2.0 ACRONYMS |
File details come from the government source that posted it. Updated .