PWS_DMSS_SSN.pdf
PDF 527 KB Posted
- Attached to
- DMSS Training Support Federal contract opportunity
- Solicitation number
- N3600120RC023FS
About this file
This document includes a performance work statement and sources sought notice for Deployable Mission Support System-Navy training support. The Department of the Navy's Naval Information Forces Command requires onsite instruction for Deployable Mission Support System-Navy security operators and engineers to train, exercise, and assess members of 20 Cyber Protection Teams. The security operator course will cover Linux, Zeek, Kafka, file scanning frameworks, Elastic Stack, The Hive, Git, packet analysis, intrusion detection systems, and Kibana, while the engineer course will cover additional topics such as passive operations, Suricata rule management, Ansible, and sensor installation and maintenance. The contractor must provide qualified instructors and facilities to deliver the operator training to 525 personnel over 21 iterations and the engineer training to 80 personnel over four iterations at locations in Maryland, Florida, and Hawaii by [DATE]. The sources sought notice requests capability statements from interested sources by April 30, 2020 in preparation for a future indefinite delivery/indefinite quantity contract to provide this training support.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sources_Sought_NAVIFOR_DMSS.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
Deployable Mission Support System-Navy (DMSS-N) Training Support
Naval Information Forces
Suffolk, VA 23435
1.0 Introduction
1.1 Scope
This Performance Work Statement (PWS) describes required contractor support to Fleet Cyber
Command/U.S. Tenth Fleet (FLTCYBERCOM/USTENTHFLT) and Naval Information Forces
(NAVIFOR) for required security operator foundational training on the Deployable Mobile
Support System-Navy (DMSS-N) tool kit.
The primary objectives of this effort are to provide professional education and training support services, training consultation/expertise, course analysis support, scenario development, and course completion certification for the DMSS-N tool kit.
1.2 Background
FLTCYBERCOM/USTENTHFLT plans, coordinates, integrates, synchronizes, directs and conducts the full spectrum of cyberspace operational activities required to ensure freedom of action across all of the Navy’s warfighting domains in, through and from cyberspace and to deny the same to our adversaries. FLTCYBERCOM/USTENTHFLT ensures current readiness of the assigned operational forces to meet operational mission requirements and articulates to
NAVIFOR when current readiness does not meet operational requirements. NAVIFOR, as the
Type Commander (TYCOM), corrects current readiness deficiencies identified by
USFLTCYBERCOM/USTENTHFLT, maintains future readiness, and provides personnel, training, repairs, maintenance, and spares in response to operational requirements.
The Training and Exercise (N7) Directorate within FLTCYBERCOM/USTENTHFLT provides guidance and support to U.S. Cyber Command, U.S. Fleet Forces Command, U.S. Pacific Fleet, Numbered Fleets, combatant commands (CCMD), and aligned forces for unit training and exercises related to FLTCYBERCOM/USTENTHFLT. N7 performs Command Lessons
Learned Program Oversight and executes Maritime Operations Center (MOC) operational functions in accordance with the MOC Standardization instruction. N7 is dual-hatted as the Joint
Force Headquarters–Cyber (JFHQ-C FLTCYBER) J7. The N7 Directorate is the
USFLTCYBERCOM/USTENTHFLT lead for coordination and participation in Fleet and joint exercises. The exercises support efforts to train and assess Navy operational forces ashore and afloat to successfully operate in the cyber environment. N7 works through Naval Information
Forces to ensure the forces’ training requirements are met.
NAVIFOR provides naval and joint operational commanders with combat-ready Information
Warfare forces to execute missions in support of U.S. interests worldwide. NAVIFOR supports operational commanders ashore and afloat by providing combat-ready Information Warfare forces, which are forward deployable, fully trained, properly manned, capably equipped, always ready, well maintained, and combat sustainable.
Each headquarters supports the Cyber Mission Force (CMF) in sustaining training and readiness across forces supporting the Defense Cyber Operations (DCO) and Department of Defense
Information Networks (DoDIN) mission. This task includes objectives under
FLTCYBERCOM/USTENTHFLT purview to support training for all Navy Cyber Protection
Teams (CPT) under FLTCYBERCOM/USTENTHFLT. Training identified with be a collaboration effort between FLTCYBERCOM/USTENTHFLT and NAVIFOR to implement and maintain efficient foundational training for the Fleet.
2.0 Inspection and Acceptance
Inspection and Acceptance (Destination): Naval Information Forces, Suffolk, VA.
The government technical point of contact, Mr. Wesley Latchford, will perform inspection and acceptance of the services to be furnished hereunder at destination.
3.0 Task Overview
3.1 The contractor will provide onsite a DMSS-N Security Operator course of instruction to teach the methodologies for performing Security Monitoring, Incident Response, and Cyber
Hunting using the DMSS-N kit to train, exercise, and assess members of the 20 CPTs.
The contractor will provide onsite a DMSS-N Security Engineering course of instruction to teach the methodologies for performing Security Monitoring, Incident Response, and Cyber Hunting using the DMSS-N kit to train, exercise, and assess members of the 20 CPTs.
3.1.1 The contractor will provide training that is valid for Domain A or B Continuing
Professional Education (CPE) Credits for International Information System Security
Certification Consortium, or (ISC) ².
3.1.2 The contractor will provide onsite education staff with the ability to obtain base access as well as all required equipment for students and instructors to teach the course of instruction.
3.2 DMSS-N Security Operator Course
3.2.1 The DMSS-N Security Operator Course will be for security operations, incident response, and hunt operators leveraging the DMSS-N platform. The course will be offered on ten occasions, lasting five days for each occasion and will include, at a minimum:
Introduction to Linux;
Introduction to Zeek (formerly Bro);
Introduction to Kafka;
Introduction to the File Scanning Framework;
Introduction to the Elastic Stack;
Introduction to The Hive;
Introduction to Git;
Introduction to Packet Analysis;
Advanced Zeek (formerly Bro);
Intrusion Detection Systems;
Kibana for Operators; and
DMSS-N Operator Capstone Event
3.2.2 The contractor will provide training for 525 personnel in 21 iterations of no more than 25 individuals per iteration at three sites (i.e., seven iterations with no more than 25 students in
Maryland, seven iterations with no more than 25 students in in Florida, and seven iterations with no more than 25 students in in Hawaii).
3.2.3 Seventy percent of each course must be Hands-on in nature.
3.3 DMSS-N Security Engineer Course
3.3.1 The DMSS-N Security Engineer Course will be for building, operating, maintaining, and troubleshooting the DMSS-N platform equipment. The course will be offered on two occasions, lasting ten days for each occasion and will include, at a minimum:
Introduction to Linux;
Introduction to Zeek (Formerly Bro);
Introduction to Kafka;
Introduction to the File Scanning Framework;
Introduction to the Elastic Stack;
Introduction to The Hive;
Introduction to Git;
Passive Operations and Tapping;
Suricata Rule Management and Tuning;
Ansible;
Zeek (Bro) – Installation, Operation, and Maintenance;
Zeek (Bro) Performance Tuning;
Kafka - Installation, Operation, and Maintenance;
TheHive - Installation, Operation, and Maintenance;
Installation, Operation, and Maintenance;
DMSS Network Sensor - Installation, Operation, and Maintenance;
DMSS Sensor Troubleshooting; and
DMSS Sensor Engineer Capstone Event
3.3.2 The contractor will provide training for 80 personnel in four iterations of no more than 20 individuals per iteration sessions. (i.e., two iterations with no more than 20 students in Maryland, one iteration with no more than 20 students in in Florida, and one iteration with no more than 20 students in in Hawaii).
3.3.3 Seventy percent of each course must be Hands-on in nature.
4.0 Requirements
4.1 General Requirements
4.1.1 The contractor shall have a minimum of 15-months of experience in contributing to the creation, maintenance, support, or operation of the technologies identified in Section 3.0.
4.1.2 The contractor will submit proposed course content 30 days in advance of each class to the government technical POC, to receive 100% approval of proposed course content in Section 3.0 by U.S. Cyber Command to ensure course content meets mission objectives for existing and future cyber missions within the past 24-months.
4.2 Education Requirements
4.2.1 The contractor shall have a minimum of 15-months of experience in training all the technologies mentioned in Section 3.0.
4.2.2 All instructors shall have a minimum of 36-months of operational experience, beyond instruction, in all technologies listed in Section 3.0.
4.4 Travel and Program Support
Travel will be included in each course’s contractual line item. No additional travel or program support is anticipated.
5.0 (Reserved)
6.0 Period of Performance
The period of performance will be 12-months from the date of award, consisting of the base year and three (3) 12-month option years, to include FAR 21.217-8 (Option to Extend Services) for up to 6 months.
7.0 (Reserved)
8.0 Deliverables
8.1 Deliverables
The contractor will provide the deliverables listed below to be detailed on each task.
Deliverables will be prepared in contractor format where not otherwise specified by the government. Deliverables will be provided to the government technical POC. All final deliverable submissions will remain the property of the U.S. Government. All revisions will be due in the specified timeframe as identified by the government. All methodologies and recommendations will be reviewed and approved by the government prior to submission/implementation.
8.2 Method of Delivery
Electronic copies will be delivered using Microsoft Office suite of tools (for example, MS Word, MS Excel, MS PowerPoint, MS Project, or MS Access format), unless otherwise specified by the
COR. Electronic submission will be made via email, unless otherwise agreed upon with the government technical POC. Oral status reports may also be requested periodically.
8.3 Government Acceptance Period
The government technical POC will have five workdays to review draft deliverables and make comments. The contractor will have two workdays to make corrections. Upon receipt of the final deliverables, the government technical POC will have two workdays for final review prior to acceptance or providing documented reasons for non- acceptance.
The government technical POC will have the right to reject or require correction of any deficiencies found in the deliverables. In the event of a rejected deliverable, the contractor will be notified in writing by the government technical POC of the specific reasons for rejection. The contractor will have five workdays to correct the rejected deliverable and return it per delivery instructions.
8.4 Project Start Meeting
The contractor will provide a project start meeting no later than 10 days after project start or at a date and time that is convenient to, and agreed upon by all parties, at a government site or virtual location agreed upon by all parties. The project start meeting topics will include:
a) Project organization;
b) Project requirements;
c) Concept of operations
d) Reporting requirements (including format, content and structure);
e) Identification of primary stakeholders among government and contractor personnel. All primary stakeholders will attend;
f) Further elaboration on deliverables (answering any questions/concerns).
8.5 Three (3) Course Deliveries
Delivery of three (3) courses as described in Section 3.0 Task Overview.
8.9 Written Quarterly Reports
The contractor will provide the government technical POC with quarterly written reports. The reports will be due as discussed during the project start meeting. The report will be provided by email. The Quarterly Report will include, but not be limited to:
a) Contract Number, Task Order Number and Project Number.
b) Brief task description.
c) A narrative review of any classes held during the reporting period and/or significant events.
d) Description of student survey results.
e) Problem areas.
f) Any perceived problems anticipated
g) Anticipated activity for the next quarterly reporting period.
9.0 Summary Schedules of Tasks and Deliverables
Tasks Section Date
DMSS-N Security Operator Course 3.1, 3.2 As scheduled
DMSS-N Security Engineer 3.1, 3.3 As scheduled
Domain A or B Continuing Professional
Education (CPE) Credits for International
Information System Security Certification
Consortium (ISC)2
3.1 As scheduled
Deliverables Section Date
Project Start Meeting 8.4 10 days following
Project Start date
Written Quarterly Report 8.9 Once Each Quarter, as scheduled
10.0 Government Furnished Information / Government Furnished Equipment
10.1 Government Work Spaces and Information
The work under this PWS is to be performed at FLTCYBERCOM/USTENTHFLT, Ft. Meade, MD; Navy Information Operations Command (NIOC) Pensacola, Pensacola, FL; and NIOC
Hawaii, Honolulu, HI, or contractor-provided facility; at least eighty percent of the work on the overall contract effort within the 12-month performance period will be conducted at government facilities and up to twenty percent may be conducted at contractor facilities.
For work to be performed at FLTCYBERCOM/USTENTHFLT, Ft. Meade, MD; Navy
Information Operations Command (NIOC) Pensacola, Pensacola, FL; and NIOC Hawaii, Honolulu, HI, the government will provide office facilities, equipment, and materials for daily business use of contractor personnel performing under this contract, to include desk, telephone, chair, computer, shared printer, and requisite consumable materials.
The government will provide access to current reference data and information as needed to complete designated tasks. Contractor personnel will be provided access to program-related government-owned information, decision papers, briefings and any other related documentation as needed, in order to perform assigned tasks.
10.2 Navy Marine Corps Intranet (NMCI) / Continuity of Services Contract User Accounts
The government will provide Navy Marine Corps Intranet user accounts for contractor personnel who satisfy all training requirements and execute required documentation (e.g., System Access
Authorization Request-Navy (SAAR-N)). Contractor personnel will comply with all Navy and
DoD information technology system certification and operation requirements and directives.
11.0 Travel
11.1 Travel Requirements
Travel to course delivery locations is included FFP in the course price.
12.0 Other
12.1 Security
The effort is UNCLASSIFIED and therefore requires no access to classified information. All work is to be performed per DoD and Navy Operations Security (OPSEC) requirements.
12.2 Privacy Act Compliance
The contractor may be in contact with data and information subject to the Privacy Act of 1974
(Title 5 of the U.S. Code Section 552a). The contractor will ensure that its employees assigned to this effort understand and adhere to the requirements of the Privacy Act and to Department of
Defense and Department of the Navy regulations that implement the Privacy Act. Department of
Navy policy and procedures implementing the Privacy Act are detailed in SECNAVINST 5211.5
(Series), Department of the Navy Privacy Act Program. The contractor will identify and safeguard data, information and reports accordingly. In addition, the contractor will ensure that contractor employees assigned to the contract are trained on properly identifying and handling data and information subject to the Privacy Act prior to commencing work.
12.5 Personnel Qualifications
The contractor is responsible for providing personnel with expertise in the areas as described in the contract. Candidates are expected to be high-level self-starters with demonstrated technical experience in the appropriate functions. Personnel assigned to this task must keep current on the respective technologies associated with the contract.
12.6 Government Identification
All contractor personnel performing under this PWS will identify themselves as a contractor employee to avoid creating any impression that they are government officials. Such identification will be made in all meetings attended, when answering government telephones, on all e-mails, and when working in other situations where their contractor status is not obvious to third parties. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.
ADDITIONAL CLAUSES
AUTHORIZED CHANGES ONLY BY THE CONTRACTING OFFICER
THE FOLLOWING NAVSUP LOCAL TEXT IS HEREBY MADE PART OF THE
STATEMENT OF WORK/PERFORMANCE WORK STATEMENT.
AUTHORIZED CHANGES ONLY BY THE CONTRACTING OFFICER
(a) Except as specified in paragraph (b) below, no order, statement, or conduct of Government personnel who visit the Contractor's facilities or in any other manner communicate with
Contractor personnel during the performance of this contract shall constitute a change under the
"Changes" clause of this contract.
(b) The Contractor shall not comply with any order, direction or request of Government personnel unless it is issued in writing and signed by the Contracting Officer, or is pursuant to specific authority otherwise included as a part of this contract.
(c) The Contracting Officer is the only person authorized to approve changes in any of the requirements of this contract and notwithstanding provisions contained elsewhere in this contract, the said authority remains solely with the Contracting Officer. In the event the
Contractor effects any change at the direction of any person other than the Contracting Officer, the change will be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in charges incurred as a result thereof. The address and telephone number of the Contracting Officer is:
NAME: Dorothy Curling
ADDRESS: 1968 Gilbert Street, Suite 600
Norfolk, VA 23511-3392
TELEPHONE: 757-443-1955
OR
NAME: Heather Coleman
ADDRESS: 1968 Gilbert Street, Suite 600
Norfolk, VA 23511-3392
TELEPHONE: 757-443-2066
CONTRACTOR UNCLASSIFIED ACCESS TO FEDERALLY CONTROLLED
FACILITIES, SENSITIVE INFORMATION, INFORMATION TECHNOLOGY (IT)
SYSTEMS OR PROTECTED HEALTH INFORMATION
THE FOLLOWING NAVSUP LOCAL TEXT IS HEREBY MADE PART OF THE
STATEMENT OF WORK/PERFORMANCE WORK STATEMENT.
Contractor Unclassified Access to Federally Controlled Facilities, Sensitive Information, Information Technology (IT) Systems or Protected Health Information
Executive Order 13467, Reforming Processes Related to Suitability for Government Employee, Fitness for Contractor Employees and Eligibility for Access to Classified National Security
Information, Homeland Security Presidential Directive (HSPD)-12, requires government agencies to develop and implement Federal security standards for Federal employees and contractors. The 5 CFR 32 Part 157 in concert with DoD Manual 1000.13, Vol 1, implements the
Federal Standards.
APPLICABILITY
This text applies to all DoD sponsored individuals who require CAC eligibility (or login and
P/W if acceptable per contract) for: Physical access to DoD facilities or non-DoD facilities on behalf of DoD; Logical access to information systems (whether on site or remotely); or remote access to DoD networks that use only the CAC logon for user authentication, or access to sensitive and protected information. This applies to the Office of the Secretary of Defense, the
Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the DoD, the Defense
Agencies, the DoD Field Activities and all other organizational entities within the DoD
(hereinafter referred to collectively as the "DoD Components").
Each contractor employee providing services at a Navy Command under this contract is required to obtain a Department of Defense Common Access Card (DoD CAC). Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.
ACCESS TO FEDERAL FACILITIES
Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this clause will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Command’s
Security Manager upon arrival to the Command and shall out-process prior to their departure at the completion of the individual’s performance under the contract.
START-UP PERIOD
All contractor resource onboarding documents must be submitted via the prime contractor. The prime contractor shall make all necessary preparations to assume full responsibility for productive performance of the performance start date.
Definition of “productive”:
a) Visit Authorization Request (VAR)
b) Contractor Information Sheet (CIS)
c) Completed EQIP (Electronic Investigation)
d) All contractor resource(s) must have an active JPAS profile.
e) Common Access Card (CAC)
Note (1): Invoicing by the contractor will begin as of the commencement of the performance period of services and no reimbursement will be paid by the government for efforts expended during the start-up period.
Note (2): Foreign Nationals are not allowed access of the functional/system side of Enterprise
Resource Planning (ERP).
ACCESS TO DOD INFORMATION TECHNOLOGY (IT) SYSTEMS
In accordance with (IAW) Secretary of the Navy (SECNAV) M-5510.30, contractor employees who require access to DON or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to sensitive information. Sensitive information includes information protected under the Privacy
Act, to include Protected Health Information (PHI). All contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than
IT-II. IT Levels are determined by the requiring activity’s Command Information System
Security Manager (ISSM)/Information Assurance Manager (IAM).
Contractor employees requiring privileged or IT-I level access, (when specified by the terms of the contract) require a Single Scope Background Investigation (SSBI) or T5 or T5R equivalent investigation , which is a higher level investigation than the National Agency Check with Law and Credit (NACLC)/T3/T3R described below. Due to the privileged system access, an investigation suitable for High Risk national security positions is required. Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance Technical
Level 1, and must be trained and certified on the Operating System or Computing Environment they are required to maintain.
Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to IT systems is required for performance of the contractor employee’s duties, such employees shall in-process with the Navy Command’s CSM and
ISSM/IAM upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual’s performance under the contract. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The decision to authorize access to a government IT system/network is inherently governmental. The contractor supervisor is not authorized to sign the SAAR-N; therefore, the government employee with knowledge of the system/network access required or the COR shall sign the SAAR-N as the “supervisor”.
The SAAR-N shall be forwarded to the Command’s Security Manager at least 30 days prior to the individual’s start date. Failure to provide the required documentation at least 30 days prior to the individual’s start date may result in delaying the individual’s start date.
When required to maintain access to required IT systems or networks, the contractor shall ensure that all employees requiring access complete annual Cyber Awareness training, and maintain a current requisite background investigation. The Contractor’s Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required.
INTERIM ACCESS
The Command's Security Manager may authorize issuance of a DoD CAC and interim access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.
DENIAL OR TERMINATION OF ACCESS
The potential consequences of any requirement under this clause including denial or termination of physical or system access in no way relieves the contractor from the requirement to execute performance under the contract within the timeframes specified in the contract. Contractors shall plan ahead in processing their employees and subcontractor employees. The contractor shall insert this clause in all subcontracts when the subcontractor is permitted to have unclassified access to a federally controlled facility, federally-controlled information system/network and/or to government information, meaning information not authorized for public release.
CONTRACTOR’S SECURITY REPRESENTATIVE
The contractor shall designate an employee to serve as the Contractor’s Security Representative.
Within three work days after contract award, the contractor shall provide to the requiring activity’s Security Manager and the Contracting Officer, in writing, the name, title, address and phone number for the Contractor’s Security Representative. The Contractor’s Security
Representative shall be the primary point of contact on any security matter. The Contractor’s
Security Representative shall not be replaced or removed without prior notice to the Contracting
Officer and Command Security Manager.
BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL
PROCESS FOR CONTRACTORS ASSIGNED TO NATIONAL SECURITY POSITIONS
OR PERFORMING SENSITIVE DUTIES
Navy security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Contractor employees under this contract are recognized as Non-Critical Sensitive [ADP/IT-II] positions when the contract scope of work require physical access to a federally controlled base, facility or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to contractor employees who access Privacy Act and Protected Health Information
(PHI), provide support associated with fiduciary duties, or perform duties that have been identified as National Security Positions. At a minimum, each contractor employee must be a
US citizen and have a favorably completed NACLC or T3 or T3R equivalent investigation to obtain a favorable determination for assignment to a non-critical sensitive or IT-II position. The investigation consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. Each contractor employee filling a non-critical sensitive or IT-II position is required to complete:
SF-86 Questionnaire for National Security Positions (or equivalent OPM investigative product)
Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)
Original Signed Release Statements
Failure to provide the required documentation at least 30 days prior to the individual’s start date shall result in delaying the individual’s start date. Background investigations shall be reinitiated as required to ensure investigations remain current (not older than 10 years) throughout the contract performance period. The Contractor’s Security Representative shall contact the
Command Security Manager for guidance when reinvestigations are required.
Regardless of their duties or IT access requirements ALL contractor employees shall in-process with the CSM upon arrival to the command and shall out-process prior to their departure at the completion of the individual’s performance under the contract. Employees requiring IT access shall also check-in and check-out with the Navy Command’s ISSM/IAM. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The SAAR-N shall be forwarded to the Navy Command’s Security Manager at least 30 days prior to the individual’s start date.
shall result in delaying the individual’s start date.
The contractor shall ensure that each contract employee requiring access to IT systems or networks complete annual Cyber Awareness training, and maintain a current requisite background investigation. Contractor employees shall accurately complete the required investigative forms prior to submission to the Command Security Manager. The Command’s
Security Manager will review the submitted documentation for completeness prior to submitting it to the Office of Personnel Management (OPM); Potential suitability or security issues identified may render the contractor employee ineligible for the assignment. An unfavorable determination is final (subject to SF-86 appeal procedures) and such a determination does not relieve the contractor from meeting any contractual obligation under the contract. The
Command’s Security Manager will forward the required forms to OPM for processing. Once the investigation is complete, the results will be forwarded by OPM to the DoD Central Adjudication
Facility (CAF) for a determination.
If the contractor employee already possesses a current favorably adjudicated investigation, the contractor shall submit a Visit Authorization Request (VAR) via the Joint Personnel
Adjudication System (JPAS) or a hard copy VAR directly from the contractor’s Security
Representative. Although the contractor will take JPAS “Owning” role over the contractor employee, the Navy command will take JPAS "Servicing" role over the contractor employee during the hiring process and for the duration of assignment under that contract. The contractor shall include the IT Position Category per SECNAV M-5510.30 for each employee designated on a VAR. The VAR requires annual renewal for the duration of the employee’s performance under the contract.
BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL
PROCESS FOR CONTRACTORS ASSIGNED TO OR PERFORMING NON-
SENSITIVE DUTIES
Contractor employee whose work is unclassified and non-sensitive (e.g., performing certain duties such as lawn maintenance, vendor services, etc. ...) and who require physical access to publicly accessible areas to perform those duties shall meet the following minimum requirements:
Must be either a US citizen or a US permanent resident with a minimum of 3 years of legal residency in the United States (as required by The Deputy Secretary of Defense
DTM 08-006 or its subsequent DoD instruction) and
Must have a favorably completed National Agency Check with Written Inquiries (NACI) or T1 investigation equivalent including a FBI fingerprint check prior to installation access.
To be considered for a favorable trustworthiness determination, the Contractor’s Security
Representative must submit for all employees each of the following:
SF-85 Questionnaire for Non-Sensitive Positions
Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)
Original Signed Release Statements
The contractor shall ensure each individual employee has a current favorably completed National
Agency Check with Written Inquiries (NACI) or T1 equivalent investigation, or ensure successful FBI fingerprint results have been gained and investigation has been processed with
OPM
may result in delaying the individual’s start date.
* Consult with your CSM and ISSM/IAM for local policy when IT-III (non-sensitive) access is required for non-US citizens outside the United States.
COMBATING TRAFFICKING IN PERSON (CTIP)
The Department of Defense (DOD) has a zero tolerance policy regarding trafficking in persons.
FAR Subpart 22.17: Prescribes overall federal regulation implementing 22 U.S.C. 7104 which applies to all acquisitions. Requires government contracts to (a) Prohibit contractors, contractor employees, subcontractors, and subcontractor employees from engaging in trafficking in persons during the period of performance of the contract. See FAR Provision 52.222-56 and FAR Clause
52.222-50.
NMCARS 5237.102-90 ENTERPRISE-WIDE CONTRACTOR MANPOWER
REPORTING APPLICATION (ECMRA).
The contractor shall report contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for DMSS-N Training via a secure data collection site. Contracted services excluded from reporting are based on Product Service Codes
(PSCs). The excluded PSCs are:
1) W, Lease/Rental of Equipment;
2) X, Lease/Rental of Facilities;
3) Y, Construction of Structures and Facilities;
4) D, Automatic Data Processing and Telecommunications, IT and Telecom-
Telecommunications Transmission (D304) and Internet (D322) ONLY;
5) S, Utilities ONLY;
6) V, Freight and Shipping ONLY.
The contractor is required to completely fill in all required data fields using the following web address: https://www.ecmra.mil.
Reporting inputs will be for the labor executed during the period of performance during each
Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. Contractors may direct questions to the help desk, linked at https://www.ecmra.mil.
SUPTXT203.1106-1 (3-18) NAVY USE OF ABILITYONE SUPPORT CONTRACTOR -
RELEASE OF OFFEROR INFORMATION (Mar18)
NAVSUP FLC Norfolk may utilize contractor support through the AbilityOne Program, as needed, to perform contract closeout functions for this acquisition. Information, including business sensitive/confidential or proprietary data, that the offeror provides to the Government or information already in the possession of the Government may be viewed and utilized by the
AbilityOne Program support contractor personnel during the course of its contract performance.
https://www.ecmra.mil/ https://www.ecmra.mil/
The information that may be made available to the support contractor may include, for example, pricing and technical proposals, historical contract, pricing and performance information, Commercial Asset Visibility (CAV) reporting information and similar data/information.
By submission of a proposal in response to this solicitation, the offeror and its subcontractors consent to a release of their business sensitive/confidential or proprietary data to the
Government's AbilityOne Program support contractor personnel in order to perform close out services. Prior to the release of any such information to the support contractor, the support contractor will have in place with the Government a Non-Disclosure/Non-Use Agreement in accordance with the terms of the AbilityOne Program support contract.
Offerors may execute their own Non-Disclosure Agreement with the AbilityOne Program
(AbilityOne contact information available from the contracting point of contact). The support contractor must provide copies of the executed agreements to the Contracting Officer and the
Contracting Officer's Representative (COR) for the support contract; and the offeror/contractor for this acquisition must provide copies of the executed Agreement to the Contracting Officer for this acquisition. If the offeror/contractor seeks such a Non-Disclosure Agreement with the
AbilityOne Program support contractor, the Agreement must be executed no later than the date of final delivery under the resulting NAVSUP FLC Norfolk contract.
File details come from the government source that posted it. Updated .