PWS - Technical Analytical Mission Support.pdf
PDF 783 KB Posted
- Attached to
- Technical and Analytical Support Federal contract opportunity
- Solicitation number
- FA701421R0001
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sources Sought - Technical Analytical Support.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA7014‐XX-X-XXXX
PERFORMANCE WORK STATEMENT
FOR
DC3 Technical and Analytical Support
AT
LINTHICUM, MARYLAND
27 June 2020
DRAFT V3.0
Contents
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 GENERAL
1.1.1 SCOPE
1.2 BACKGROUND
SECTION II
2.0 TASK DESCRIPTIONS
2.1 BUSINESS & TECHNOLOGY OPERATIONS (BTO)
2.1.1 CURRENT INFORMATION TECHNOLOGY (IT) ENVIRONMENT
2.1.2 SUBTASK 1 – SERVICE DESK SUPPORT
2.1.3 NETWORK AND SYSTEMS ADMINISTRATION SUPPORT
2.1.4 ENTERPRISE ARCHITECTURE (EA) AND CONFIGURATION MANAGEMENT
(CM)
2.1.5 IT ASSET MANAGEMENT
2.1.6 CYBERSECURITY (CS)
2.1.8 DATABASE MANAGEMENT SUPPORT
2.2.2 DATA IMAGING AND EXTRACTION (I&E) SUPPORT
2.2.3 EXAMINATION SUPPORT
2.2.4 EVIDENCE CUSTODIAL SUPPORT
2.2.5 DC3/CFL TRAINING DEVELOPMENT AND MENTORING PROGRAM
2.4 DC3/DCISE SUPPORT
2.4.1 DEFENSE INDUSTRIAL BASE CYBERSECURITY (DIB CS) PROGRAM
OFFICE AND POLICY SUPPORT
2.4.2 DIB PORTAL AND KNOWLEDGE MANAGEMENT SUPPORT
2.4.6 DC3/DCISE EXTERNAL ENGAGEMENTS SUPPORT
2.5 DC3/AG OPERATIONS SUPPORT
SECTION III
3.0 SERVICE SUMMARY
SECTION IV
4.0 DELIVERABLES
SECTION V
5.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,
INFORMATION, OR SERVICES
5.1 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, MATERIAL,
INFORMATION, OR SERVICES
SECTION VI
6.0 GENERAL INFORMATION
6.1 SCHEDULING CONCERNS
6.2 PROGRAM MANAGEMENT
6.2.3 DEVELOP AND MAINTAIN AN INTEGRATED MASTER SCHEDULE (IMS) . 41
6.2.4 PROGRAM BASELINE REVIEW
6.2.5 RISK MANAGEMENT
6.2.6 PREPARE A PROJECT MANAGEMENT PLAN (PMP)
6.3.1 PROGRAM MANAGER
6.3 NON KEY PERSONNEL REQUIRMENTS
6.5 TRANSITION-IN PLAN
6.6 TRANSITION-OUT PLAN
6.7 QUALITY CONTROL
6.7 EMERGENCY OPERATIONS/MISSION ESSENTIAL PERSONNEL
6.8 CONTRACTOR MANPOWER REPORTING APPLICATION (CMRA)
6.8.2 Subcontractor Input in CMRA
6.9 SECURITY INSTRUCTIONS
6.9.1 SECURITY CLEARANCES
6.10 TRAVEL
6.11 EMPLOYEE ACCOUNTABILITY & TURNOVER
SECTION VII
APPENDIX 1
1.0 DEFINITIONS, ABBREVIATIONS, AND ACRONYMS
2.0 ACRONYMS
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 GENERAL
The Department of Defense Cyber Crime Center (DC3) was unofficially formed in 1998 as an entity under the Department of the Air Force (AF). The initial operational capability brought together the Defense Computer Forensics Laboratory (DC3/CFL) and the Defense
Computer Investigations Training Program (DCITP). DC3 is now designated as a National
Cyber Center by the National Security Presidential Directive 54 / Homeland Security
Presidential Directive 23 and a Department of Defense (DoD) Center of Excellence by
DoD Directive (DoDD) 5505.13E with the mission to set the standards in digital and multimedia (D/MM) forensics, develop and deliver specialized cyber investigative training, and serve as a focal point for information sharing on cybersecurity (CS) matters across the DoD.
The Secretary of the AF serves as the DoD Executive Agent for these activities and the
Inspector General of the United States (U.S.) AF provides overall program management.
1.1.1 SCOPE.
The scope of this effort is to support six of the eight DC3 Directorates. The six directorates are outlined below:
COMPUTER FORENSICS LABORATORY (DC3/CFL)
Support Digital Multi-Media (D/MM) forensic examinations, device repair, data extraction, and expert testimony for DoD agencies Support intrusion and malware analysis.
TECHNICAL SOLUTIONS DEVELOPMENT (DC3/TSD)
Tailor software and system solutions engineered to the specific requirements of digital forensic examiners and cyber intrusion analysts. Validate commercial off-the-shelf (COTS), Government off-the-shelf (GOTS), and custom developed software/hardware before it can be used in a forensic process. In addition, DC3/TSD functions as the DoD repository for cyber CI tools.
DOD-DEFENSE INDUSTRIAL BASE COLLABORATIVE INFORMATION
SHARING ENVIRONMENT (DC3/DCISE)
Support DC3 with assisting Defense Industrial Base (DIB) companies to safeguard DoD content and intellectual property residing on or transiting their unclassified networks. The contractor shall develop and share actionable threat products, and performs cyber analysis, diagnostics, and remediation consults for DIB Partners.
CYBER CRIME CENTER ANALYTICAL GROUP (DC3-AG)
Perform technical analyses supporting the investigations and operations of national Law
Enforcement/Counter Intelligence (LE/CI) agencies. The primary agencies served are the Air
Force Office of Special Investigations (AFOSI), Naval Criminal Investigative Service (NCIS) and the Federal Bureau of Investigation (FBI).
Support DC3’s role as a member of the National Cyber Investigative Joint Task Force
(NCIJTF) including collaborative analytical and technical exchanges with subject matter experts (SMEs) from LE/CI, Computer Network Defense (CND), United States Intelligence
Community (USIC), and IA agencies. The purpose of these information exchanges is to enable proactive LE/CI cyber operations.
VULNERABILITY DISCLOSURE PROGRAM (DC3/VDP)
Support DC3’s role in the Vulnerability Disclosure Policy approved by the Secretary of
Defense and the Department of Justice which authorizes private-sector cybersecurity researchers (AKA Hackers) to scan public-facing DoD web sites for vulnerabilities.
DC3 is the sole focal point for receiving vulnerability reports and interacting with researchers.
DC3 ensures that reports are delivered to the system owner and remediation personnel as quickly as possible.
BUSINESS AND TECHNOLOGY OPERATIONS (DC3/BTO)
BTO is the support element of DC3 and provides five functions: human resources, security administration, information technology (IT), cyber security, and logistics that enable operations in a complex dynamic cyber environment. This requirement is supports two of the five: information technology (IT), cyber security.
1.2 BACKGROUND
DC3’s mission is to deliver superior D/MM lab services, cyber technical training, technical solutions development, and cyber analytics for the following DoD mission areas: information assurance (IA) and critical infrastructure protection (CIP), law enforcement and counterintelligence (LE/CI), document and media exploitation (DOMEX), and counterterrorism (CT).
Located in Linthicum, Maryland, DC3 components serve the DoD and other U.S. Federal agencies throughout the world. The DC3 organization consists of a mix of military, civilian, and contractor support personnel. The DC3 environment is dynamic and constantly evolving which contributes to priorities frequently changing.
DC3 is operationally aligned into the organizations described below each with interrelated missions and support requirements that collectively contribute to the overall mission.
The DC3 is comprised of six operational directorates and two support directorates:
Operational:
a. Computer Forensics Laboratory (DC3/CFL)
b. Technical Solutions Development (DC3/TSD)
c. Cyber Investigations Training Academy (DC3/CITA)
d. Defense Industrial Base Collaborative Information Sharing Environment
(DC3/DCISE)
e. Analytical Group (DC3/AG)
f. Vulnerability Disclosure Program (DC3/VDP)
Support:
g. Business and Technology Operations (DC3/BTO)
h. Enterprise Management and Resourcing (DC3/ER)
This requirement is a follow-on to Task Order GSQ0017AJ0021 under the Government Wide
Acquisition Contract (GWAC) Alliant I GS00Q09BGD0011 issued by GSA FEDSIM.
SECTION II
2.0 TASK DESCRIPTIONS
2.1 BUSINESS & TECHNOLOGY OPERATIONS (BTO)
The contractor shall provide assistance to DC3’s IT infrastructure, telecommunications requirements, service desk, and cyber security.
The ITD requires on-call contractor support to maintain 24 hours per day, seven days per week, 365 days per year (24x7x365) operational availability of critical networks and systems.
The ITD is currently responsible for 12 separate networks and telecommunications systems of all classification levels serving more than 400 users throughout the DC3 organization. ITD critical networks and systems currently consist of the Unclassified DC3 Enterprise Network
(DEN), Classified Secure DC3 Enterprise Network (SDEN), DC3's Open Network (DC3ON), DC3/CFL Networks (ExLAN, IA LAN), and phone systems. The ITD also maintains and supports all Corporate and Forensics applications that run on forensically sound workstations, several of which are mission critical.
Over the life of this task order, ITD shall transition to the latest Information Technology
Infrastructure Library (ITIL) framework for IT Services Management (ITSM). The contractor shall be responsible for implementing, transitioning and maintaining ITD operations using the
ITIL framework.
2.1.1 CURRENT INFORMATION TECHNOLOGY (IT) ENVIRONMENT
DC3’s IT services are maintained in accordance with all DoD and AF directives, guidelines, and requirements such as (but not limited to) DoDD 8570, DoDD 8140, AF Manual (AFMAN)
17-1303, and AFMAN 17-1301.
DC3 operates and maintains two Non-classified Internet Protocol (IP) Routing Network
(NIPRNET) and DC3 Open Network (DC3ON), two Secret Internet Protocol Routing
Network (SIPRNET) network, DC3’s Classified Secure StormSystem Network, one Joint
Worldwide Intelligence Communications System (JWICS) and multiple stand-alone forensic/examination networks that provide processing and communications support.
The NIPRNET provides seamless interoperability for unclassified combat support applications, as well as controlled access to the Internet. SIPRNET is DoD’s largest interoperable command and control data network, supporting the Global Command and
Control System (GCCS), the Defense Message System (DMS), collective planning, and numerous other classified warfighter applications.
Over the life of this task order, the Government shall be transitioning ITD to the latest
Information Technology Infrastructure Library (ITIL) framework for IT Services
Management (ITSM). The contractor shall be responsible for implementing, transitioning and maintaining ITD operations using the ITIL framework.
2.1.2 SUBTASK 1 – SERVICE DESK SUPPORT
The ITD Service Desk is the single POC for all DC3 requests for service including computer user and telecommunications-related issues. The Service Desk supports the Linthicum, Maryland locations. In 2019 ITD received 6,728 calls/requests. The requests are generally resolved via first call resolution; however, technicians may be required to be dispatched to troubleshoot and provide immediate resolution to the problem. The issues occur based on various security classifications levels to include: Controlled Unclassified Information (CUI), Secret, TS, SCI, Special Access Program (SAP) and Special Access Required (SAR). All technicians performing network functions (as defined in AFMAN 17-1303 or later version) shall be Information Assurance Technical (IAT) Level II or higher certified in accordance with DoDD 8570.01 and 8140.01.
The contractor shall provide Tier 0 (self-service), Tier 1 and 2 service desk support for all
DC3 computer users. This activity includes requests for installation, repairs, and upgrades of existing equipment. The contractor shall provide personnel onsite daily to respond to technical support issues from 0600-1800 Eastern Standard Time (EST) on 12 hours a day, five days a week basis (Monday thru Friday). The contractor is required to provide on-call support
(outside of the standard working hours) for unplanned events. The contractor is required to adhere to the on-call support timelines defined per the service level agreements (SLAs).
The contractor shall develop the Tier 0 or self-service mechanism to support DC3 computer users. The contractor shall provide a technical Tier 1 service desk (initial caller support) for
DC3. Tier 1 is the first point of customer contact for network related operational issues.
Typical Tier 1 support includes, but is not limited to, requests related to COTS hardware failures, software failures, application questions, installations, relocations, turn-ins, access rights, hardware/software loaners, network communication failures, new user requirements, temporary computer product check-outs, and other computer related requirements. All issues beyond the capabilities of Tier 1 caller support are escalated to Tier 2 or Tier 3.
The contractor shall provide Tier 2 service desk technical support for DC3 user issues. The contractor shall serve as the SME for troubleshooting desktop support related issues. The contractor shall design, troubleshoot, and implement DC3 computer-related equipment. In addition to Tier 2 troubleshooting, the contractor shall:
a. Identify network problems due to design and implementation constraints.
b. Identify and implement workarounds to resolve DC3 network problems.
c. Work with DC3 network design engineers on engineering and design issues to develop operationally sound implementations.
d. Develop troubleshooting guides and SOPs to improve Tier 0 and enable Tier 1 technicians to efficiently troubleshoot and resolve DC3 network problems
(Deliverable).
The contractor shall respond to and document all network incidents including security and informational requests that result from proactive network monitoring or customer-initiated contacts. The contractor shall isolate and document network problems using industry best practice troubleshooting skills, as well as available system and network management tools.
The contractor shall use or recommend a new Service Desk Ticket application (currently
Footprints, but be Jira) as a central repository for technical advice and solutions for IT systems, software applications assistance, automatic data processing support, hardware exchange, repair service support, and other related service desk functions.
The contractor shall utilize network management tools to provide efficient, responsive, and rapid problem resolution.
The contractor shall collect and report IT service desk service performance metrics. The contractor, as a minimum, shall establish and maintain metrics (subject to Government approval) of the following items, and be prepared to present the findings to DC3 management:
a. Total number of queries into the ITD
b. Total number of queries into the ITD that result in a trouble ticket (separated by category, such as, incidents, problems, requests for change, and requests for services)
c. Total number of queries that are resolved during initial contact
d. Total number of queries resolved by the ITD
e. Total time to complete (resolve) the trouble ticket
The contractor shall adhere to the approved SLA process for responding to service desk queries. At a minimum, the contractor shall respond to customer service desk requests within four (4) hours and complete resolution within 24 hours (during regular business hours M-F
0600-1800 EST). The contractor shall provide supporting documentation for validation by the
DC3 Contracting Office Representative (COR) for those requests beyond the desired response and resolution periods. The contractor shall track all service desk requests from inception through completion in the service desk ticketing system.
The contractor shall provide Monthly Service Desk Trouble Call Status Reports (TCSRs). The contractor shall provide Service Desk TCSRs that provide relevant data and reports on information such as:
a. Analyses/type of trouble calls
b. Unusual patterns
c. Potential DC3 IT/Communications/application problems and proposed resolutions
d. Unresolved Trouble Tickets
e. Tracking and resolution of service complaints
f. Backup source data
g. Summary status (in spreadsheet format) of all hardware maintenance for each month
2.1.3 NETWORK AND SYSTEMS ADMINISTRATION SUPPORT
DC3 relies upon the following networks (currently 12 in total) and their associated services for its daily operations and mission support:
a. DC3 Enterprise Network (DEN) NIPRNet (supporting approximately 450 users)
b. Secure DC3 Enterprise Network (SDEN) SIPRNet (supporting approximately 250 users)
c. Joint World-Wide Communications System (JWICS) (supporting approximately 200 users)
d. DC3’s (internal) Laboratory Information Management System (CIMS10), Forensic
Examiner, and Intrusion Networks
e. DC3's Open Network (DC3ON)
f. StormSystem Classified Network Enclave
g. Covered Accounts Network
h. Virtual Private Network (VPN) on unclassified networks
i. Other networks as required by the Government (e.g., Defense Industrial Base LAN
(DIBLAN))
The contractor shall ensure identified networks and IT (currently DEN, SDEN, DC3ON, and
DIBLAN) align to the complete Risk Management Framework (RMF) and successfully obtain and maintain Authority to Operate (ATO).
The contractor shall install and maintain routers, switches, hubs, and cabling comprising DC3’s network infrastructure. The contractor shall maintain the IP addressing schema for the entire enterprise infrastructure; modify switch, router, and hub configurations to ensure optimum network performance; and configure Access Control Lists (ACLs) to grant/restrict network access to authorized uses and protocols.
The contractor shall provide proactive and reactive management of resources by monitoring and controlling networks, available bandwidth, hardware, and distributed software resources.
The contractor shall operate and maintain the aforementioned networks to include but not limited to the following tasks:
a. Install, configure, manage, troubleshoot, and secure network infrastructure, including but not limited to servers, storage components, desktop computers (PCs), laptops, printers, scanners, routers, switches, network devices, and other tools.
b. Design and configure network components, including VPN capabilities.
c. Monitor and manage network bandwidth.
d. Perform back-up and recovery functions.
e. Establish, monitor, and maintain all computer and network accounts
(Add/Change/Deletion) in accordance with DoD, AF and DC3 BTO/ITD computer security regulations.
f. Maintain the Global Address List, Active Directory and other network directory services.
g. Maintain an up-to-date listing of user accounts, email accounts, passwords, software licenses; systems file directories, and system/network accreditation documentation.
h. Operate, maintain, and trouble-shoot video teleconferencing hardware and software
i. Manage internet and intranet web servers, remote Access Security Services, and maintain the Domain Name System (DNS) server.
j. Maintain and monitor standardized file storage directory structures.
k. Establish, maintain, and monitor print servers.
l. Coordinate with third party organizations and network carriers to perform operational activities.
m. Develop and document network administration policies and procedures.
n. Document and report all network faults, outages, and security incidents.
o. Document and maintain enterprise user account information.
p. Conduct analysis of network characteristics to include traffic, connect time, transmission speeds, packet, and modifications to network and system components.
q. Recommend processes and tools to improve overall network performance and user experience.
All technicians performing network and IT functions (as defined in AFMAN 17-1303 or later version) shall be, at a minimum, IAT level II certified in accordance with DoD 8570.01 and
DoD 8140.01.
DC3 is currently moving its existing infrastructure to a thin client and virtual environment with an objective state of using cloud services both on premise and off-premise. The contractor shall provide planning, implementation and maintenance support for all new infrastructure changes, phases, or surge efforts as required.
The contractor shall also make recommendations to the Government for upgrades, equipment replacement, repairs, changes, additions, and removal of parts of DC3 IT infrastructure. The contractor shall notify the Government of all necessary required changes, additions or removals from the existing system and obtain concurrence before any changes, additions, or removals are performed. The DC3 has a configuration control process to document and approve all changes to the IT services baseline. The contractor shall ensure all changes are processed through this process and conform to established policy and standards. The contractor shall document all repairs, changes, additions, or removals in the summary status included in the TCSR. The contractor shall conduct technical testing on existing and newly procured ITD systems, subsystems, and applications. The contractor shall evaluate communications hardware and software, troubleshoot problems, and provide technical expertise for optimal performance of equipment. The contractor shall recommend additional hardware and software tools, which could improve the systems.
The contractor shall ensure that DC3’s networks, applications, and systems maintain at a minimum a monthly 99.5 percent network/systems availability. The contractor shall notify the
Government of any unusual circumstances that exist beyond the contractor’s control for not meeting the availability service levels. The contractor is required to monitor, maintain, track, record, and report monthly system availability, up time, and downtime. This information shall be made available, on-demand, to the Government via the DC3 Business Intelligence Center.
In the event that network connectivity/availability is caused or impacted by an external source
(not DC3), the contractor shall ensure the BTO Director/CIO and TPOC are notified, in writing, within 30 minutes of the incident (during regular business hours M-F 0600 - 1800 EST). This report shall include the cause and anticipated restoration time.
The contractor shall ensure all network incidents are identified in the MSR with descriptions of the incident, causes, resolutions, and any Government actions required. The contractor shall ensure this information is made available, on demand, to the Government via the DC3 IC.
The contractor shall respond to detected security incidents, network faults (errors), and user reported outages within 30 minutes of notification of an incident. The contractor shall notify the Government (BTO Director/CIO and TPOC) within 30 minutes of any security incident or network outage (during regular business hours M-F 0600-1800 EST, incidents outside of business hours shall be reported by 0630 the next business next day). The contractor shall document, record, and report all network incidents and include these within the MSR.
2.1.4 ENTERPRISE ARCHITECTURE (EA) AND CONFIGURATION
MANAGEMENT (CM)
DC3’s EA conforms to the DoD Joint Information Environment (JIE), which consists of five major focus areas: optimization of information, network, hardware, applications, and governance. Each of these capabilities is described in terms of activities, services, and rules necessary to ensure the capability is achieved. The DoD Information Environment Area (IEA) outlines how capabilities are delivered by providing descriptions of services the DoD IEA must have to operate at optimum effectiveness. These services represent a collection of required information across the spectrum of Doctrine, Organization, Training, Material, Leadership and education, Personnel, Facilities, and Policy (DOTMLPF-P).
The contractor shall develop and maintain the baseline artifacts of the following views: AV-1, AV-2, CV-1, CV-2, CV-6, CV-7, OV-1, OV-5a, OV-6a, SvcV-1, SvcV-4, StdV-1, and StdV-
2 (Deliverable).
Furthermore, the contractor shall provide documentation in accordance with DC3 standards to substantiate the DC3 current and future states as the DC3 architecture evolves.
The contractor shall be responsible for requirements analysis, evaluation, and design of the IT architecture environment for DC3. The contractor shall maintain a current EA and configuration design for all DC3 networks. The contractor shall provide DC3 with a well-defined practice for conducting enterprise analysis, design, planning, and implementation, using a holistic approach at all times, for the successful development and execution of strategy. The contractor shall apply DoD/AF architecture principles and practices to guide the
DC3 through the business, information, process, and technology changes necessary to execute its strategies and objectives.
The contractor shall develop, implement, and support DC3’s Configuration Management
(CM) processes for all networks and supporting technologies identified in this PWS
(Deliverable). The DC3 CM shall consist of a systems engineering process for establishing and maintaining consistency of a product's performance, functional, and physical attributes with its requirements, design, and operational information throughout its life. This shall include assurance of adequate CM software that tracks and controls changes in any DC3 IT, software or application thereby maintaining strict accounting of the DC3 IT services baselines.
The CM system process shall include configuration identification, data management, audits, change control, status accounting, and deficiency reporting. The CM system/process shall be documented in a Configuration Management Plan (CMP) that includes/addresses the entire IT lifecycle.
The contractor shall support the installation and configuration of network servers, routers, and other peripherals. The contractor shall be responsible for CM design, architecture, and
COTS/GOTS software and hardware integration to include, but not limited to, describing provisions for configuration identification, configuration of requirements documentation, design documentation, software, and related documentation.
The contractor shall be responsible for configuration change control, configuration status accounting, and configuration audits. The contractor shall regulate the change process so that only approved and validated changes are incorporated into product documents and related software. The contractor shall track and report all CM problems and support software quality assurance process audits.
The contractor shall evaluate, implement, and configure hardware and software to ensure Air
Force Information Protection (AFIP) and DOD policies are enforced and safeguards are active.
The contractor shall configure test beds to conduct testing on DC3 networks; record and analyze results; and provide recommendations for improvements of the products/systems tested. The contractor shall encode, debug, and test software applications to meet established operational and system requirements using industry standard products such as programming languages and tools as required.
2.1.5 IT ASSET MANAGEMENT
The contractor shall provide support in receiving, tracking, distributing, and accounting for
DC3’s hardware and software inventory. DC3 shall use Jira for its asset management software.
The contractor shall maintain an up to date library of all major equipment warranty/maintenance contract information as well as life cycle and end of life (EOL) status.
The contractor shall support maintaining a complete inventory of all of DC3’s major hardware and/or designated components and the recording of serial numbers and related nomenclature.
The contractor shall maintain and update a software library accounting for all software, licenses, and issuance data. The contractor shall ensure all asset lifecycle information is tracked, monitored, and reported appropriately to ensure timely renewal or refresh of EOL assets.
The contractor shall document and regularly update the total cost of operations (TCO) for each DC3 network in accordance to guidelines provided by the Government. The need to identify costs as well as provide investment transparency, the contractor shall assist the
Government in developing a chargeback or show back model that depicts IT investments by identifying the components of IT costs that are directly associated to the infrastructure, data transfer, application licenses, training, etc., which they generate. The intent is to ensure appropriate use of IT resources, providing visibility to the DC3 leadership, substantiate rationale for IT decisions, and conform to budgeted IT services.
The contractor shall ensure IT asset information is made available to the Government, on demand.
2.1.6 CYBERSECURITY (CS)
The contractor shall assist in maintaining CS protection of all DC3 data and systems. The contractor shall provide technical support to maintain the confidentially, integrity, and privacy of DC3 IT and mission information systems.
The contractor shall support the DC3 Chief Information Security Officer (CISO) in executing the CS requirements for DC3 information technologies through the use of the RMF consistent with the principles established in National Institute of Standards and Technology (NIST)
Special Publication (SP) 800-37r2 and as outlined in DoDI 8510.01, RMF for DoD IT. The contractor shall perform continuous monitoring activity and support the implementation and operations of an insider threat capability. The contractor shall continually identify and inject
RMF requirements into DC3 acquisition processes, requirements development, procurement, and IT (hardware and software) development efforts.
The contractor shall provide services to include active security vulnerability assessment, implementation, and monitoring of all computer systems and network infrastructure. The contractor shall perform vulnerability/risk analyses of computer/network systems and applications during all phases of the system development life cycle. The contractor shall assist in conducting certification and accreditation on applications in accordance with the RMF.
The contractor shall assist in eliminating the threat of network intrusions by proactively probing network defenses to identify vulnerabilities to include administering network scans as required.
The contractor shall ensure the latest security updates are enforced, ensure Information
Assurance Vulnerability Alert (IAVA) and Tactical Computer Network Operator (TCNO) compliance, and provide real-time protection from any threats of active files using anti-virus tools. The contractor shall operate and maintain firewall(s), web proxy, caching servers, and e-mail gateway servers to protect DC3 information resources from internal and external threats. The contractor shall ensure all current network security tools and patches are implemented across all internal DC3 systems in accordance with AF and DoD standards. The contractor shall conduct daily security scans of computer/network systems and advise the
Government of potential computer security concerns and problems along with recommendations for solutions.
The contractor shall develop/maintain measures and controls to protect the DC3 networks from denial of service, unauthorized access, and modification of data and destruction of DC3 networks, network components, or information processed on them. The contractor shall document and maintain IT security policies, procedures and awareness.
The contractor shall perform information protection functions for networks and IT systems.
The contractor shall test computer/network systems and applications for the following:
a. Ease of unregulated entry
b. Systems resources denial
c. System information corruption
d. Unlawful use of system resources
e. Vulnerability to electronic disruption
The contractor shall report and document all identified system attacks to the DC3 BTO
Director/CIO and TPOC.
The contractor shall provide support related to Communications Security (COMSEC). The contractor shall document receipt, custody, issuance, transmittal, storage, accountability, classification, and destruction of all Classified Material. The contractor shall maintain logs and journals to comply with AF security, regulatory, and policy guidelines. The contractor shall be responsible for maintaining and updating all secure equipment, records, and self-inspection programs concerning Classified Material.
The contractor shall ensure all systems and equipment are operated and maintained in accordance with DoD, Defense Information Systems Agency (DISA), USAF, Secretary of the
Air Force/Inspector General (SAF/IG) and OSI security guidelines, directives and updates.
The contractor shall ensure all security policies are within the limits of existing architecture and software capabilities. The contractor shall assure the DC3 network and IT systems are
100 percent in compliance with applicable DoD and USAF directives for Network and
Computer Security.
2.1.7 WEB, PORTAL, AND CONTENT MANAGEMENT SYSTEM (CMS)
DEVELOPMENT AND MANAGEMENT
The contractor shall support the DC3 internet and intranet websites, collaborative portals, and
CMSs supported by this contract. The contractor shall provide administrative, development, and technical management of all facets of the managed websites, portals, and CMSs as directed by the responsible Government Information/Knowledge/Records Management lead.
The contractor shall keep current all content on managed DC3 websites/portals and ensure these are compliant with DoD and USAF policies, directives, and standards. The Government
PAO must approve all public facing information. The contractor shall provide a review of all content updates at each MSR. The contractor shall perform continual evaluations of websites, portals, and CMS software and hardware to ensure continued and future effectiveness and efficiency of these capabilities and recommend updates, changes to the Government as appropriate and necessary.
The contractor shall design, develop and implement web pages that fully comply with
AF/DOD/DC3/PAO requirements and standards. The contractor shall maintain DC3’s World
Wide Web (WWW), NIPRNET, SIPRNET, DFI Portal and JWICS websites and content.
2.1.8 DATABASE MANAGEMENT SUPPORT
The contractor shall provide database installation, configuration and management for all DC3 databases. The maintenance of databases includes ensuring data reflected is accurate and current with incremental daily backups and a full backup provided weekly. The contractor shall modify the information contained in the database as directed by the Section Chief. The contractor shall ensure that information from the databases is accessible to users as determined by the Section Chief using documented instructions provided by the contractor.
The contractor shall develop and administer security procedures to ensure only valid users have access to data and data modification. The contractor shall be responsible for ensuring data integrity while performing database related functions.
2.1.9 VIDEO AND TELECOMMUNICATIONS SUPPORT
The contractor shall provide overall support to DC3’s telephone, telecommunications systems, and secure telecommunications equipment (currently Nortel and PBX). The contractor shall provide day-to-day technical administration of the phone system, perform scheduled and non-scheduled maintenance, coordinate repair actions with service providers, and verify telecommunications circuits are active and available for use. The contractor shall monitor the performance of telephone sets, voicemail systems, modems, fiber optic cables, telephone switching units, and data circuits. The contractor shall provide immediate written notice within
24 hours to the DC3 ITD Director, BTO Director/CIO and TPOC of a situation impacting communications.
The contractor shall provide end-user training for telephone devices; configure voicemail, and all other phone system operations and features of the equipment.
The contractor shall provide onsite technical support for Audio Visual (AV) and Video
Conferencing equipment (currently Tandberg) for multiple classification levels (NIPR, SIPR, and JWICS.)
2.2 DEFENSE CYBER FORENSICS LAB (DC3/CFL) OPERATIONS SUPPORT
DC3 operates an ANAB accredited digital data / multimedia forensic laboratory called the
Defense Cyber Forensic Lab (DC3/CFL). DC3/CFL conducts examinations on digital and multimedia items submitted to the lab for analysis. DC3/CFL receives examination requests from all across the reach and scope of the DoD. DC3/CFL conducts a wide variety of examinations to include, but not limited to, homicide, child sexual exploitation, sexual assault, identity theft, counterfeiting, misconduct, terrorism, intrusions, fraud, and misuse of
Government property. DC3/CFL operates across various security classifications levels to include: SBU, Secret, TS, SCI, SAP and SAR.
2.2.1 DC3/CFL INTAKE SUPPORT
The contractor shall support inbound customer service inquiries including DC3/CFL forensic examination requests. The contractor shall assist with identifying potential case conflicts, evidential issues, and operational or policy impacts. The contractor shall recommend, update, and maintain the intake procedures under the direction of the Lab Director of CFL; and identify forensic requirements of customer request and potential schedule.
2.2.2 DATA IMAGING AND EXTRACTION (I&E) SUPPORT
The contractor shall perform forensic imaging and extraction of digital information in support of forensic examinations to develop evidence and intelligence information. The contractor shall ensure data imaging and extraction of media is completed within specified timelines indicated in the Service Level Agreements (SLA). The size and complexity of each forensic image is considered when determining actual suspense.
a. The contractor shall prepare and perform forensic imaging and extraction on a variety of digital media including computers and laptops, mobile devices, Internet-of-Things
(“IOT”) devices, optical and removable media, Digital Video Recorders (“DVR”), cameras, gaming devices, and others yet to be determined. Contractor shall have the expertise to assess new and esoteric devices that may contain data and identify methods for data extraction and imaging.
The contractor shall be required, at times, to provide on-site imaging and extraction at specific evidence sites and alternate operating locations.
The contractor shall be responsible for extracting and duplicating forensically sound images of the media utilizing DC3/CFL-approved imaging tools. Once the evidence or original media is extracted and duplicated, the contractor shall be responsible for archiving all image files to an appropriate storage media.
The contractor shall record, document, and maintain written notes throughout the forensic imaging process and input data into appropriate information systems as directed. All forensic processes conducted by the contractor shall be documented as directed by policies and procedures set forth by CFL. The contractor shall perform repair and recovery of data from damaged media on all cases assigned by the Government. The contractor shall have the ability to and employ specialized techniques for damaged media recovery, hard drive repair, and
CD/DVD ROM disk resurfacing; and be able to produce restored copies of the suspect media for examination.
Additionally, the contractor shall participate, present, and provide input at briefings, meetings, conferences, panels, boards, seminars, working group sessions, technical exchanges, and public forums on cyber-crime and forensic-related D/MM media imaging and extraction as directed by CFL.
2.2.3 EXAMINATION SUPPORT
The contractor shall support the planning, organization, and execution of digital forensic examinations for a broad range of evidence items submitted to DC3. This work shall be completed in accordance with requirements set forth by the Government and Federal law, the
Uniform Code of Military Justice, CFL guidelines and policy , and the DC3 Personnel
Handbook.
Forensic analysis shall include exams in support of civil, criminal, and other casework and cover a broad range of expertise areas. Contractor must have capabilities in advanced forensic analysis including cryptography, malware reverse engineering, specialized mobile forensics, data recovery from damaged media, password cracking, unknown file system analysis, and other complex forensic processes as the need arises. Cases shall be assigned by the Government.
The contractor shall conduct malware analysis, reverse engineering software development, and the cyber-attack lifecycle, from the initial exploit and malware execution path to callback destinations and follow-on binary download attempts.
The forensic examination performed by the contractor shall follow industry-standard Digital
Forensic processes that protect the integrity of the evidence and may include verification and comparison of the forensic image files; examination for the presence of malicious logic such as viruses, Trojans, worms, etc.; examination of media for deleted files and folders;
documenting active and recovered deleted files; analysis for misnamed files; conducting word searches; and, analysis for relevant hardware and software configuration information.
The contractor shall write concise, comprehensive, and accurate notes throughout the examination process. The contractor shall also develop a complete D/MM Forensic Analysis
Report (DFAR) upon completion of the examination.
The contractor shall perform technical peer reviews and feedback of other examiner cases.
The technical peer review shall include reviewing other examiners reports for technical accuracy, readability, and administrative compliance with all procedures.
The contractor may be required to present findings of their work in Military, Federal, State, or local courts as an expert witness and oftentimes, with little notice. The contractor may be required to travel to CONUS and OCONUS court proceedings to provide testimony.
The contractor shall also perform D/MM forensics examinations in support of the National
Media Exploitation Center (NMEC). This support includes processing critical national intelligence level cases that require expert analysis on audio/visual equipment, cell phones, and other mobile devices, and analyze information to determine useful data and content across a number of NMEC databases. The contractor shall perform audio and video forensics on commercial video systems and digital recording devices to extract, digitize, and enhance audio and video data for case agent review.
2.2.4 EVIDENCE CUSTODIAL SUPPORT
The contractor shall assist the evidence custodian in ensuring an effective evidence program is maintained and provides support services for all evidence entering and exiting DC3/CFL at the direction of the Government.
All contractor personnel assigned to the Evidence Room shall be trained to handle evidence in accordance with DC3/CFL and DoD policies. Upon completion of the training program, personnel shall be required to pass a written test to work in the Evidence Room.
The contractor shall receive, review, and maintain the integrity and proper custody of the evidence. The contractor shall identify and report any discrepancies in receipt of the evidence to the Evidence custodian. The contractor shall ensure forensic processes, handling, and hardware utilized are designed to safeguard all submitted evidence.
The contractor shall receive, inspect, and administratively process all incoming evidence, packages, and freight deliveries into the laboratory. Some items received may be large and the contractor shall be capable of handling heavy objects up to 50 pounds.
The contractor shall establish chain-of-custody documents for all evidence to document the transfer of the evidence within DC3/CFL.
The contractor shall identify, photograph, store, and ensure all evidence is properly marked, tracked, and processed. The contractor shall update received evidence into CFL’s various information management programs as directed by policy. In addition, the contractor shall assist in resolving evidence control problems and perform routine evidence audits.
The contractor shall create, update, and maintain case folders containing all required forms and supporting documentation for the case.
The contractor shall monitor and control the evidence in all aspects of laboratory operations and shall conduct reviews of all incoming and outgoing evidence chain-of- custody documents.
The contractor shall be responsible for returning all evidence to the owning agency when the imaging and extraction process is complete. The contractor shall support the tracking and monitoring of all related shipping costs identifying all costs to the DC3 Financial Manager for review.
2.2.5 DC3/CFL QUALITY ASSURANCE
The contractor shall provide assistance to DC3/CFL in maintaining, updating, and managing the lab’s Quality Assurance Program (QAP). The contractor shall support CFL’s document control program and ensure appropriate controls, versioning, and updates are regularly maintained. This includes the issuance of lab orders, quality manual updates, and creating or updating other lab-related documents.
The contractor shall also be responsible for managing documents and controls related to examiner qualifications, education, and prior testimony as well as documents related to scientific procedures and methods as directed by the Government. The contractor shall maintain the DC3/CFL QAP to include performance metrics to measure the lab’s effectiveness, formal and informal reviews of analyses, and methods to ensure quality and customer satisfaction. This includes regular monthly metrics as well as ad-hoc reporting as directed by the Government.
2.2.5 DC3/CFL TRAINING DEVELOPMENT AND MENTORING PROGRAM
To remain on the cutting edge of advances in D/MM forensic technology, DC3/CFL personnel require continual training. The contractor shall support DC3/CFL by monitoring, updating, and tracking all DC3/CFL personnel (contractor and Government) training through completion to maintain currency and adherence to the QAP. Currently, there is a 40-hour continuing education requirement for all examiners.
The contractor shall assist DC3 with establishing and maintaining requirements for a D/MM
The contractor shall assist in developing and maintaining a remedial action plan to ensure all
Forensic Examiners successfully complete proficiency tests as required by the QAP to perform forensic work in DC3/CFL.
The contractor shall assist the DC3 with the establishment and management of a D/MM forensic examiner mentoring program to assist in the training of all new DC3/CFL employees in accordance with the DC3/CFL Employee handbook and DC3 SOPs. The contractor shall ensure all new employees are assigned a mentor to provide guidance through site-specific policies, initial tasks, and training. The contractor shall document the effectiveness of the mentor program and provide input on strategies to improve the new employee transition in program at DC3/CFL.
2.3 DC3/TSD OPERATIONAL SUPPORT
The contractor shall assist the DC3/TSD with its mission to provide legally and scientifically accepted standards, techniques, methodologies, research, tools, and technologies on digital forensics and cyber threat analysis to meet current and future threats. The contractor shall assist DC3/TSD with pioneering digital forensic and cyber threat analysis tools, processes, and procedures to ensure DC3 remains on the leading edge of the discipline. The contractor shall assist DC3/TSD in managing the planning, programming, and execution of program and infrastructure requirements linked to advancing digital forensic and cyber threat analysis research, development, test, and evaluation efforts.
2.3.1 DC3/TSD SYSTEMS DEVELOPMENT
The contractor shall assist with the planning, design, development, and deployment of digital forensics and cyber threat analytical capabilities. The capabilities developed in support of this task consist of short to long term software development projects. Once developed, these capabilities are property of the Government.
The new development projects range from large, complex modernization efforts to a smaller file parsing effort. Historically, new development projects of large scale have required five or more resources, medium scale projects up to four resources, and smaller scale projects up to two resources. On average per year, DC3/TSD does approximately four large scale projects
(greater than 240 hours for development and IT support), nine small scale projects (less than
240 hours for development and IT support). There were approximately ten operations and maintenance (O&M) projects that required approximately four releases each a year.
The contractor shall support the incoming project requirements at DC3/TSD which are generated from internal DC3 customers (Directorates) as well as external customer agencies
(i.e., SOCOM, MDCOs, NMEC, etc.). Customer engineering requests are delivered to
DC3/TSD through submissions to the current System of Record (DC3 Enterprise Support
Center – TSD Support)”. When necessary, the contractor shall support the requirements for submitting new projects through the DC3’s Baseline Change Control Process. The contractor shall assist DC3/TSD with creating, reviewing, prioritizing, and tracking requests. The contractor shall review requests for existing solutions as well as commonalities with other solutions and document those identified commonalities.
The contractor shall ensure all established requirements requests are in line with agency regulations, Federal law, the Uniform Code of Military Justice, DC3 SOPs and Quality
Assurance guidelines, and the DC3 Personnel Handbook in developing computer software and performing forensic tests of computer forensic software. The contractor shall provide a written analysis of all requests that are outside the scope or problematic to such regulations.
The Government’s desire is to use Commercially Off the Shelf (COTS) or already existing
Government Off The Shelf (GOTS) products (hardware/software) at DC3. During the
Technical Assessment (TA) of the Baseline Change Control Process the contractor shall complete an alternative analysis by searching for existing COTS and GOTS solutions.
The contractor shall be responsible for creating the system concept, capturing requirements, design, development, testing, deployment, and O&M. The contractor shall, for all priority projects as defined by the Government, develop a project in accordance with the DC3/TSD
System Development Lifecycle SOP and Baseline Change Control Process. All projects are required to be tracked in the DC3 Integrated Master Schedule (Deliverable) in accordance with DC3.
The contractor shall work with all system stakeholders during requirements gathering to ensure the requirements are accurate, documented, and approved before design.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .