RFI Attachment 5-Draft_IA-RMF_C5ISCTaskOrderPWS_v0.3_05-25-23.docx

DOCX document 403 KB Posted

Attached to
USCG Information Assurance (IA) Risk Management Framework (RMF) Services Federal contract opportunity
Solicitation number
70Z04423IESDIAB01
Issued by
Department of Homeland Security US Coast Guard

View the file

Other files for this federal contract opportunity

Other files attached to USCG Information Assurance (IA) Risk Management Framework (RMF) Services, newest first.
File Type Posted
RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23.xlsx XLSX spreadsheet
RFI Attachment 1-Questionaire_RFI ESDIAB01_05-25-23.docx DOCX document
RFI Attachment 2 - Draft_IA-RMF-IDIQ_RFP_v4_05-22-23.docx DOCX document
RFI Attachment 3-Draft_IA-RMF-IDIQ_Scope of Work_20230525_v2.0.4.docx DOCX document
RFI Attachment 6-Question-Comment Form - v1_05-22-23.xls XLS spreadsheet
RFI Attachment 4-Draft_IA-RMF-IDIQ_Labor Categories_V1_04-17-23.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

COMMAND, CONTROL, COMMUNICATIONS, COMPUTERS, CYBER, AND INTELLIGENCE SERVICE CENTER (C5ISC)

PERFORMANCE WORK STATEMENT

FOR

RISK MANAGEMENT FRAMEWORK (RMF) SUPPORT SERVICES

Contract: xxxxxxxxxxxxx
29 March 2023
Task Order: yyyyyyyyyyyyy
Version 0.2 DRAFT

PR #:

PERFORMANCE WORK STATEMENT

PWS – C5ISC RMF Support Services v0.2, 29 Mar 2023 PAGE 8/17

Table of Contents

1.0General4
1.1Background4
1.2Scope4
1.3Objectives5
1.4Applicable Documents5
1.5Performance Requirements Summary7
1.6Technologies7
1.7Tools7
1.8Service Delivery8
1.8.1IT Management Best Practices8
1.9Scale of Work8
1.9.1Information Systems8
1.9.2Platform IT8
2.0Specific Requirements/Tasks10
2.1Task One: Information System Security Officer (ISSO) Services10
2.2Task Two: Cybersecurity Compliance and Readiness Services12
2.2.1General12
2.2.2Scanning and Vulnerability Management13
2.2.3Incident Management13
2.2.4Knowledge and Metrics Management14
2.3Project Management14
3.0Contractor Personnel15
3.1Qualified Personnel15
3.1.1Cybersecurity Professional Certification15
3.2Key Personnel15
3.2.1Task Order Lead16
3.3Coverage17
3.4Continuity of Support17
3.5Employee Identification17
3.6Employee Conduct17
3.6.1Removing Employees for Misconduct or Security Reasons18
3.7Contractor Training18
4.0Contract Administration19
4.1Contract Type19
4.2Personal Services19
4.3Period of Performance19
4.4Places of Performance19
4.5Hours of Operation19
4.5.1After Hours Access20
4.6Routine Tele-Work20
4.7Travel20
4.7.1Trip Reports20
4.8Contracting Points of Contact20
4.8.1Inspection and Acceptance21
4.9Post Award Conference21
4.10Phase In21
4.11Phase Out21
4.12Project Management Plan21
4.13Contract Status Report and Meeting22
4.14Monthly Operations Progress Report and Meeting22
4.15Quality Assurance23
4.16Quality Assurance Surveillance Plan23
5.0Other Applicable Conditions25
5.1Security25
5.1.1Facility and Computer Access26
5.1.1.1Security Risk and Background Investigation26
5.1.1.2Trusted Associate Sponsorship System (TASS)26
5.1.2Special Categories28
5.1.3Contractor Personnel Security Training28
5.1.4Safeguarding Sensitive Information28
5.1.5Security Deliverables29
5.1.6Requirements for Providing Hardware, Software, and Services29
5.1.7Contractor Proposed Cyber/IT-related Solutions29
5.2Intellectual Property29
5.3Protection of Information29
5.4Section 508 Compliance30
5.4.1Section 508 Requirements for Technology Services30
5.4.2Section 508 Deliverables31
5.5DHS-USCG Enterprise Architecture Compliance31
5.6Government Furnished Vehicles32
5.6.1Accident Reporting32
5.7Government Furnished Property32
6.0Deliverables34
6.1Delivery Address34
6.2Delivery Method34
6.3Government Acceptance Period34
6.3.1Acceptance Criteria34
6.4Deliverables35
7.0Supported Systems37
8.0Performance Requirements Summary42

Table of Tables

Table 1 - Applicable Documents5
Table 2 - Technologies Employed7
Table 3 - Security Tools8
Table 5 - Cybersecurity Certification Requirements15
Table 6 - Performance Period19
Table 7 - Government Contracting Management Points of Contact20
Table 8 - Contractor-Proposed Cyber/IT-related Solutions for CG-6 Review29
Table 9 - Deliverables35
Table 10 - Supported Systems37
Table 11 - Performance Requirements Summary42

General Background The United States Coast Guard (USCG) depends on information systems to carry out their missions and business functions in support of six major operational mission programs: Maritime Law Enforcement, Maritime Response, Maritime Prevention, Marine Transportation System Management, Maritime Security Operations, and Defense Operations. An “information system” is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information [44 USC 3502].

The USCG further categorizes “information system” by type, such as Platform Information Technology (PIT), PIT System, and Operational Technology (OT). Examples of USCG information systems include but are not limited to computing systems; cyber-physical systems; industrial/process control systems; environmental control systems; Supervisory Control and Data Acquisition (SCADA); Programmable Logic Controllers (PLC); weapons systems; command, control, communications, intelligence, surveillance, reconnaissance, and navigation systems; devices and information technology products such as smart phones and tablets; and embedded devices/sensors. For the purposes of this document, the term “information system” or “system” refers to any type categorization descriptor used in practice by the USCG, and includes systems connected to the Non-Classified Internet Protocol Router Network (NIPRNet), Secret Internet Protocol Router Network (SIPRNet), systems deployed in commercial cloud environments, and off-network systems.

“Cybersecurity” (which replaced the term Information Assurance [IA]) is defined as prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation.

The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, Risk Management Framework (RMF) for Information Systems and Organizations, provides a system lifecycle approach for security and privacy, and is integral to the implementation of the Federal Information Security Modernization Act (2014). The RMF is mandatory for federal government use and promotes near real-time risk management and ongoing information system authorization through the implementation of continuous monitoring processes; provides senior leaders the necessary information to make cost-effective, risk-based decisions with regard to the information systems supporting their core missions and business functions; and integrates cybersecurity into the enterprise architecture and system development life cycle. The seven-step process of the RMF includes preparation, categorization, selection, implementation, assessment, authorization, and monitoring.

Scope The USCG continues to strive to meet existing security mandates as well as new and emerging security requirements from the Department of Defense (DoD) as well as the Department of Homeland Security (DHS).

The USCG Command, Control, Communications, Computers, Cyber and Intelligence Service Center (C5ISC) requires contractor support to augment the Government’s program to perform the RMF tasks that are the responsibility of the Information System Security Officer, to also include cybersecurity compliance assessment, management, and reporting.

This Performance Work Statement (PWS) defines the related Cybersecurity tasks, RMF Services and management required to support DHS and USCG systems developed and maintained at multiple geographic locations. Most of the Places of Performance are Government-Owned Contractor-Operated facilities with the primary function of providing full life-cycle support for operationally focused USCG systems. Secondary Places of Performance may be USCG vessels and shore facilities, as well as commercial cloud facilities.

Objectives The following are objectives of the C5ISC Cybersecurity Program:

· Provide a comprehensive, consistent, and efficient Cybersecurity Program.

· Ensure risk is identified and managed across the organization focused on cybersecurity.

· Ensure consistent enforcement of information security standards across all information systems.

· Provide consistent, repeatable processes.

· Reduce/eliminate redundant services and delivery methods.

· Provide a more automated approach to provide better solutions with the capability of determining compliance for all information systems on demand.

· Meet all regulatory and agency documented standards and guidance.

· Ensure all regulations and standards are integrated into a fully implementable security program.

· Ensure all new information technology (IT) projects meet or integrate security standards into their development.

· Maintain full compliance with the RMF for all systems.

· Develop a culture of security-mindful professionals across the community.

· Strive to be more flexible and responsive to new regulatory directives.

· Serve as the central authority for all IT security-related activities across the scope of this PWS.

· Ensure information system survivability and integrity.

· Optimize processes to meet IT security-related goals and strategies.

Applicable Documents The following documents provide mandates, policy, specifications, standards, or guidelines that apply to performing the work described in this document. This listing is not all inclusive, as many of these documents provide a chain of references within. As these documents are updated and revised, the most current version takes precedence as the required standard, regardless of the version referenced below:

Table 1 - Applicable Documents

REFERENCE
DESCRIPTION / TITLE
FISMA
Federal Information System Modernization Act (2014)
P.L. 93-579
Public Law 93-579 Privacy Act, December 1974 (Privacy Act)
P.L. 104-191
Health Insurance Portability and Accountability Act (HIPAA) of 1996
P.L. 104-106
Clinger-Cohen Act (CCA)
EO 13526
Classified National Security Information
OMB A-130
Managing Information as a Strategic Resource
FAR
Federal Acquisition Regulation (FAR)
CJCSI 6510.01E
Information Assurance and Support to Computer Network Defense
DoDD 8140.01
Cyberspace Workforce Management
DoD 5200.1R
DoD Information Security Program
DoDI 8500.01
Cybersecurity
DoDI 8510.01
Risk Management Framework for DoD Systems
DoD 8570.01-M
Information Assurance Workforce Improvement Program
DHS BOD 18-02
Securing High Value Assets
DHS MD 140-01
Information Technology Security Program
DHS MD 11042.1
Safeguarding Sensitive but Unclassified (FOR OFFICIAL USE ONLY) Information
DHS MD 11056.1
Sensitive Security Information (SSI)
DHS Instruction 102-01-103
Systems Engineering Life Cycle (SELC)
DHS Instruction 102-01-004
Agile Development and Delivery for IT
COMDTINST M2620.2 *
Cyberspace Operations Manual
COMDTINST 4130.6
USCG Configuration Management Policy
COMDTINST M5216.4
Coast Guard Correspondence Manual
COMDTINST M5000.10 (series)
USCG Major System Acquisition Manual (MSAM)
COMDTINST M5000.11 (series)
USCG Non-Major System Acquisition Manual (NMAP)
COMDTINST M5500.13 *
U.S. Coast Guard Cybersecurity Manual
COMDTINST 5500.18
Coast Guard Trusted Associate Sponsorship System (TASS)
COMDTINST M5520.13 *
USCG Industrial Security Program
C5ISCINST M4130
C5ISC Configuration and Change Management Policy
FIPS 199
Federal Information Processing Standards Publication (FIPS) 199 - Standards for Security Categorization of Federal Information and Information Systems
FIPS 200
Minimum Security Requirements for Federal Information and Information Systems
NIST SP 800 Series
National Institute of Standards and Technology (NIST) Special Publication (SP) 800 Series
DISA STIGs & SRGs
Security Technical Implementation Guides and Security Requirements Guides

* Accessible on CG Network (not publicly accessible) Performance Requirements Summary This Task Order includes a Performance Requirements Summary (PRS) in Section 8.0. The PRS plays an integral role in the administration of the Task Order. In addition to any applicable inspection clauses or other related terms and conditions contained in the contract, the PRS shall serve as a primary tool for inspection and acceptance of services as facilitated by the Contracting Officer’s Representative (COR). Evaluation of the Contractor’s overall performance shall be in accordance with the performance standards set forth in the PRS, and will be conducted by the COR. The PRS constitutes a material aspect of the Task Order and will not be changed or otherwise modified without prior written approval of the Contracting Officer (KO).

Technologies The following list of technologies employed is not exhaustive and is intended to be representative.

Table 2 - Technologies Employed

Technology Category
Examples
Operating Systems
Windows, *nix
Web
Windows Internet Information Services (IIS), Apache, Oracle Application Server
Database
Microsoft SQL Server, Oracle Database
Infrastructure
CISCO Hardware (switches, routers, Unified Computing Services), Virtualization (VMware ESXi)
Application development
Containerization capabilities such as Docker, Continuous inspection capabilities such as HP Fortify

Tools The following table provides a short description of the organizationally approved tools that are instrumental in providing the services described in this PWS. This list is subject to change because of one tool superseding another or additional security products being adopted by USCG, DoD, or DHS and being mandated for use. Contractor personnel are expected to be trained and knowledgeable in the use of the tools listed below at a minimum appropriate to the services they are providing.

Table 3 - Security Tools

Tool
Description
ACAS / Nessus / Security Center
Network vulnerability assessment system
Elastic SIEM
Centralized log correlation solution
eMASS
DoD FISMA tracking and reporting system
BMC Remedy
Ticket system for support requests
Host Based Security System (HBSS)
DoD host-based security system providing end point security services
Tanium
Unified end point management and security platform
Splunk
Provides IT, security, and business analytics
Burpsuite
Website vulnerability scanner

Service Delivery One of the overarching goals of providing cybersecurity services across a large organization is to execute services in the most efficient means possible. The following guidelines are to be used when organizing staff and developing or re-engineering processes.

· For assigned systems, there shall be an Information System Security Officer (AISSO) assigned to each information system. One ISSO can have more than one system. It is imperative these positions are always covered during the period of performance.

· There shall be a “back-office” capability that centralizes some cybersecurity functions and provides services to C5ISC ISSOs.

IT Management Best Practices The Contractor shall adopt, apply, and help institutionalize the IT Delivery Standards of the Defense Enterprise Service Management Framework (DESMF) and norms from bodies of knowledge such as the Information Technology Infrastructure Library (ITIL®), Control Objectives for Information and Related Technologies (COBIT®), the Capability Maturity Model Integration (CMMI®), Six Sigma, International Organization for Standardization/ International Electrotechnical Commission (ISO/IEC) 20000, ISO/IEC 27001, and Project Management Institute (PMI) Project Management Body of Knowledge (PMBOK®).

Scale of Work Information Systems Unless otherwise specifically stated, the Contractor is responsible for full RMF Process support of the Information Systems and Platform IT Systems that are listed in Section 7.0, Table 9.

Platform IT Platform IT (PIT) is often unique and has technical constraints that limit or prohibit the implementation of traditional cybersecurity due to the use of specialized software, hardware, and protocols. Though all PIT has cybersecurity considerations, PIT that does not rise to the level of a PIT System will not follow the full Risk Management Framework (RMF) process.

When starting the assessment process for PIT, the ISSO follows the Risk Management Framework (RMF) process (for “assess only”) up to Step 5, where the Authorizing Official (AO) makes a determination of an acceptable level of risk and grants a PITA. Unlike the Authority to Operate (ATO), the PITA is not reassessed every three years. Upon the receipt of the PITA, the system maintains its approval for the life of the system, following a continuous monitoring approach, while continuing to maintain its configuration management through the Request for Modification (RFM) process.

The contractor is responsible for service delivery for PIT, as assigned and prioritized. Due to the nature of the PIT RMF process requirements, the government will provide the contractor with a prioritized list of PIT work based on critical mission need and backlog management. The government expects a minimum of 15 PIT assessments be submitted annually.

Specific Requirements/Tasks The Contractor shall provide Cybersecurity Services in support of the C5ISC Cybersecurity Program. Given the details provided in this PWS, the Contractor shall provide the expertise, technical knowledge, staff support, and other related resources necessary to provide the services and deliverables as described.

The Contractor shall designate sufficient management to oversee and ensure that Services and Deliverables are submitted, performed efficiently, accurate, on time, and in compliance with the standards of this document as well as any other supplemental guidance provided by the Government within the scope of this Task Order. Section 6.4 of this PWS provides a table of formal deliverables.

0. Task One: Information System Security Officer (ISSO) Services The Contractor shall serve as the designated ISSO for assigned systems. The ISSO is responsible for but not limited to the following tasks:

(a) Lead the RMF process for assigned systems, or enclaves.

(b) Generate and maintain the RMF documentation package that meets all Department of Defense (DoD) requirements and is tailored to a specific system to include but not limited to; Security Categorization Determination, Implementation Plan, System Security Plan (SSP), Configuration Management Plan (CMP), Incident Response Plan (IRP), Contingency Plan (CP), Authorization documentation, IT Security Plans of Action & Milestones (POA&Ms), Scorecards, Security Assessment Reports (SAR), Continuous Monitoring Strategy, Hardware/Software lists, Threat Models, Cybersecurity Strategy, Network Topology, Network Cybersecurity Boundary Diagrams, and Data Flow Diagrams using Government prescribed tracking and processing tools.

(c) Continue to maintain all Ongoing Authorization (OA) requirements as determined by the Government.

(d) Ensure that all DoD Information System (IS) cybersecurity-related documentation is current and accessible to properly authorized individuals.

(e) Provide analyses and decision support information for Coast Guard Cyber Command (CGCyber) to make system/network risk management determinations for an authorization decision.

(f) Interpret system designs and diagrams for the purposes of identifying data interconnections, interfaces, protocols, and data types in order to select appropriate security controls to remediate or minimize Cybersecurity risk exposure to the Coast Guard.

(g) Provide support and develop a connection approval package such as an Interconnection Security Agreement (ISA), Memorandum of Understanding (MOU), Service Level Agreement (SLA), Authorization to Connect (ATC), and so forth, for systems that require connectivity to any type of USCG Local Area Network (LAN) (i.e., DoD Information Network (DoDIN), CGOne, SIPRNet).

(h) Develop plans and perform testing to evaluate compliance with all applicable DoD and industry security requirements, standards, and best practices.

(i) Utilize Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)/Secure Requirements Guide (SRG) assessments including leveraging automation as much as possible to gain efficiencies.

(j) Perform Security Readiness Reviews (SRR) for the Operating Systems and applications.

(k) Perform automated scans and analysis using Security Compliance Checker (SCC) DISA Security Content Automation Protocol (SCAP) benchmarks or current DoD approved tools.

(l) Perform automated scans and analysis using the Assured Compliance Assessment Solution (ACAS)/Nessus or current DoD approved tools.

(m) Maintain the continuous monitoring process and ensure all systems are compliant with DoD and USCG security guidelines, and DISA STIGs.

(n) Review all vulnerabilities identified through regularly scheduled and ad-hoc scanning, assign and track remediation responsibility, and track identified vulnerabilities through remediation via the regular patching cycles or until a POA&M is created for tracking.

(o) Identify any vulnerabilities that remain on the system after a period of time and notify designated patch manager to engage to determine how the finding will be disposed.

(p) Maintain process and procedures, in coordination with the government, that enable the organization to adhere to Requests for Modification (RFM) while remaining compliant with the overall RFM organizational process.

(q) Participate in system change management boards and DHS Systems Engineering Life Cycle (SELC) reviews, as necessary.

(r) Conduct Security Impact Assessments (SIA) as part of the change management process to determine if there are any impacts to implemented security controls.

(s) Ensure that all Assessment and Authorization (A&A) packages are completed and submitted in time to prevent Authorization to Operate (ATO) expiration.

(t) Provide oversight (approval/disapproval) of Ports, Protocols, and Services (PPS), which includes initial registration for an information system, Enterprise Application, or network ports, protocols, and services, and maintain updates to the registered PPS baseline in compliance with the Category Assurance List (CAL).

(u) Initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered.

(v) Coordinate any security incident forensic analysis with CGCyber Cyber Security Operations Center (CSOC) Incident Response Service Line.

(w) Review, update and publish all cybersecurity artifacts to support unclassified (including Chief Financial Officer (CFO)), and classified efforts within USCG prescribed tools and maintain any security relevant artifacts.

(x) During all SELC phases, develop documentation and provide any required information for all levels of classification in support of the RMF process.

(y) Provide support and collaboration to external inspections, evaluations, audits, and assessments as applicable for supported systems.

(z) Manage and track all Plans of Action and Milestones (POA&Ms) created by the organization to address identified weaknesses, vulnerabilities, and audit/assessment findings from creation to closure. Coordinate with other organizations as needed in the processing and management of the POA&Ms. This includes validation of POA&M content submitted by the area of responsibility (AOR) for weakness remediation; ensuring POA&Ms are submitted via proper channels; providing reports and status tracking of remediation efforts; working with the AOR as needed to ensure items are completed in a timely manner; gathering appropriate artifacts for closure; and identifying POA&Ms that will need waivers or risk acceptance.

(aa) Develop and coordinate Contingency Plan (CP) training/testing as required by DoD and USCG policy annually on or before the expiration date of the previous annual test.

(ab) Coordinate annual Disaster Recovery (DR) Failover testing for systems with a DR presence and document results of testing to present to the government as needed.

(ac) Maintain Host Based Security System (HBSS) compliance for assigned systems, and ensure systems are Command Cyber Readiness Inspection (CCRI) compliant.

(ad) Review HBSS exception and exclusion requests and provide recommendation for government approval.

(ae) Monitor and remediate rogue devices.

(af) Review system HBSS reports.

(ag) Review applicable system logs in accordance with USCG or DoD security policies and security configuration guidance.

(ah) Request system-related audit triggers to monitor and correlate daily records at least once per week. Coordinate with C5ISC-ISD-SEC on any custom parser/triggers/alerts.

(ai) Review system audit records and intrusion detection data to identify security incidents.

(aj) Analyze any potential threat vectors across disparate internal related systems.

(ak) Report any system related log data integrity issues or gaps to the government.

Task Two: Cybersecurity Compliance and Readiness Services General

(a) Support Cybersecurity strategic planning activities to evaluate enterprise services through the assessment of priorities and risks.

(b) Review and provide feedback and/or approval for all Firewall requests submitted to the USCG Kearneysville data center Local Area Network (LAN), to ensure request implementation complies with established Firewall standards and any deviations are documented and authorized by the government.

Scanning and Vulnerability Management

(a) Conduct and evaluate vulnerability scans, including Information Assurance Vulnerability Management (IAVM) compliance, using USCG prescribed tools recurring by the end of each month, and as necessary as directed by the government for assigned systems.

(b) Develop and maintain procedures to track IAVM compliance, and remediation responsibilities (e.g., patching oversight) for assigned systems.

(c) Utilize standard software tools to conduct vulnerability scans of networks and databases.

(d) Conduct ad hoc remediation vulnerability and compliance scans.

(e) Conduct and/or coordinate monthly scans for all devices at National Maritime Center (NMC) – approximately 300 workstations/laptops, servers, and printers)

(f) Ensure that 95% authenticated ACAS vulnerability scan rate is achieved and maintained.

(g) Coordinate services with CGCyber Vulnerability Assessment Team (VAT) to ensure service levels are maintained and available.

(h) Ensure that all assets within scanning tools are assigned to the appropriate boundaries to ensure that complete and accurate scanning is occurring.

(i) Provide scan results to the ISSO’s and AISSO’s, as well as information system administrators.

(j) Manage and coordinate scanning credentials to ensure all environments are accessible by the scanners and sensors.

(k) Provide false-positive (FP) management ensuring there is a means to submit a FP claim, process that claim through proper validation, and coordinate with CGCYBER for submission of DISA tickets if warranted. Prevent the FPs from continuously being analyzed but be able to revalidate and dispose of periodically.

Incident Management

(a) Initiate Cybersecurity Incident Response procedures, and protective or corrective measures when a cybersecurity policy or process violation (e.g., local USB violation, and so forth) is discovered.

(b) Work with the site Command/Division Security Officer to investigate and process policy violations in accordance with established procedures.

(c) Close out policy violations in the Violations, Infractions, and Negligent Disclosures (VIND) database once they are resolved.

Knowledge and Metrics Management

(a) Develop and maintain matrices to track and analyze trends in IA readiness and compliance.

(b) Collaborate with the government to develop metrics to provide the Cyber Health for information systems based on mandated reporting and supplemental risk scorecards.

(c) Track and report status on all official authoritative orders. These orders can originate from JFHQ-DoDIN, US Cyber Command, CG Cyber Command, and generally take the form of Operational Orders (OPORDs), Task Orders (TASKORDs), Fragmentation Orders (FRAGOs) applicable to released TASKORDs or OPORDs, ALCOASTs or Time Compliant Technical Orders (TCTOs).

(d) Maintain awareness of all policy that provides input to Cybersecurity requirements and facilitate standards and guidance distribution and updates to IA stakeholders.

(e) Respond to ad-hoc IA data calls as directed by the government.

(f) As security requirements change, assist in preparation, review, and update policies and procedures for compliance with DHS, DoD and USCG requirements.

(g) Create, update, and maintain standard operating procedures (SOPs) for all processes, tools, and procedures necessary for the contractor to fulfill the requirements of this PWS.

(h) Provide data analysis, metrics development, and reporting for cybersecurity areas such as Inventory and Asset Management, Vulnerability remediation AORs, IAVM tracking, and so forth.

(i) Maintain the Information Assurance A to Z (IAATZ) database in support of data analysis and metrics development.

(j) Coordinate reporting with Government management.

Project Management The Contractor shall utilize IT Management best practices as indicated in Section 1.8.1 and applicable C5ISC Project Management processes to ensure services comply. The Contractor shall ensure the proper coordination of activities in alignment with C5ISC Project Management processes, SELC processes, and appropriate associated reviews and control gates.

(a) Develop and maintain a 3-year master schedule for assessment efforts for all assigned systems.

(b) Develop and maintain a Service Catalog that includes level of effort (LOE) documented for all services listed.

(c) Develop and maintain DoD Architecture Framework (DoDAF) artifacts that describe work efforts and align to ITIL. (Specifically, OV-6C or swim lane diagrams.)

Contractor Personnel

0. Qualified Personnel The Contractor must provide qualified personnel to perform all functional and technical requirements specified in this PWS.

All Contractor employees shall be citizens of the United States and meet the security background criteria as defined in Section 5.1, Security. All Contractors, to include internal and external consultants and/or support staff must also meet required security criteria. All Contractor personnel must have a favorably adjudicated background investigation as defined by the USCG prior to being granted access to a USCG IT System.

The contractor is responsible for applying for, obtaining, and maintaining a valid Common Access Card (CAC) as a condition of continued employment under the contract. Contractors that access USCG IT must also follow USCG Cybersecurity guidelines and provisions and may be required to complete a System Authorization Access Request (SAAR) DD-2875.

Contractor personnel with privileged access requirements will follow the USCG Privileged User Management Program (PUMP) process for access.

Cybersecurity Professional Certification The Cyberspace workforce elements addressed include contractors performing functions in designated Cyber IT positions and Cybersecurity positions. Contractor personnel performing cybersecurity functions must meet all cybersecurity training, certification, and tracking requirements as cited in DoD 8570.01-M prior to accessing DoD information systems. Proposed contractor Cyber IT and cybersecurity personnel must be appropriately qualified prior to the start of the Task Order performance period or before assignment to the Task Order during the performance period. Per DoD Information Assurance Workforce Improvement Program, DOD 8570.01-M (series), waivers and exceptions for Contractor certifications will not be granted.

Table 5 - Cybersecurity Certification Requirements

Cybersecurity Role
Required Certification Level
ISSO
IAM II
Privileged User
IAT I
Cybersecurity Compliance and Readiness
IAT II
Task Order Lead
IAM II

The Contracting Officer (KO) or the appointed COR will ensure that all Contractor personnel are appropriately certified and provide verification to the Defense Manpower Data Center (DMDC) database: https://milconnect.dmdc.osd.mil/milconnect/ (go to Status Finder).

Key Personnel Key personnel are Contractor personnel in positions that the Government considers to be essential to the performance of this Task Order. Before replacing any individual designated as Key by the Government, the Contractor must notify the Contracting Officer (KO) no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes must possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor must not replace Key Contractor personnel without approval from the Contracting Officer. Vacant Key Personnel positions shall be filled within 60-days.

The following Contractor personnel are designated as Key for this requirement. Note: The Government may designate additional or different Contractor personnel as Key at the time of individual task order awards.

· Task Order Project Manager/Lead The Contractor shall provide an organizational chart, as a graphical means of displaying the reporting relationships of the designated key personnel in relation to all other Contractor personnel, to primary Government management and administrative personnel along with their proposal and updated as personnel change. Include lines of communication to on-site Contractor key personnel as well as corporate senior management and administration. The Contractor management staff may be split out to cover the various locations where contract staff are located. The name(s) of Key Personnel, and the name(s) of any alternate(s) who shall act for the Contractor in the absence of Key Personnel, shall be provided to the Government as part of the Contractor's proposal. During any absence of Key Personnel, only one alternate shall have full authority to act for the Contractor on all matters relating to work performed under this contract. Key Personnel and all designated alternates shall be able to read, write, speak, and understand English.

Task Order Project Manager/Lead The Task Order PM/Lead for operations and technical oversight shall be responsible for the day-to-day Task Order operations of the contracted functions at all locations covered by the Task Order, and shall be the single point of contact for the COR. The Task Order Lead shall be responsible for leading the functional areas with a focus on the technical aspects to meet customer requirements. The Task Order Lead will be responsible for ensuring that all services and deliverables as described in the PWS are met for the contracted functions. The Task Order Lead shall have strong project management skills in addition to interpersonal, writing and presentation skills. He/she must be dedicated to working full-time on this contract.

This position will be focused on scheduling personnel, staffing levels, assigning, and prioritizing work within the team, coordination and submission of travel and training requests, quality control within the team, and providing appropriate measurement criteria on a daily, weekly, monthly, quarterly, and annual basis. This position is responsible for coordinating all aspects of onboarding and departing contractor personnel, including coordinating with the Command/Division Security Office and Property Control Officer. The Task Order Lead will be responsible for overseeing the proper operation of Task Order resources including but not limited to the tools used to support the contracted functions. The Task Order Lead will be responsible for making continuous improvement recommendations to the COR on the operation of the contracted functions.

The Task Order Lead must be available to the COR via telephone between the hours of 0800 and 1600 EST (UTC -5), Monday through Friday, excluding Federal holidays, and must respond to a request for discussion or resolution of technical problems within 2 hours of notification. The Contractor shall provide notification to the KO and COR five (5) calendar days prior to any scheduled absence of the Task Order Lead.

The Task Order Lead must have 4 years of equivalent work experience, with direct project management experience in an IT/Service Management environment. It is also required that the Task Order Lead be certified at or above Information Assurance Manager (IAM) Level II. The Task Order Lead shall have demonstrated direct hands-on experience in the areas of cybersecurity, information assurance, and project management. The Task Order Lead reports to the Program Manager of the Contract and the government representative for each functional area.

Coverage The contractor shall provide supervision during the hours of 0800 to 1600 Monday through Friday, excluding Federal holidays and those periods when the facility is closed by direction of the Commanding Officer. The contractor shall provide recall phone numbers for the Task Order Lead, to be utilized during non-business hours, or in the absence of the Task Order Lead, an alternate who shall have the authority to represent the Task Order Lead. The Contractor shall also provide recall phone number(s) for the Duty Analyst for incident response to be utilized during non-business hours. All the above-mentioned numbers will be held on the Emergency Operations Center – West (EOC-West) Recall Bill.

Continuity of Support The Contractor must ensure that the contractually required level of support for this requirement is maintained at all times. The Contractor must ensure that all contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor must provide e-mail notification to the Contracting Officer’s Representative (COR) at least five (5) business days prior to employee absence. Otherwise, the Contractor must provide a fully qualified replacement.

Employee Identification

(a) Contractor employees visiting Government facilities must wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level, and badge expiration date. Visiting Contractor employees must comply with all Government escort rules and requirements. All Contractor employees must identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.

(b) Contractor employees working on-site at Government facilities must wear a government issued identification badge that is displayed in plain view above the waist at all times. All Contractor employees must identify themselves as Contractors when their status is not readily apparent (in meetings, when answering Government telephones, in e-mail messages, etc.) and ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.

Employee Conduct Contractor’s employees must comply with all applicable Government regulations, policies, and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor must ensure Contractor employees present a professional appearance at all times and that their conduct must not reflect discredit on the United States or the Department of Homeland Security. The Task Order Lead must ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.

Removing Employees for Misconduct or Security Reasons The Government may, at its sole discretion (via the Contracting Officer), direct the Contractor to remove any Contractor employee from the Task Order or DHS facilities for misconduct or security reasons. Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The COR will provide the Contractor with a written explanation to support any request to remove an employee.

Contractor Training The Contractor shall provide adequately trained personnel and shall be responsible to ensure that necessary professional certifications are kept up to date in relevant areas. The Government will not allow costs nor reimburse costs associated with the Contractor training employees in an effort to attain and/or maintain minimum personnel qualifications reasonably expected for their labor category and skill set.

Training includes classroom, online, and other professional development courses, as well as attendance at conferences, seminars, workshops, or symposiums.

The Contractor is responsible for all costs associated with training of personnel to maintain proficiency in the tools and technologies currently employed by the Government. This includes course/event registration, training materials and supplies, travel costs (airfare, per-diem (hotel and meals), and so forth) and any other costs incurred as a result of sending contractor personnel to training. There will be no direct charges for any of these training costs.

In instances where the Government mandates a change in technology, the Government Contracting Officer may approve the direct charge of training (including all associated travel costs as described above). All such requests should be initiated by the COR and must be approved in writing by the Contracting Officer prior to execution of the training event.

The preceding paragraphs define the Government’s position on reimbursement of training costs. However, at the Government’s discretion, training and travel costs may be approved by the COR and Contracting Officer. These instances would be rare exceptions, reviewed on a case-by-case basis, and will only be approved when there is clear benefit to the Government. If disapproved, this does not relieve the Contractor of fulfilling the requirements as defined in the previous paragraphs.

The Contractor shall require its employees to take any required Coast Guard security training upon initiation of employment and any required annual security training. Mandated desktop Government security training should be completed during normal working hours and is permissible to be a direct charge. The Contractor is responsible for monitoring and recording the completion of all training and ensuring that personnel are trained to conform to the requirements of DoD 8570.01-M.

Contract Administration

0. Contract Type Firm Fixed Price (FFP) Labor, and Time and Materials (T&M) for Other Direct Costs (ODCs) incidental to services performed and for any Travel in support of this Task Order.

Personal Services The Government shall neither supervise Contractor employees nor control the method by which the Contractor performs the required work under this task order. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual Contractor employees. It shall be the responsibility of the Contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the Contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor's responsibility to notify the COR and/or Contracting Officer immediately.

Period of Performance The period of performance for this Task Order will be 60 months broken down into a base period with four option periods as follows:

Table 6 - Performance Period

Performance Period
Dates of Performance Period
Phase-In
March 1, 2024 – March 31, 2024
Base Period
April 1, 2024 – March 31, 2025
Option Period 1
April 1, 2025 – March 31, 2026
Option Period 2
April 1, 2026 – March 31, 2027
Option Period 3
April 1, 2027 – March 31, 2028
Option Period 4
April 1, 2028 – February 28, 2029

Places of Performance The Contractor must provide on-site contract support which could additionally include travel to other facilities and vessels (air and sea) both CONUS and OCONUS. Physical locations include but are not limited to the following sites:

· USCG Headquarters, 2703 Martin Luther King Jr. Ave, SE, Washington DC

· USCG C5ISC, 7323 Telegraph Rd, Alexandria, VA

· USCG C5ISC, 4000 Coast Guard Blvd, Portsmouth, VA

· USCG C5ISC, 408 Coast Guard Drive, Kearneysville, WV

· USCG Aviation Logistics Center (ALC), 1664 Weeksville Rd, Elizabeth City, NC Hours of Operation Contractor employees must generally perform all work between the hours of 0600 and 1800 ET, Monday through Friday (except Federal holidays). Core working hours are 0900 – 1500. During core working hours, all Contractor personnel are required to be at work. During normal hours of operation, lunch break shall be taken between the hours of 1100 – 1300. The Contractor shall ensure that all Contractor personnel conform to core working hours and shall provide a means of accountability for personnel time and attendance to the Government periodically as requested.

After Hours Access Access badges for all C5ISC employees will allow access to their workspaces during normal hours of operation. After hours is defined as 1800 – 0600 Monday through Friday and from 1800 Friday to 0600 Monday. After-hours access will be authorized to C5ISC employees upon a request from: military personnel, Government civilian employees, or senior contract managers.

Routine Tele-Work Contract staff may work remotely up to full-time. Tele-workers may be required to participate in office ‘hoteling’ when on-site instead of having dedicated office space. They must be on-site for any meetings or events at the site to which they are assigned that requires their presence; at no additional cost to the Government for travel. Some work, by its sensitive nature or technological limitation must be performed on-site, i.e., work classified as SECRET, on/off boarding of personnel, training, and so forth. Coverage and continuity prescribed in Sections 3.3 and 3.4 must be maintained. The Contractor must submit their telework policy for COR review and Contracting Officer approval.

Travel Contractor travel may be required to support this requirement. All travel required by the Government outside the local commuting area(s) will be reimbursed to the Contractor in accordance with Federal Acquisition Regulations. Reimbursement for travel costs under the travel cost CLIN will not include any indirect costs or labor hours. All labor must be reflected under the appropriate labor hours CLIN. A minimum of seven (7) working days in advance of each travel event, the Contractor must obtain a COR-approved travel request (electronic mail is acceptable) for all reimbursable travel. The travel request must include the trip’s objective/purpose and an estimated expense outline.

Trip Reports Within five (5) working days following the completion of approved travel, a trip report must be submitted to the COR. Each trip report must contain a summary of work performed, accomplishments, and an expense report for each traveler.

Contracting Points of Contact Table 7 - Government Contracting Management Points of Contact

Title
Name
Phone Number
Email Address
Contracting Officer
TBD
Contract Specialist
TBD
Contracting Officer’s Representative (COR)
Richard (Rick) Peat
(304) 283-0973
Richard.T.Peat@uscg.mil
Alternate COR
TBD
Technical Monitor
Alexandria TBD
Technical Monitor
Kearneysville TBD
Technical Monitor
Portsmouth TBD

Inspection and Acceptance The COR for the Task Order is responsible for inspection and acceptance of all services, incoming shipments, and documentation.

Post Award Conference The Contractor shall attend a Post Award Conference with the Contracting Officer and the COR no later than fifteen (15) business days after the date of award. The purpose of the Post Award Conference is to discuss task order objectives and review the Contractor’s Phase-In Plan. The Contractor will be notified of the exact time and location of the conference not later than (NLT) five (5) business days prior to the scheduled date of the conference. The Post Award Conference will be held at the Government’s C5ISC Kearneysville facility, located at 408 Coast Guard Drive, Kearneysville, WV, or via video-teleconference.

The Contractor shall provide a draft Phase-In Plan for Government review and comment five (5) business days prior to the conference. The Government will provide comments on the plan at the conference. The Contractor shall provide the final version of the Phase-In Plan within five (5) business days after the Post Award Conference Meeting.

Phase In The Contractor shall enable a smooth transition between the incumbent and the new contractor for this PWS to ensure minimum disruption of vital Government operations. The Contractor must, therefore, possess a thorough understanding of current operations and demonstrate skills in each area required in this PWS to provide immediate, high quality performance.

The Contractor shall provide a Phase-In Plan that includes, but is not limited to:

· Overview of the Contractor’s transition team and Organization

· Transition strategy

· Transition risk register

· Communication plan

· Schedule for transition/phase-in tasks.

Phase Out A smooth transition between contractors is required to ensure minimum disruption to vital Government business. The contractor shall prepare and submit a Phase-Out Plan 60 days prior to the final option period completion for Government review and approval and shall include:

· Copies of all standard operating procedures and OV-6Cs.

· A strategy to Phase Out with minimal interruptions to the existing systems.

The contractor shall submit a certification to the contracting officer that the Government Issued Badges, Identification Cards, and Passes have been accounted for all employees and subcontractor employees.

Project Management Plan The Contractor shall provide a draft Project Management Plan (PMP) no later than 15 business days after Task Order award for Government review and comment. The PMP shall consist of the Contractor’s control policies and procedures in accordance with standard industry best practices as indicated in Section 1.8.1. The PMP, at a minimum, shall include the following:

· Cost and Schedule Management

· Deliverables/Milestone Management

· Resource Management

· Risk and Issue Management

· Communication Management

· Configuration and Change Management

· Procurement Management

· Quality Management

· Project Monitoring and Reporting

· Service Delivery Management

· Service Integration and Transition The Contractor shall provide a final Project Management Plan to the COR not later than 10 calendar days after Government…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .