About this file

This document contains a draft performance work statement (PWS) and a related federal contract opportunity notice for training services to support the Navy Cyber Defense Operations Command's Cyber Network Defense Continuous Learning Program.

The draft PWS outlines requirements for providing high-quality training through a SANS voucher program to maintain cyber network defense proficiency and meet continuing education requirements for certifications. Key training areas include DoD 8140.01m baseline and advanced certifications in cybersecurity, incident response, and digital forensics. The period of performance is from October 2022 through September 2023.

The related sources sought notice seeks information from qualified vendors to provide the training services described in the draft PWS on a commercial item basis. Responses are requested by April 11, 2022 and must include company information, past performance, technical expertise, and ability to serve as prime or subcontractor. The potential award would be for the period of September 2022 through September 2023 to support training at the Navy Cyber Defense Operations Command located in Suffolk, Virginia.

View the file

Other files for this federal contract opportunity

Other files attached to Training Services to Support Navy Cyber Defense Operations Command Cyber Network Defense Continuous Learning Program, newest first.
File Type Posted
_RFI_PWS.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

1.0 BACKGROUND

The Navy Cyber Defense Operations Command (NCDOC) Cybersecurity Workforce Program Manager (CSWF-PM) and the N7 Training Department are responsible for administering, managing and facilitating the NCDOC Cybersecurity Workforce Qualification Program (CSWF-QP). The CWSF-QP is NCDOC’s development program designed to develop a highly skilled Department of the Navy Cybersecurity Workforce (CSWF) program. A common understanding of the cyber security concepts, principles and application for each Department of Defense (DOD) category, level and functions to enhance protection and availability of NCDOC information, information systems and networks. The CWSF-QP establishes baseline skills among personnel performing Cyberspace IT or Cybersecurity Workforce (Cyber IT/CSWF), Certification and Accreditation (C&A) and other Information Assurance (IA) related functions within the NCDOC domain.

The NCDOC requires that all NCDOC personnel meet or exceed the DOD Information Assurance Workforce (IAWF) requirements outlined in the DoD 8140.01mM. All commercial certification under the DoD 8140.01M require attaining and reporting Continuing Professional Education (CPE) credits; this is accomplished by attending a minimum of 20 hours of CPEs annually in the Cyber field according to the mandate of the SECNAV M-5239.2. The training CPEs reported to meet these certification maintenance requirements can for the most part be met by normal Cyber proficiency training.

NCDOC’s Training Department is responsible for providing the means for training for its personnel’s professional development through a Continuous Learning Program (CLP) that incorporates this type of course availability into its approved annual training budget and plan. The Cyber Network Defense (CND) is defined as the actions taken to protect, monitor, analyze, detect and respond to unauthorized activity within DOD information systems and computer networks. Under the DOD 8140.01m, there are five CND Incident Responder certifications, the Global Information Assurance Certification (GIAC) Systems and Network Auditor (GSNA), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Forensic Examiner (GCFE), and Certified Ethical Hacker (CEH). The GSNA, (GIAC Systems and Network Auditor) the GCIH ( GIAC Certified Incident Handler), the GCIA (GIAC Certified Intrusion Analyst) and GCFE (GIAC Certified Forensic Examiner) certification courses are to be offered exclusively by SANS,and available through the a training account Voucher program for on-line and classroom training. In addition, the GCFA (GIAC Certified Forensics Analyst), GCED (GIAC Certified Enterprise Defender (GCED)) and GCFE are the additional certifications with preparation courses to be offered by SANSthat also qualify personnel as Incident Handlers to receive, operate, and maintain the NCDOC’s digital forensics kits for obtaining evidence-quality digital forensics images in the field.

2.0 OBJECTIVE

The objective of this requirement is to provide high quality training services in support of NCDOC’s CND CLP program that will maintain personnel CND proficiency, and provide the necessary technical CPEs for advanced certification maintenance.

3.0 SCOPE

As a part of the Cyber Workplace Improvement Program CWIP and CND CLP requirements, the SANS Voucher program and the courses it offersrequired are a vital component to the program curriculum as it hones significant IA &CND competency skills and qualifies personnel as effective members of the NCDOC CND-SP Team. The SANS Voucher programtraining program should provide the adult training mode and scheduling flexibility best suited to the adult training needs of the participating personnel, with course work to be the course by work be taken online with instructor, online on-demand, or in a standard classroom setting when travel can be afforded by NCDOCaccommodated by the command. As learning is

Commented [PEACUNNV(1]: What is “normal Cyber proficiency training”? And if that is the case then why does our customer want to sole source to SANS on this? I don’t expect you to know the answer, let’s ask our customer about this statement and impact to the acquisition strategy they want us to support.

Commented [PEACUNNV(2]: I don’t understand the purpose of this statement in the PWS. Is it necessary? Again a question for the customer. I am of the opinion we don’t need to give this kind of information to industry or our vendors. The PWS is meant to tell them their responsibilities in supporting what the Government needs from them…

Commented [PEACUNNV(3]: This was a capital one place and lower here, what the correct format?

Commented [MKCNFNC224R3]: Lowercase, amended above.

Commented [MKCNFNC226R5]: Amended.

Commented [PEACUNNV(5]: What does this acronym stand for?

Formatted: Not Highlight

Commented [PEACUNNV(7]: What is this?

Commented [MKCNFNC228R7]: Amended.

Commented [PEACUNNV(9]: I don’t understand this part of the statement. Should this be re-worded?

Commented [MKCNFNC2210R9]: Amended.

an essential attribute of high-performing individuals and organizations, it is therefore, a critical concept in performance excellence. The course curriculum should all be ANSI and DoD 8140.01m certified courses and built on the Office of Personnel Management (OPM)’s National Initiative for Cybersecurity Education (NICE) Cyber Core Competencies (CCCs): (1) Computer Network Defense, (2 Technology Awareness, (3) Vulnerabilities Assessment, (4) Infrastructure Design, (5) Information Assurance, and (6) Information Systems/Network Security.

4.0 DEFINITIONS

ANSI – American National Standards Institute CCC- Cyber Core Competency CND – Cyber Network Defense CPE – Continuing Professional Education Credit GIG – Global Information Grid ISSM – Information Systems Security Manager CSWFPM – Cybersecurity Workforce Program Manager CWIP - Cyber Workforce Improvement Program NCDOC – Navy Cyber Defense Operations Command NICE – National Initiative on Cyber Education

5.0 SPECIFIC PERFORMANCE REQUIREMENTS AND TASKS

5.1 – Training NCDOC Voucher Account. The SANS Voucher Credittraining Account for NCDOC should be continuously updated to reflect the training funds invested and be managed by the NCDOC N7 Training Department.

5.1.1 Program Core Curriculum

Core Curriculum should at the minimum consist of the following courses of interest:

A. DoD 8140.01m Baseline ISSM Certification Courses

a. SEC 301 Intro to INFOSEC to obtain a GISF certification

b. SEC 401 Security Essentials to obtain a GSEC certification

c. MGT 512 Security Leadership Essentials for Managers to obtain a GSLC

d. MGT 414 +S Training Program for the CISSP Certification Exam

e. SEC501: Advanced Security Essentials – Enterprise Defender to obtain a GCED certification

AB. DoD 8140.01m Advanced CND ISSM Certification Courses

a. SEC 504 Hacking Techniques and Incident Handling to obtain a GCIH

b. SEC 503 Intrusion Detection In-Depth to obtain a GCIA certification

c. AUD507 Auditing Networks, Perimeters, Systems to obtain a GSNA

C. Advanced Incident Handling and Digital Forensics Courses

a. FOR 408 Computer Forensic Investigations – Windows to obtain a GCFE

b. FOR 508 Advanced Computer Forensic Analysis to obtain a GCFA

c. SEC 560 Net Pen Testing and Ethical Hacking to obtain a GPEN

Additional courses shall be available as validated via the N7 Training Department based on individual requirement and the operational necessity.

6.0 DELIVERABLES

1) Training AccountVouchers

Formatted: Indent: Left: 0.5", First line: 0"

a) The Contractor shall provide on-line secure account registrations for NCDOC Training Department to access and request class vouchers from the training SANS Voucher Credit aAccount.

b) The Contractor shall inform NCDOC Training Department of courses available and any changes under to Voucher system and any changes or updates to the curriculums of courses available.

c) The Contractor shall provide the courses to approved Voucher participants in the training modality selected: Online Virtual Classroom, Online On-Demand, or traditional scheduled classroom at a conference setting.

2) Command and Control – The contractor shall provide an automated means for controlling courses offered, and limiting the approval of course vouchers requested by NCDOC to the designated Training Department person and his/her designated Alternate.

3) The Contractor wishall inform the Training Department of Courses Requested, Completed, and Exam Status.

7.0 TRAVEL

There will be no travel requirements for this PWS.

8.0 SECURITY

Performance of this task is UNCLASSIFIED. An interaction with the training account Voucher Program is limited to accessing a secure commercial website through a User account based on the NCDOC Training Department e-mail account.

9.0 PERIOD OF PERFORMANCE

The Period of Performance for the base year is 01 October 2022 through 30 September 2023; all training will be initiated during this period of performance.

10.0 WIDE AREA WORKFLOW

Invoices for vouchers under this SOW shall be submitted electronically through Wide Area Workflow (WAWF) in accordance with the WAWF Routing Table listed in the contract. The WAWF website is https://wawf.eb.mil.

11.0 ENTERPRISE-WIDE CONTRACTOR MANPOWER REPORTING APPLICATION

(ECMRA)

The contractor shall report contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the Naval Cyber Defense Operations Command via a secure data collection site. Contracted services excluded from reporting are based on Product Service Codes (PSCs). The excluded PSCs are:

(1) W, Lease/Rental of Equipment;

(2) X, Lease/Rental of Facilities;

(3) Y, Construction of Structures and Facilities;

(4) D, Automatic Data Processing and Telecommunications, IT and Telecom- Telecommunications Transmission (D304) and Internet (D322) ONLY;

(5) S, Utilities ONLY;

(6) V, Freight and Shipping ONLY.

The contractor is required to completely fill in all required data fields using the following web address https://doncmra.nmci.navy.mil.

File details come from the government source that posted it. Updated .