SOO - PCI Advisory Consultant 7 Feb 2025.docx
DOCX document 602 KB Posted
- Attached to
- Payment Card Industry Data Security Standard (PCI DSS) Advisory Consultant Federal contract opportunity
- Solicitation number
- Not on record
About this file
This is a Statement of Objectives (SOO) for a Payment Card Industry Data Security Standard (PCI DSS) Advisory Consultant at the Air Force Services Center (AFSVC) in San Antonio, TX. The SOO outlines requirements for consulting services to help AFSVC achieve PCI DSS compliance across approximately 104 worldwide locations processing over 13 million annual credit card transactions through 2,200+ point-of-sale systems.
The contractor must provide both business advisory and PCI DSS compliance consulting services, with key deliverables including business process evaluation, POS system assessment, risk identification, compliance verification, and strategic planning guidance. The period of performance shall not exceed three years. Contractor qualifications include at least five years of experience establishing enterprise systems, Qualified Security Assessor (QSA) certification preferred, and expertise in current PCI DSS standards. Responses to this sources sought notice are due by 4:00 PM CST on February 13, 2025, with questions to be answered by February 21, 2025. The opportunity is currently in pre-solicitation phase for market research purposes only.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 1 Verizon Gap Analysis.pdf | ||
| Q and A PCI DSS Consultant.pdf | ||
| SOO - PCI Advisory Consultant 7 Feb 2025.pdf | ||
| SOO - PCI Advisory Consultant 7 Feb 2025.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1
FA5000‐XX-X-XXXX
STATEMENT OF OBJECTIVES (SOO)
FOR
Air Force Services Payment Card Industry Data Security Standard (PCI DSS) Advisory Consultant
AT
Air Force Services Center (AFSVC), Port San Antonio, TX
Table of Contents
| SECTION I | 6 | |
| 1.4 Scope | 6 | |
| SECTION II | 7 | |
| 2.0 | PROBLEM STATEMENT | 7 |
| 2.1 Objective(s) | 8 | |
| 2.2 Final Outcome | 8 | |
| SECTION III | 9 | |
| 3.0 | DELIVERABLES AND ACCEPTANCE CRITERIA | 9 |
| 3.1 Deliverables: | 9 | |
| 3.2 Acceptance Criteria | 12 | |
| SECTION IV | 12 | |
| 4.0 | TERMS OF THE CONTRACT, STAKEHOLDER (collaborating offices) | 12 |
| 4.1 Timeline | 13 | |
| 4.2 Contractor Qualifications. | 13 | |
| 4.3 Stakeholders (Collaborating Offices). | 13 | |
| SECTION V | 14 | |
| 5.0 | CONTRACT ADMINISTRATION | 14 |
| 5.1 Reporting. | 14 | |
| 5.2 Schedule. | 14 | |
| 5.3 Resource Calendar | 15 | |
| 5.4 Meetings | 15 | |
| 5.5 Weekly Status Meetings | 15 | |
| 5.6 Documentation. | 15 | |
| SECTION VI | 15 | |
| 6.0 | GENERAL INFORMATION | 15 |
| 6.1 Contracting Officer’s Representative (COR) Responsibilities. | 15 | |
| 6.2 Place of Performance | 16 | |
| 6.3 Government Furnished Equipment (GFE) & Personnel | 16 | |
| 6.4 Travel | 17 | |
| 6.5 Identify Known or Possible Conflicts of Interest | 17 | |
| 6.6 Security and Training Requirements | 17 | |
| 6.7 Security Clearances | 19 | |
| 6.8 Privacy Act | 19 | |
| 6.9 Cyber Security | 19 | |
| 6.10 Security Education, Training and Awareness (SETA) | 19 | |
| 6.11 Data Stewardship and Governance | 19 | |
| SECTION VII | 20 | |
| 7.0 | APPENDIX | 20 |
| 7.1 DEFINITIONS & ABBREVIATIONS | 20 | |
| 7.3 Sample Weekly Status Reports or as agreed upon by COR | 22 | |
| 7.4 Sample Contract Progress Report | 24 | |
| 7.5 NAFI Observed Holidays | 25 |
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 General. The Air Force Materiel Command’s Air Force Services Center (AFSVC), headquartered at Joint Base San Antonio-Lackland, Texas, provides critical support to military personnel and their families through Department of the Air Force Nonappropriated Fund Instrumentalities (DAF NAFI) across enterprise Services programs, including food, fitness, childcare, lodging, and recreation. AFSVC is responsible for developing programs, managing support functions, and responding to high-level inquiries. Merchant card processing is vital to AFSVC’s operations, accounting for 90% of its transaction revenue. However, current merchant processing practices are not fully compliant with Payment Card Industry Data Security Standard (PCI DSS), posing risk to the security of Department of Defense connected consumer payment card data.
1.2 Background.
1.2.1 The AFSVC merchant card processing operations are currently non-compliant with the PCI DSS for a Level 1 Merchant. The compliance effort encompasses a comprehensive review of networks, hardware, software, policies, and procedures associated with merchant card processing.
1.2.2 This lack of compliance poses a significant risk to Department of Defense (DoD) connected consumer payment card data and jeopardizes the continuity of essential card services for mission execution. Addressing these vulnerabilities is critical not only for regulatory adherence, but also for safeguarding sensitive information and ensuring the operational integrity of the business unit. Effective program management and strategic oversight are essential to implement the necessary changes to achieve full compliance and enhance overall security.
1.3 Volumetrics:
· Estimated 104 worldwide locations
· 2200+ lines of business
· 13M+ annual credit card transactions
· Unknown number of payment channels
· Unknown number of disparate network cardholder data environments and payment application configurations across the estimated 104 locations
1.4 Scope.
1.4.1 AFSVC is seeking contractor consultation in two areas:
1.4.1.1 PCI DSS compliance consultant to provide advisory analysis and PCI scoping of all DAF NAFI payment channels and cardholder data environments across the estimated 104 subordinate locations worldwide. Intent is to identify applicable PCI DSS compliance requirements and guidance in developing an expedited path forward.
1.4.1.2 Business advisory expert to provide consulting services aimed at maturing and/or developing end-to-end business systems and processes related to merchant processing. The consultant will identify improvement opportunities and assess the efforts required to reach and sustain PCI DSS compliance across DAF NAFI enterprise business unit systems, point-of-sale (POS) hardware, software, and network infrastructures. The engagement will ensure a comprehensive understanding of compliance needs and advise on the development of strategic and tactical plans to ensure AFSVC PCI DSS compliance objectives are met. Additionally, the consultant will evaluate and address training gaps, delivering a recommended training strategy with facilitation support, as needed.
1.4.1.3 Specific milestone deliverables will be part of the Contractor Statement of Objectives (SOO). A cadence of status reports and meetings with AFSVC's PCI Cell members will be established to ensure ongoing alignment and transparency throughout.
SECTION II
2.0 PROBLEM STATEMENT
The AFSVC Merchant card processing is not PCI DSS compliant across the DAF NAFI enterprise for people, processes, and technology. Currently, there are 2200+ disparate POS systems in operation, along with gaps in network infrastructure and business processes, leading to fragmented efforts to achieve PCI DSS compliance.
AFSVC is seeking a consulting company to provide AFSVC assistance in creating and developing robust business processes for merchant processing affecting PCI DSS compliance. Additionally, AFSVC is pursuing advisory support to implement an effective enterprise PCI compliance program for an estimated 104 geographically separated locations operating multiple lines of business (i.e., hospitality, food and beverage, entertainment, etc.).
2.1 Objective(s).
To secure expert guidance and insights on industry best practices to support AFSVC in achieving and maintaining compliance with the Payment PCI DSS. This initiative will focus on a strategic, business process, and sustainment approach across disparate POS, hardware and software, network infrastructures, and business processes and procedures related to merchant card servicing activities. The goal is to enhance security, mitigate risks, and ensure a robust and comprehensive approach toward compliance while optimizing business processes.
Final Outcome.
The consultant will deliver strategies, tools, and frameworks to help AFSVC in developing an effective and robust enterprise PCI compliance program to achieve and maintain PCI DSS compliance, mitigate risks associated with payment card processing, and enhance overall business system processes affecting cybersecurity. The consultant will provide ongoing support throughout the implementation phase and ensure readiness for subsequent assessments.
The deliverable will also include a comprehensive suite of integrated tools and strategies that ensure full PCI DSS compliance while improving the overall security and efficiency of payment processing across business operations and geographically separated locations, protecting payment card data and streamlining related processes.
Strategic pillars (not an exhaustive list):
2.1.1 Strategic planning guidance, including steps required to achieve compliance, timelines, resource allocation, risk management strategies and sustainment plans.
2.1.2 QSA Assessment readiness. Advisor will provide actionable recommendations to guide AFSVC in the development and implementation of security measures, documentation, and reporting to ensure readiness for formal PCI DSS compliance assessments.
2.1.3 Commercial expertise to recommend turnkey compliance solution suite, including tools, technologies, and processes that ensure adherence to PCI DSS standards. Examples of the industry expertise requested:
· Process and procedure codification
· Merchant ID management and adjudication
· Integrated technology and data solutions with approved purchase list
· Enterprise data management strategy
· Governance framework
· Asset management process
· Lifecycle management
· Sustainment & growth strategies
· Recommendations or solutions for enterprise PCI compliance tools and services designed for geographically separated networks and technology in scope for PCI DSS compliance
· Recommendations or solutions for PCI DSS compliance oversight, to include templates for PCI DSS enterprise policies, operating procedures, and forms
2.1.4 Return on Investment (ROI) assessment of cost savings tied to utilizing a consolidated system recommended versus current state multiple disparate solutions.
2.1.5 Ability to implement recommended solutions and provide a cost and timeframe estimate based on the assessments and research conducted.
SECTION III
3.0 DELIVERABLES AND ACCEPTANCE CRITERIA
The Contractor shall provide deliverable(s) in a format mutually agreed upon by the Government and the Contractor. The following deliverables are not expected to change. Due date intervals are not expected to change but actual dates may be revised depending upon actual contract start date. The Contractor shall provide a list of deliverables based upon the proposed technical solution. This section will be updated based on the proposed technical solution selected by the Government.
Contractors must provide the below for each of the deliverables for the bid process:
· Experience on implementation of each deliverable with Points of Contact (POC)
· Number, type and amount of time for FTE to implement each deliverable
· Labor Rates of each person assigned to each deliverable
· Implementation timeline for each deliverable, if concurrent with another deliverable, please annotate
· Full implementation timeline of all deliverables combined w/ Total cost of project
· Summary of experience with DoD and Federal entities, to include agency, scope of work, and outcome description whether successful or unsuccessful
3.1 Deliverables:
3.1.1 Business Advisor Deliverables
3.1.1.1 Business Process Evaluation: Deliver an evaluation of business processes involving cardholder data to ensure alignment with PCI DSS standards, focusing on secure data handling, processing, storage, and disposal.
3.1.1.2 POS System Assessment: Deliver an evaluation of POS systems for the multiple lines of business (i.e., hospitality, food and beverage, entertainment, etc.), assessment of POS system business processes affecting PCI DSS compliance, identify merchant processing efficiencies, and provide recommendations to improve POS business processes across the DAF NAFI enterprise.
3.1.1.3 Risk Identification and Mitigation: Identify potential risks within the business processes and POS systems, including vulnerabilities related to payment data security. Provide actionable recommendations to mitigate these risks and strengthen overall security.
3.1.1.4 Compliance Verification: Ensure that all POS systems and related business processes meet the required PCI DSS controls, including physical security measures, secure data transmission, encryption, and user authentication.
3.1.1.5 Incident Response and Contingency Planning: Assess existing incident response procedures related to POS systems and business processes, ensuring they are aligned with PCI DSS standards and include clear roles, responsibilities, and communication protocols for handling data breaches or security incidents.
3.1.1.6 Training and Awareness: Evaluate the effectiveness of employee training programs related to PCI DSS compliance, ensuring that personnel involved in handling payment transactions are adequately trained on security protocols and best practices.
3.1.1.7 Documentation and Reporting: Review and assess documentation of PCI DSS compliance for business processes and POS systems, ensuring that appropriate evidence is available to demonstrate adherence to standards and facilitate audits.
3.1.1.8 Ongoing Monitoring and Maintenance: Advise on mechanisms for continuous monitoring and ongoing maintenance of both POS systems and related business processes to ensure sustained PCI DSS compliance.
3.1.1.9 Strategic planning guidance, including steps required to achieve compliance, timelines, resource allocation, risk management strategies and sustainment plans.
3.1.1.10 Payment Processing Analysis: Reviewing a merchant's current payment processing setup to identify areas for improvement, such as reducing fees, improving security, or increasing efficiency.
3.1.1.11 Merchant Account Setup: Helping merchants set up new merchant accounts or reorganizing existing ones to ensure compliance with industry regulations and optimal payment processing rates.
3.1.1.12 Payment Gateway Integration: Assisting with the integration of payment gateways, such as online payment portals, mobile payment apps, or point-of-sale (POS) systems, to facilitate seamless transactions.
3.1.1.13 Fee Optimization: Analyzing and negotiating payment processing fees to ensure merchants receive the best possible rates, reducing their overall costs and increasing profitability.
3.1.1.14 Payment Technology Implementation: Recommending and implementing payment technologies, such as contactless payments, mobile wallets, or cryptocurrency payments, to enhance the customer experience and stay competitive.
3.1.1.15 Customer Support: Providing ongoing support and training to merchants on payment processing best practices, troubleshooting, and issue resolution.
3.1.1.16 Industry Insights and Trends: Staying up-to-date with the latest payment industry trends, technologies, and regulatory changes to provide informed guidance and recommendations to merchants.
3.1.2 QSA PCI Advisory Support Deliverables:
3.1.2.1 PCI Scoping: Identifying areas where AFSVC’s current security controls and processes do not meet the requirements of the PCI DSS. The Contractor shall provide a PCI QSA advisory analysis and scoping of all AFSVC payment channels across an estimated 104 subordinate locations worldwide for multiple payment channels to identify applicable PCI DSS controls according to the most up-to-date PCI DSS Requirements and Testing Procedures. The scoping effort includes identifying all AFSVC and subordinate locations’ business payment channels and applicable cardholder data environments. The contractor shall include the following services.
3.1.2.1.1 The Contractor shall provide PCI discovery assessment support that meets the most current PCI Security Standards Council (PCI SSC) PCI compliance requirements.
3.1.2.1.2 The Contractor shall provide an inventory of detailed payment channels at AFSVC at the estimated 104 locations worldwide.
3.1.2.1.3 The Contractor shall identify current level of compliance at each DAF installation worldwide and at AFSVC with the most current PCI DSS regulations. The Contractor shall identify and prioritize the AFSVC key work areas that must be addressed and provide recommend remediations and solutions.
3.1.2.2 Risk Assessment: Evaluating the organization's risk posture and identifying potential vulnerabilities that could impact the security of cardholder data. The Contractor shall identify current level of compliance at each AF installation worldwide and at AFSVC with the most current PCI DSS regulations.
3.1.2.3 Compliance Planning: Developing a plan to address identified gaps and risks, and to achieve compliance with the PCI DSS.
3.1.2.4 Security Control Implementation and Remediation: Assisting with the implementation and remediation of non-compliant security controls and processes to meet the requirements of the PCI DSS. The Contractor shall identify and prioritize the AFSVC key work areas that must be addressed and provide solutions and manpower resources to complete remediation requirements within8 months.
3.1.2.5 Vulnerability Management: Identifying and addressing vulnerabilities in the organization's systems and networks that could impact the security of cardholder data.
3.1.2.6 Penetration Testing: Simulating attacks on systems and networks that handle cardholder data.
3.1.2.7 Audit Preparation: Assisting with preparation for PCI DSS audits, including reviewing audit reports and providing guidance on addressing any findings or deficiencies.
3.1.2.8 The Contractor shall present a written report to the COR within 21 days of completing the PCI DSS Discovery which contains:
3.1.2.8.1 A short and graphical executive summary aimed at senior management. The executive summary contains a statement of the project scope, non-technical descriptions of vulnerabilities, along with those findings’ inherent business risk. It also provides a comparison of the AFSVC’s security posture with that of other organizations of similar size and business objectives.
3.1.2.8.2 A narrative body, which details major events that have occurred during the project. The narrative body of the report restates the scope and approach and presents the engagement results for a non-technical audience. In addition, the contractor shall provide the broad next steps AFSVC can take to address PCI compliance deficiencies from an enterprise, architectural, and solutions implementation perspective.
3.2 Acceptance Criteria.
3.2.1 All deliverables, technical services, and products must be functionally tested to ensure compatibility with Air Force systems. They must be approved by the Contracting Officer’s Representative (COR) and designated representatives from AFSVC before acceptance and must be capable of obtaining a viable assessment and authorization.
3.2.1.1 Weekly/Monthly status reports/meetings to the government with the following information:
3.2.1.1.1 Contract funds expended during the reporting period (monthly).
3.2.1.1.2 Description of the activities of the past week/month.
3.2.1.1.3 Any issues or problems affecting project progress along with proposed resolution (weekly/monthly).
3.2.1.1.4 Schedule of activities planned for next reporting period (weekly/monthly).
3.2.1.1.5 Acceptance criteria for metrics, trip reports, and technical presentation requirements are as specified in the Deliverables section.
3.2.1.1.6 Quarterly Total Quality Management (TQM) reports.
3.2.1.1.7 Documented recommendations, system configurations/set-up and guidance identified/discussed in meetings or collaborative sessions.
3.2.2 All data or work products generated in the support and development effort shall be property of AFSVC.
3.2.3 Acceptance or rejection of named deliverables will occur within 14 business days after receipt by the COR.
SECTION IV
4.0 TERMS OF THE CONTRACT, STAKEHOLDER (collaborating offices)
4.1 Timeline. The customer intends to award one contract. Period of Performance: Shall not exceed three (3) years.
4.2 Contractor Qualifications.
AFSVC is seeking an Advisory Consultant with Commercial PCI DSS expertise and a track record of successfully guiding companies in achieving PCI DSS Compliance utilizing industry best practices. They will have worked within the hospitality and entertainment industry, driving compliance success for businesses with a dispersed business model and multiple POS systems, lacking a central network infrastructure. Federal government or DoD experience is valued.
At a minimum, interested parties must possess a strong understanding of the PCI DSS standard and be trained Qualified Security Assessors (QSA). They should have experience in PCI assessment preparation, identifying and implementing integrated off-the-shelf solutions, and strategic planning across multiple unique global business units. Additionally, candidates must have at least five years of experience in establishing enterprise systems, including the development of policies, procedures, processes, and responsibilities. QSA staffing arm, preferred.
4.2.1 The Contractor shall provide the experience necessary to complete the task outlined in the SOO. The Contractor shall utilize established policies, standards, and sound management principles in the performance of the SOO requirements and deliverables. The Contractor’s personnel, at a minimum, shall have the following experience as required:
4.2.1.1 Must be well-versed in the most up-to-date PCI DSS version and all key requirements.
4.2.1.2 Must have knowledge of off-the-shelf and integrated (cloud) network solutions that work best within specific industries.
4.2.1.3 5+ years of experience in standing up an enterprise system, including the policies, procedures, processes, and RACI.
4.2.1.4 PCI Self-assessment questionnaire (SAQ) or Report on Compliance (ROC) knowledge and experience with a Level 1 Merchant.
4.2.1.5 Certified Qualified Security Assessor preferred for at least one personnel.
4.3 Stakeholders (Collaborating Offices).
4.3.1 Lead organization for this effort: AFSVC/PCI Cell
4.3.2 Collaborating organizations: AFSVC/CC, AFSVC/VI, AFSVC/VP, AFSVC/VF, AFSVC/VT, AFSVC/VM, AFSVC/VB and others as needed (i.e., impacted Major Commands/Field Commands).
SECTION V
5.0 CONTRACT ADMINISTRATION
5.1 Reporting.
5.1.1 The Contractor shall provide weekly status reports (See 7.4. Weekly Status Report) and/or other updates as needed to provide the Contracting Officer’s Representative (COR) with the current status of the tasks completed for the week. The status report must identify action and/or items completed by individual contract resources, planned task/activities, risks and status updates.
5.1.2 Provide a list of planned task/activities for the week in the status report. Subsequent status reports shall include completed percentage of completion of the previous week’s planned task/activities and a new list of planned activities for the following week.
5.1.3 The Contractor shall provide a monthly contract progress report, with their monthly invoice, that shall be consistent with the submitted and COR approved weekly status reports. (See 8.5. Contract Progress Report)
5.2 Schedule.
5.2.1 A detailed contract plan that shall outline major tasks such as discovery/ramp up time, and environment configuration, validation/review, development and required support activities. The Contractor shall deliver in accordance with (IAW) the approved schedule.
5.2.1.1 The Contractor shall provide, at the scheduled kick-off meeting, a detailed contract plan (i.e. Gantt Chart) outlining major tasks such as discovery/ramp up time, environment configuration, validation/review, development and required support activities.
5.2.1.2 The Contractor shall provide, thirty (30) days, after the kick-off meeting, a realistic detailed project plan outlining the tasks and subtasks for both the AF and the Contractor based on the deliverables and requirements listed in the SOO. Once the submitted plan/schedule is approved by the COR, the Contractor shall deliver IAW the approved schedule.
5.2.1.3 All forecasted or unexpected delays to the schedule must be reported to the COR within one (1) business day of discovery. The Contractor shall provide reason for delay and proposed resolutions to the COR no later than 1600 CST the same day.
5.2.1.4 If a delay occurs and is the result of Contractor error, the Contractor shall submit a revised schedule to the COR for review and approval within two workdays of recognition of delay.
5.3 Resource Calendar.
5.3.1 At a minimum of 21 business days in advance, the Contractor shall provide the COR, in writing, the projected days the Contractor’s resources will be unavailable. This information is necessary to help plan for critical support task/activities like patching, system upgrades but not limited to these activities. This will allow AFSVC to coordinate and plan for resource availability.
5.4 Meetings.
5.4.1 Kick-Off Meeting. A kick-off meeting will be held after contract award on a date and time agreeable by both parties. The meeting will be held at the Place of Performance. The Contractor shall designate a primary Point of Contact (POC) for the contract for the kick-off meeting.
5.5 Weekly Status Meetings.
5.5.1 The day and time of the weekly status meeting shall be determined by the COR and the Contractor after contract award. Meetings will be held virtually unless otherwise coordinated between COR & Contractor.
5.5.2 Recommendations identified or discussed in meetings or collaborative sessions shall be provided in writing within two (2) business days of initial recommendations. Contractor shall provide any recommendations, alternate options, scenarios or configurations in writing in MS Word format or COR approved format.
5.6 Documentation. All recommendations, configurations, and guidance must be provided in writing in MS Word format or COR approved format.
5.6.1 Provide guidance and instruction for existing documentation provided such as setup and configuration documents.
5.6.2 Provide guidance and instruction to develop system documentation provided such as setup and configuration documents.
SECTION VI
6.0 GENERAL INFORMATION
6.1 Contracting Officer’s Representative (COR) Responsibilities.
6.1.1 The Contracting Officer (CO) will designate an individual as the Contracting Officer’s Representative (COR).
6.1.2 The COR is responsible for monitoring the performance of work under this contract. In no event, shall any understanding, agreement, modification, change order, or other matter deviating from the terms of this contract be effective or binding upon the contracting customer unless formalized by proper contractual documents executed by the CO prior to the completion of the contract.
6.1.3 This designation shall remain in effect throughout the life of the contract, unless terminated sooner in writing by the CO or due to reassignment. Primary responsibilities of the COR may include, but are not limited to, the following:
6.1.3.1 The COR is responsible for performing post award administrative functions necessary to ensure performance of services required by this contract. If the COR believes performance by the Contractor has not met the level required by the contract, the problem shall be referred to the CO for resolution.
6.1.3.2 The COR shall maintain and approve the list of all products required to be delivered by the Contractor as well as when the product is delivered and its acceptability status, this includes the project schedule.
6.1.3.3 The COR will maintain a record of all contract deliverables and a copy of the email message or cover letter used to deliver the deliverables.
6.1.3.4 The COR will work with CO to ensure the following responsibilities are adhered to:
6.1.3.4.1 Verify that the Contractor performs the technical requirements of the contract in accordance with the terms, conditions, and specifications therein. Specific emphasis shall be placed on the quality provisions, for both adherences to the contract provisions and to the Contractor's own quality control program.
6.1.3.4.2 Perform acceptance for the customer of services performed under this contract.
6.1.3.4.3 Communication will be the key to success of this effort. Maintain liaison and direct communications with the Contractor and the CO. Written communications with the Contractor and other documents pertaining to the contract shall be signed by the COR and a copy shall be furnished to the CO.
6.1.3.4.4 Monitor the Contractor's performance, notify the Contractor of deficiencies observed and direct appropriate action to effect correction. Record and report to the CO incidents of faulty or non-conforming work, delays, or problems.
6.2 Place of Performance
6.2.1 3515 South General McMullen Bldg. 1, San Antonio, TX 78236-9854. Remote work is authorized for a majority of the contract, however in office work may be required as recommended by COR & Contractor.
6.3 Government Furnished Equipment (GFE) & Personnel
6.3.1 AFSVC will provide GFE-owned PCs to do the required work and to access the applications.
6.4 Travel
6.4.1 Contractor shall include in their price for the assigned team to travel to San Antonio, TX for the kick-off meeting, to pick-up & turn-in Government Furnished Laptops (turn-in will include a Contract Closeout Meeting). All other travel must be mutually coordinated & reimbursed by AFSVC in accordance with the Federal Travel Regulations (FTR see Clause 29 of the SEC I – NAF Standard Clauses).
6.5 Identify Known or Possible Conflicts of Interest
6.5.1 Contractor will have access to the Department of Air Force execution data from financial systems, contracts, and pricing data at the CLIN level. Contractor shall identify any known or possible conflicts of interests to
6.6 Security and Training Requirements
6.6.1 Highest level: UNCLASSIFIED. The preponderance of work will be at the unclassified level.
6.6.2 Building Access. Unescorted access to the AFSVC/Building 1 is approved and shall be coordinated through the COR and AFSVC’s Security Manager. Any other locations shall be approved on a case-by-case basis
6.6.3 Training. Cyber Awareness Challenge Training, Controlled Unclassified Information (CUI) Training (one-time) and Privileged User Cybersecurity Responsibilities (if server access required). All Government required training shall be provided at no cost by the Government.
6.7 Security Clearances
6.7.1 The Contractor shall ensure that personnel requiring access to AFSVC information systems, or its data have the proper and current cybersecurity certifications as determined by AFSVC cybersecurity teams to perform cybersecurity functions in accordance with DoDM 8140.03, Cyberspace Workforce Qualification and Management Program located at https://dodcio.defense.gov/Portals/0/Documents/Library/DoDM-8140-03.pdf.
6.7.2 The Contractor shall meet the following contract/security clearance requirements, including:
6.7.2.1 The Contractor shall safeguard and comply with the rules and regulations issued under DoDI 5200.02, DoD Personnel Security Program (PSP), 21 Mar 2014; AFMAN 16-1405, Air Force Personnel Security Program; AFM 33-152, User Responsibilities and Guidance For Information Systems; DoDD 8500.01 security, 14 Mar 2014; AFI 17-130, Air Force Cybersecurity Program Management; and DoDM 8140.03, Information Assurance Workforce Improvement Program requirements and respective updates to the listed rules and regulations. The Contractor shall follow the DoD Privacy Office guidelines for submittal of Information Assurance Technical (IAT) security clearances
6.7.2.2 Contractor personnel shall not be assigned to perform duties within IAT-II or IAT-III, and or requiring “Limited Privileged Access” such as system or database administration rights, to any NAFI application or network.
6.7.3 Tier 1 requests are initiated using the Standard Form (SF) 85. Tier 3 requests are initiated using the Standard Form (SF) 86 and are submitted to the installation Information Protection Office through the Unit Security Manager. The initiation of the Tier 1 or Tier 3 shall include the submission of all required information and verified through the Department of Defense (DoD) Defense Information System for Security (DISS) database. The Contractor shall comply with the rules and regulations under DMDC Trusted Associate Sponsor System Overview Guide, Version 5.7, Sept 2018 and associated updates; all CAC holders must, at minimum, have an initiated a favorable completion of an FBI fingerprint check, or a DoD determined equivalent investigation. The NAFI may grant a waiver to allow the Contractor to start work after submitting all required information, passes a successful FBI fingerprint check and DISS.
6.7.4 All Contractor personnel requiring system access must be adjudicated with a Favorable determination in DISS.
6.7.5 The Contractor shall ensure all FISMA, NIST, Department of Defense (DoD), Air Force certification, accreditation/assessment and authorization, data protection and security standards are met and renewed on a continuing basis throughout the contract period.
6.7.6 Information Systems (IS)/Networks Physical Security. The Contractor shall employ physical security safeguards for IS/Networks and applications involved in processing or storage of U.S. customer data to prevent the unauthorized access, disclosure, modification, destruction, use, etc. at any time, and to otherwise protect the confidentiality and ensure use conforms with DoD regulations. In addition, the Contractor shall support a physical security audit performed by the U.S. customer of the Contractor's internal information management infrastructure that is used in development. The Contractor shall correct any deficiencies identified by the customer of the Contractor's physical security posture. The Contractor shall be required to follow all requirements in applicable DoD Information Assurance directives and policies.
6.7.7 All Contractor personnel requiring system access must respond to the AFSVC Security Manager’s inquiries within three business days (excluding federal holidays), not to exceed 72 hours. If Contractor personnel does not respond to the AFSVC Security Manager’s inquires within three business days, their non-action on this matter provides grounds for termination.
6.8 Privacy Act
6.8.1 The Contractor shall safeguard and comply with the agency rules and regulations issued under Public Law 110-53 (42 U.S.C. § 2000ee-1) Section 803; Air Force Policy Directive (AFPD) 33-3, Information Management; Department of Defense Directive (DoDD) 5400.11, Department of Defense Privacy Program; Department of Defense Regulation (DoDR) 5400.11-R, Department of Defense Privacy Program; Department of Defense Instruction (DoDI) 5400.16, DoD Privacy Impact Assessment (PIA) Guidance; DoDI 1000.30, Reduction of Social Security Number (SSN) Use Within DoD; and DoDI 1000.29, and DoD Civil Liberties Program, Privacy Act of 1974, 5 U.S.C. § 552a, E-Government Act of 2002, 44 U.S.C. §3601, Safeguarding and Responding to Personally Identifiable Information (PII) breaches, Reduction of Social Security Number (SSN) and AFI 33-332, AF Privacy and Civil Liberties Program and associated updates to the agency rules and regulations. Penalties are applied for the misuse or unauthorized disclosure of PII. The Act (5 U.S.C. 552a) provides for civil remedies for injured parties, including actual damages, attorney fees, and litigation costs.
6.9 Cyber Security
6.9.1 Where applicable, the Contractor shall ensure all components in the contractor solution, any applications that process, store, and/or transmit credit card information/cardholder data are thoroughly assessed and meet the most current version of the Payment Card Industry Data Security Standards (PCI DSS). The solution must meet all PCI DSS compliance requirements identified by the Payment Card Industry Security Standards Council. The Contractor shall provide to the NAFI sufficient evidence of PCI DSS Compliance certification regarding the solution’s PCI DSS compliance status.
6.10 Security Education, Training and Awareness (SETA) and Operations Security (OPSEC) Training
6.10.1 Contractor employees will complete initial and annual refresher SETA and OPSEC training within five days of on-boarding for initial, and annually as dictated by the unit security manager.
6.11 Data Stewardship and Governance
6.11.1 The NAFI will have unlimited rights to all technical data unless the Contractor takes specific actions and includes prescribed legends in the proposal, contract, and/or data products to limit or restrict such NAFI rights for particular identified items. “Technical data” refers to recorded information and includes (but is not limited to) research and engineering data and drawings, specifications, standards, process sheets, manuals, technical reports and computer software documentation. It does not include computer software or financial, cost/pricing or other contract and grant administrative data but does include any developed intellectual property not specific to the data.
6.11.2 Data and information generated during this agreement is owned by the NAFI. Data must be physically separated from the data of other users, on separate drives or computers, and appropriate firewalls be established to prevent other users from accessing NAFI data.
6.11.3 Should the NAFI elect to not execute option years or at the end of the contract period, whichever is sooner, data must at all times be promptly accessible until converted to the new system with no additional separation fee.
SECTION VII
7.0 APPENDIX
7.1 DEFINITIONS & ABBREVIATIONS
Contracting Officer (CO). The duly appointed Government agent authorized to award or administer contracts. The contracting officer is the only person authorized to contractually obligate the Government.
Contracting Officer’s Representative (COR). The COR is responsible for monitoring the performance of work under this contract. In no event, shall any understanding, agreement, modification, change order, or other matter deviating from the terms of this contract be effective or binding upon the contracting customer unless formalized by proper contractual documents executed by the CO prior to the completion of the contract.
Statement of Objective (SOO). A formal contracting document used to describe the goals and objectives expected from soliciting Contractor work.
7.2 ACRONYMS
AFSVC - Air Force Services Center CC – Commander CO – Contracting Officer CONUS – Continental United States COR – Contracting Officer Representative DAF – Department of the Air Force DISS - Defense Information System for Security (legacy JPAS) DOD - Department of Defense FTE – Full Time Equivalents GFE – Government Furnished Equipment NAFI - Nonappropriated Fund Instrumentality OCONUS – Outside the Continental United States PCI DSS – Payment Card Industry Data Security Standards PCI SSC – Payment Card Industry Security Standards Council POC - Point of Contact POS – Point of Sale QSA – Qualified Security Assessor RASCI - Responsible, Accountable, Supporting, Consulted and Informed ROC – Report on Compliance ROI – Return on Investment SAQ – Self Assessment Questionnaire SOO – Statement of Objectives TQM – Total Quality Management VF – Financial Management & Comptroller Directorate VBL - Lodging VI- Installation Support Division VM - Mission Operations Directorate VP – NAF Procurement Directorate VT – Business Information Technology Systems Directorate
7.3 Sample Weekly Status Reports or as agreed upon by COR
7.4 Sample Contract Progress Report
7.5 NAFI Observed Holidays
Holiday
*New Year's Day: January 1st
Martin Luther King Jr. Day: Third Monday in January
Presidents' Day: Third Monday in February
Memorial Day: Last Monday in May
*Juneteenth National Independence Day: June 19th
*Independence Day: July 4th
Labor Day: First Monday in September
Columbus Day: Second Monday in October
*Veterans Day: November 11th
Thanksgiving Day: Fourth Thursday in November
*Christmas Day: December 25th
*(observed on the following Monday if holiday falls on a Sunday, or on the preceding Friday if the holiday falls on a Saturday)
Statement of Objectives 7 Feb 2025 image1.png image2.png
File details come from the government source that posted it. Updated .