SOW_RFQ.pdf
PDF 216 KB Posted
- Attached to
- Cybersecurity Programs and Initiatives Support Services Federal contract opportunity
- Solicitation number
- 1333ND24QNB770501
About this file
This document is a Statement of Work (SOW) for providing technical coordination, outreach, and communications engagement support services to implement and improve NIST's cybersecurity and privacy program, and NIST's focus on critical and emerging technologies.
The SOW outlines specific requirements for the contractor, including: developing and assisting NIST with a comprehensive strategic planning and stakeholder engagement approach; preparing and reviewing NIST documents such as public statements, website text, and speeches; attending NIST workshops and conferences; and providing recommendations to improve program effectiveness, efficiency, and stakeholder engagement. The period of performance is a base period of 6 months from August 2024 to February 2025, with an optional 6-month extension. The work is primarily to be performed offsite, with the contractor required to have a NIST campus site badge. The contractor must meet minimum qualifications including at least 10 years of experience in cybersecurity standards, metrics, and cryptography. The SOW is in support of the related federal contract opportunity for "Cybersecurity Programs and Initiatives Support Services" solicited by the Department of Commerce National Institute of Standards and Technology.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 0001.pdf | ||
| CSS 1333ND24QNB770501_FINAL.pdf | ||
| CSS 1333ND24QNB770501.pdf | ||
| CSS 1333ND24QNB770501.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
TITLE: Technical Coordination, Outreach, and Communications Engagement Support for NIST Cybersecurity Programs and Initiatives
I. BACKGROUND INFORMATION
The need for cybersecurity standards and best practices that address interoperability, usability and privacy continues to be critical for the Nation. NIST continues to align its resources to enable greater development and application of practical, innovative security technologies and methodologies that enhance our ability to address current and future computer and information security challenges, and especially in the context of critical and emerging technologies. Active communication and engagement with diverse stakeholders helps to build trust and is crucial for the broad adoption of our cybersecurity standards and guidelines.
The task of assuring this private and public sector involvement requires NIST to develop and carry out a plan that creates dramatically greater awareness of its collaborative cybersecurity programs and initiatives, vigorously and methodically enlisting key representatives at both the executive and technical levels of private and public organizations. It is essential to coordinate this effort with the many parts of the private sector, including all parts of the Nation’s digital economy. NIST needs continued support to implement and improve its comprehensive, thoughtful, and robust stakeholder engagement plan to guide its efforts.
II. SCOPE OF WORK
a. OBJECTIVES/PURPOSE The objective of this tasking is to provide technical coordination, outreach, and communications engagement support to implement and improve NIST’s cybersecurity and privacy program, and NIST’s focus on critical and emerging technologies.
b. GENERAL:
The scope of this task is to support NIST cybersecurity, privacy, and critical and emerging technology programs and initiatives, including continued implementation of its responsibilities under relevant laws and Executive Orders. The contractor shall provide communications and stakeholder engagement support services, explained in greater detail in section C. Specific Requirements.
c. SPECIFIC REQUIREMENTS:
The Contractor shall complete the following tasks:
Task 1. Strategic Planning and Stakeholder Engagement Approach
The contractor shall develop and assist NIST in carrying out a comprehensive approach to strategic planning and stakeholder engagement that will raise awareness and improve the effectiveness of cybersecurity, privacy and critical and emerging technologies programs and initiatives. In order to accomplish this task – working with NIST staff and partners in other departments and agencies – the contractor shall:
1.1 Prepare five (5) NIST draft documents in support of cybersecurity, privacy, and critical and emerging technologies communications and stakeholder outreach program. Draft documents shall include public statements, website text, emails to stakeholders, talking points, welcome letters, and speeches on cybersecurity programs and initiatives led by NIST.
1.2 Review and edit ten (10) NIST documents in support of cybersecurity, privacy, and critical and emerging technologies communications and stakeholder outreach program. NIST documents shall include public statements, website text, emails to stakeholders, press releases, and speeches.
1.3 Prepare one (1) report with recommendations for actions by NIST to improve program effectiveness, efficiency, and stakeholder engagement.
1.4 Attend two (2) NIST cybersecurity-, privacy-, and critical and emerging technologies-related workshops and conferences. Support development and review of post-workshop summary documents and status reports. Virtual attendance is anticipated.
Task 2. Project Planning and Reporting
2.1 Kick-off Meeting. The contractor shall attend a kick-off meeting, on-site at NIST’s Gaithersburg Campus not later than ten (10) business days after award of the task order. The kick-off meeting shall be utilized to introduce contractor key personnel, review all contract requirements and deliverables, and discuss the contractor’s proposed approach. The contractor’s key personnel shall be present at the kickoff meeting.
III. PERIOD OF PERFORMANCE
The base period of performance is from 08/15/2024 to 02/14/2025 (six months). The optional period of performance is from 02/15/2025 to 08/14/2025.
IV. PLACE OF PERFORMANCE
The primary place of performance shall be offsite. It is estimated that the contractor shall participate in meetings virtually. A NIST campus site badge is required. Offsite work shall be coordinated with the Subject Matter Expert (SME) prior to execution and incur no additional cost to the government. NIST anticipates part time effort to accomplish this task order. NIST anticipates part time effort to accomplish this task order. NIST estimates 520 hours is needed for the base period, and 520 hours is needed for the option period.
V. GOVERNMENT FURNISHED PROPERTY
The Government will furnish a laptop necessary to conduct work remotely. All property, data and information provided by the Government in the performance of this task remains the property of the Government and shall be surrendered to the government upon completion or termination of this requirement. Likewise, all deliverables generated under this requirement remain the property of the Government.
VI. DELIVERABLES
Task Description Media Quantity Due Date
Task 2.1 Attend kick-off meeting at NIST. Attend meeting
1 Not more than 10 business days after task order award.
Base Period Task 1.1
Draft NIST documents, including public statements, website text, emails to stakeholders, speeches.
MS
Word
5 No later than five (5) days after notification by the SME.
Base Period Task 1.2
Review and edit NIST documents, including public statements, website
MS
Word
10 No later than five (5) days after notification by the SME.
text, emails to stakeholders, press releases, speeches.
Base Period Task 1.3
Prepare report with recommendations for actions by NIST to improve program effectiveness, efficiency, and stakeholder engagement.
MS
Word
1 No later than twenty (20) days after notification by the SME.
Base Period Task 1.4
Attend or facilitate cybersecurity-, privacy-, and AI-related workshops and conferences.
MS
Word
2 No later than thirty (30) days after notification by the SME.
Option Period Task
1.1
Draft NIST documents, including public statements, website text, emails to stakeholders, speeches.
MS
Word
5 No later than five (5) days after notification by the SME.
Option Period Task
1.2
Review and edit NIST documents, including public statements, website text, emails to stakeholders, press releases, speeches.
MS
Word
10 No later than five (5) days after notification by the SME.
Option Period Task
1.3
Prepare report with recommendations for actions by NIST to improve program effectiveness, efficiency, and stakeholder engagement.
MS
Word
1 No later than twenty (20) days after notification by the SME.
Option Period Task
1.4
Attend or facilitate cybersecurity-, privacy-, and AI-related workshops and conferences.
MS
Word
2 No later than thirty (30) days after notification by the SME.
All deliverables shall be provided to the SME. All materials shall be submitted to NIST via electronic submission.
VII. PERFORMANCE REQUIREMENT SUMMARY
Desired Output Required Service
Performance Standard Monitoring Method Narrative materials for final NIST review prior to public distribution and/or internal deliberations for NIST program planning.
Draft NIST documents, including public statements, website text, emails to stakeholders, speeches.
Generated materials are technically correct, free of spelling, grammar, and typographical errors, and reflective of input received from stakeholders on NIST programmatic priorities.
Documentation will be reviewed by the SME to ensure compliance with performance standards.
Narrative materials for final NIST review prior to public distribution and/or internal deliberations for NIST program planning.
Review, comment on, and edit NIST documents, including public statements, website text, emails to stakeholders, press releases, speeches.
Generated materials are technically correct, free of spelling, grammar, and typographical errors, and reflective of input received from stakeholders on NIST programmatic priorities.
Documentation will be reviewed by the SME to ensure compliance with performance standards.
Desired Output Required Service
Performance Standard Monitoring Method Narrative materials for final NIST review prior to public distribution and/or internal deliberations for NIST program planning.
Prepare report with recommendations for actions by NIST to improve program effectiveness, efficiency, and stakeholder engagement.
Generated materials are technically correct, free of spelling, grammar, and typographical errors, and reflective of input received from stakeholders on NIST programmatic priorities.
Documentation will be reviewed by the SME to ensure compliance with performance standards.
Substantive contributions (and/or resulting recommendations to NIST) are made to the workshop and conference discussions.
Attend or facilitate cybersecurity-, privacy-, and AI-related workshops and conferences.
Contributions to preparatory materials and post-event updates and recommendations are technically correct, free of spelling, grammar, and typographical errors, and reflective of input received from stakeholders on NIST programmatic priorities.
Contributions will be reviewed by the SME to ensure compliance with performance standards.
The SME will provide comments on each deliverable within 14 calendar days from receipt of a given deliverable. The Contractor shall make any needed changes to the reports within 14 calendar days from receipt of electronic or written comments from the SME. The SME will provide written notification when a deliverable is accepted.
VIII. TRAVEL
No travel is anticipated for this task order.
IX. CONTRACTOR’S MINIMUM QUALIFICATIONS
Level IV (Scientist/Engineer): Experienced specialized scientist or engineer with a minimum of 10 years’ experience in the related field OR, a demonstrated equivalent combination of education, training and experience can be used to meet the minimum qualifications. Contractor Key Personnel shall meet the following minimum qualifications for each of the respective required key personnel positions. The titles of the labor categories given below are not mandatory. They are simply examples of titles suitable to the type of work to be performed by the respective key personnel positions:
• Cybersecurity Subject Matter Expert – Possess at least 10 years’ experience with cybersecurity standards and metrics and cryptography, and the ability to formulate and communicate a technical message with diverse stakeholders across US industry on cybersecurity standards and practices.
X. ATTACHMENTS
• Executive Order 13636 - https://www.federalregister.gov/articles/2013/02/19/2013-
03915/improving-critical-infrastructure-cybersecurity
• Executive Order 13800 - https://www.whitehouse.gov/the-press-office/2017/05/11/presidential-executive-order-strengthening-cybersecurity-federal
• Executive Order 14028 - https://www.federalregister.gov/documents/2021/05/17/2021-
10460/improving-the-nations-cybersecurity https://www.federalregister.gov/articles/2013/02/19/2013-03915/improving-critical-infrastructure-cybersecurity https://www.federalregister.gov/articles/2013/02/19/2013-03915/improving-critical-infrastructure-cybersecurity https://www.whitehouse.gov/the-press-office/2017/05/11/presidential-executive-order-strengthening-cybersecurity-federal https://www.whitehouse.gov/the-press-office/2017/05/11/presidential-executive-order-strengthening-cybersecurity-federal https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity
• Executive Order on Artificial Intelligence - https://www.whitehouse.gov/presidential-actions/executive-order-maintaining-american-leadership-artificial-intelligence/
• Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence - https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/
• Cybersecurity Enhancement Act of 2014 - https://www.congress.gov/bill/113th-congress/senate-bill/1353/text
• NIST Cybersecurity website – https://www.nist.gov/cybersecurity https://www.whitehouse.gov/presidential-actions/executive-order-maintaining-american-leadership-artificial-intelligence/ https://www.whitehouse.gov/presidential-actions/executive-order-maintaining-american-leadership-artificial-intelligence/ https://www.congress.gov/bill/113th-congress/senate-bill/1353/text https://www.congress.gov/bill/113th-congress/senate-bill/1353/text https://www.nist.gov/cybersecurity
| I. BACKGROUND INFORMATION |
| II. SCOPE OF WORK |
| a. OBJECTIVES/PURPOSE |
| The objective of this tasking is to provide technical coordination, outreach, and communications engagement support to implement and improve NIST’s cybersecurity and privacy program, and NIST’s focus on critical and emerging technologies. |
| b. GENERAL: |
| The scope of this task is to support NIST cybersecurity, privacy, and critical and emerging technology programs and initiatives, including continued implementation of its responsibilities under relevant laws and Executive Orders. The contractor shall... |
| c. SPECIFIC REQUIREMENTS: |
| III. PERIOD OF PERFORMANCE |
| The base period of performance is from 08/15/2024 to 02/14/2025 (six months). The optional period of performance is from 02/15/2025 to 08/14/2025. |
| IV. PLACE OF PERFORMANCE |
| The primary place of performance shall be offsite. It is estimated that the contractor shall participate in meetings virtually. A NIST campus site badge is required. Offsite work shall be coordinated with the Subject Matter Expert (SME) prior to execu... |
| V. GOVERNMENT FURNISHED PROPERTY |
| VI. DELIVERABLES |
| VII. PERFORMANCE REQUIREMENT SUMMARY |
| VIII. TRAVEL |
| IX. CONTRACTOR’S MINIMUM QUALIFICATIONS |
| X. ATTACHMENTS |
File details come from the government source that posted it. Updated .