About this file

This statement of work defines system security engineering services required for sustainment of the NP2000 Propeller System and Electronic Propeller Control System on DoD aircraft operated by the United States Air Force. Key requirements include conducting engineering to study, generate, document, test, integrate and deliver artifacts aligned with the program protection implementation plan. Additional work involves reviewing and analyzing cybersecurity requirements for compliance with statutory and regulatory mandates, and providing risk assessment and mitigation related to vulnerabilities in services, design, supply chain compromise, and cyber or advanced persistent threats throughout the system lifecycle. The government will sole source this one-year basic contract without options to Hamilton Sundstrand Corporation under authority that only one responsible source can satisfy agency requirements.

View the file

Other files for this federal contract opportunity

Other files attached to System Security Engineering Services for Electronic Propeller Control System and NP2000 8-Bladed Propeller, newest first.
File Type Posted
12 - FA8504-20-R-0007 AMEND 1.pdf PDF
A023 DI-MISC-80508B Traceability Matrix.pdf PDF
FA8504-20-R-0007.pdf PDF
A019 DI-MISC-80508B Plan of Action and Milestones.pdf PDF
A030 DI-IPSC-81433A Software Requirements Specification.pdf PDF
A025 DI-MGMT-81763 Cust. Micro-Elect Dev Source Protection Plan.pdf PDF
A027 DI-QCIC-80125B GIDEP Alert_Safety Alert Report.pdf PDF
A005 DI-NDTI-81284 Test and Evaluation Program Plan.pdf PDF
A028 DI-MISC-80508B Security Assessment Plan.pdf PDF
A034 DI-IPSC-81435A Software Design Description.pdf PDF
A010 DI-SESS-81248B Interface Control Document.pdf PDF
A021 DI-MISC-80508B FMEA.pdf PDF
A014 DI-MISC-80508B Risk Assessment Report.pdf PDF
A008 DI-IPSC-81440A Software Test Report.pdf PDF
A017 DI-MISC-80508B Security Plan.pdf PDF
A031 DI-IPSC-81441A Software Product Specification.pdf PDF
A036 DI-MGMT-80934C Operations Security (OPSEC) Plan.pdf PDF
A024 DI-MISC-80508B Architect Design Document.pdf PDF
A018 DI-MISC-80508B Security Assessment Report.pdf PDF
A026 DI-MISC-81832 Counterfeit Prevention Plan.pdf PDF
A001 DI-ADMN-81306 PPIP.pdf PDF
A020 DI-MISC-80508B Criticality Analysis.pdf PDF
A012 DI-MGMT-81808 Contractor Risk Management Plan.pdf PDF
A002 DI-SDMP-81493A Program-Unique Specification Document.pdf PDF
A016 DI-MISC-80508B Cybersecurity Plan.pdf PDF
Show all 25

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1 | P a g e FD2060-20-30611/FD2060-20-30952 Rev: Basic Distribution Statement C

STATEMENT OF WORK (SOW)

For

Electronic Propeller Control System (EPCS) and NP2000 8-Bladed Propeller

System Security Engineering (SSE) Services

Collins Aerospace

PR: FD2060-20-30611

PR: FD2060-20-30952

Date: 9 March 2020

Prepared by:

AFLCMC/WLNC

235 Byron Street, Suite 19A

Robins AFB, GA 31098-1670

Procurement Contract Officer:

Erin Taylor, AFLCMC/WLNK

Program Manager:

Lt Jordan Hanlin, 1st Lt, USAF

Phone: (478) 926-3470

DSN: 468-3470

Distribution Statement C: Distribution is authorized to U.S. Government agencies and their Contractors (administrative or operational use; 01-11-27). Other requests for this document shall be referenced to AFLCMC/WLNC, Robins AFB, GA 31098-1670

2 | P a g e

Distribution Statement C

Table of Contents

1.0 SCOPE

1.1 BACKGROUND

2.0 APPLICABLE DOCUMENTS

3.0 PERIOD OF PERFORMANCE

3.1 Place of Performance

4.0 SYSTEM SECURITY ENGINEERING

4.1 Program Protection

4.2 Cybersecurity and Trusted Systems and Networks

4.3 Reserved

4.4 Security Management

APPENDICES

3 | P a g e

Distribution Statement C

1.0 SCOPE

This Statement of Work (SOW) defines the effort required to identify, correct and consolidate the changes into a final government approved deliverable Technical Data Package (TDP) for the EPCS (54H60) and NP2000 systems on the United States Air Force (USAF) C-130H aircraft.

This includes associated program management and support planning requirements.

1.1 BACKGROUND

The NP2000/EPCS program has been initiated to design, develop, produce and deploy a modernized propeller system that replaces the existing Mechanical Valve Housings and Propeller Synchrophaser currently in use on turboprop aircraft. The EPCS was designed to improve propeller reliability and maintainability with primary upgrade benefits for all C-130 aircraft.

This also allows for the future upgrade to the NP2000.

2.0 APPLICABLE DOCUMENTS

See Appendix A – Documents

3.0 PERIOD OF PERFORMANCE

The period of performance for all tasks shall be 395 days After Contract Award (ACA).

3.1 Place of Performance

All required tasks will be performed at the contractors’ facilities.

4.0 SYSTEM SECURITY ENGINEERING

4.1 Program Protection

The contractor shall deliver a Program Protection Implementation Plan (PPIP). The contractor shall integrate the PPIP activities in the Integrated Master Plan (IMP)/Integrated Master Schedule (IMS). The contractor shall derive requirements from the PPIP and put into specification(s), trace, and verify through the Systems Engineering processes. Program Protection includes the following areas: Cybersecurity to include Trusted Systems and Networks (TSN), Cyber Resiliency, and Information Protection. All paragraphs below shall be contained in the PPIP. The government shall be able to participate in all testing.

(CDRL A001, DI-ADMN-81306, PPIP)

(CDRL A002, DI-SDMP-81493A, Program-Unique Specification Document) (CDRL A003, Reserved) (CDRL A004, Reserved) (CDRL A005, DI-NDTI-81284, Test and Evaluation Program Plan (TEPP)) (CDRL A006, Reserved) (CDRL A007, Reserved) (CDRL A008, DI-IPSC-81440A, Software Test Report (STR)) (CDRL A009, Reserved) (CDRL A010, DI-SESS-81248B, Interface Control Document (ICD)) (CDRL A011, Reserved)

4.1.1 The contractor shall perform a Program Protection/System Security Risk Assessment of the requirements per section 1.10 Risk Management of the USAF System Security Engineering

4 | P a g e

Distribution Statement C

Acquisition Guidebook, utilizing the System Security Working Groups. These risks shall be part of the program risks. In addition, the contractor shall provide risk mitigation steps to alieve risks.

(CDRL A012, DI-MGMT-81808, Contractor’s Risk Management Plan) (CDRL A013, Reserved) (CDRL A014, DI-MISC-80508B, Risk Assessment Report)

4.1.2 Reserved

(CDRL A015, Reserved)

4.1.3 Reserved

4.1.4 Reserved

4.2 Cybersecurity and Trusted Systems and Networks

4.2.1 The contractor shall provide the Cybersecurity Plan (to include TSN and Cyber Resiliency) and data to support the development of the Security Plan. The contractor shall provide a Security Assessment Plan, a Security Assessment Report, and a Plan of Action and Milestones (POA&M). The contractor shall ensure the weapons system’s configuration has been baselined and documented to meet the cyber requirements.

(CDRL A016, DI-MISC-80508B , Cybersecurity Plan) (CDRL A017, DI-MISC-80508B , Security Plan) (CDRL A018, DI-MISC-80508B, Security Assessment Report)

(CDRL A019, DI-MISC-80508B, POA&M)

4.2.2 The contractor shall provide the Criticality Analysis for Safety Critical Functions and Mission Critical Functions thread IAW DoDI 5200.44, 5200.47 and 5000.39, Airworthiness Circular AC-17-01, and the USAF Combined Process Guide for CPI and Critical Component (CC) Identification. In addition, the Contractor shall ensure the Failure Modes, Effects Analysis (FMEA) trace to the Criticality Analysis, which are documented in the Failure Modes, Effects, and Criticality Analysis (FMECA). The contractor shall design the system with redundant capability(ies) to reduce and eliminate single point of failure of all safety critical functions and mission critical functions based on risk.

(CDRL A020, DI-MISC-80508B, Criticality Analysis)

(CDRL A021, DI-MISC-80508B, FMEA)

(CDRL A022, Reserved)

4.2.3 Reserved

4.2.4 The contractor shall allocate system security and resiliency requirements to architectural entities and system elements. The contractor shall trace system architecture design to the requirements derived from the agreed to SCTM NIST 800-53R4 controls (SP/SAP) IAW DoDI

8500.01 and DoDI 8510.01 and TSN per DoDI 5200.44, and Resiliency requirements. The contractor shall allocate requirements to the Safety Critical Functions (SCFs) and Mission Critical Functions (MCFs) commensurate with operational risk categorization. The contractor shall utilize the lower level requirements located in attachment 1 of the USAF Systems Security Engineering Acquisition Guidebook, and provide a requirements traceability matrix. The

5 | P a g e

Distribution Statement C contractor shall ensure integration and verification that SCFs and MCFs have the appropriate segregation and diverse redundancy in the architecture to complete the mission (resiliency), see requirement section for more information. In addition, the Architect Design Document shall include an analysis of any other systems’/subsystems’ interconnects/interfaces that are not SCF and MCF. If there are interconnects/interfaces, the Architect Design Document shall ensure the appropriate segregation and diverse redundancy is maintained for the SCF and MCF.

(CDRL A023, DI-MISC-80508B, Traceability Matrix) (CDRL A024, DI-MISC-80508B, Architect Design Document)

4.2.5 The contractor shall ensure all hardware with special emphasis on lowest CCs are from trusted sources and are manufactured by approved personnel as documented in the Security Plan.

The contractor shall develop and implement a Counterfeit Parts Prevention program in compliance DFARS 252.246–7007 Contractor Counterfeit Electronic Part Detection and Avoidance System using SAE AS5553, SAE AS6171, SAE AS6081, and IDEA-STD-1010B or similar practices to prevent the inclusion of counterfeit parts or parts with malicious logic. The contractor shall ensure that no critical components procured are on the section 806 List in the Supplier Performance Risk System (SPRS). The contractor shall develop a Supply Chain Risk Management (SCRM) plan documented in the Security Plan IAW the current version of CNSSD No. 505 and NIST SP 800-160 to mitigate supply chain risk. The contractor shall perform acceptance testing on lowest CCs.

(CDRL A025, DI-MGMT-81763, Customized Microelectronics Devices Source Protection Plan) (CDRL A026, DI-MISC-81832, Counterfeit Prevention Plan) (CDRL A027, DI-QCIC-80125B, Government Industry Data Exchange Program (GIDEP) Alert/Safety Alert Report)

4.2.6 The contractor shall ensure software assurance IAW the current version of Software Assurance Countermeasures in Program Protection Planning IAW table 5.3.3-1 of the Office of Secretary of Defense (OSD) Program Protection Plan (PPP) Outline & Guidance, dated July 2011. The contractor shall provide a Software Development Plan and the source code to complete software assurance independently for all safety critical and functions . In addition, the software development plan shall include an analysis of any other systems that are not SCF and MCF of interconnects. If there are interconnects/interfaces, the software development plan shall ensure the software assurance is maintained for the SCF and MCF.

(CDRL A028, DI-MISC-80508B, Security Assessment Plan) (CDRL A029, Reserved) (CDRL A030, DI-IPSC-81433A, Software Requirements Specification) (CDRL A031, DI-IPSC-81441A, Software Product Specification) (CDRL A032, Reserved) (CDRL A033, Reserved) (CDRL A034, DI-IPSC-81435A, Software Design Description)

4.2.7 Reserved

4.2.8 Reserved

4.2.9 Reserved

6 | P a g e

Distribution Statement C

4.3 Reserved

(CDRL A035, Reserved )

4.4 Security Management

4.4.1 The contractor shall establish and maintain a security program to comply with requirements of the Government-provided Contract Security Classification Specification, DD Form 254, and other security-related contractual requirements as indicated in all Request for Proposal (RFP)/Statement of Work (SOW) documents.

4.4.2 The contractor shall apply Operations Security (OPSEC) in their management of the Program IAW AFI 10-701 Operations Security and the OPSEC Plan and program’s Critical Information List provided by the Government program office.

(CDRL A036, DI-MGMT-80934C, OPSEC Plan)

4.4.3 The contractor shall provide Operations Security (OPSEC), Communications Security (COMSEC) and Cybersecurity (CS) Training as part of its overall training requirements.

OPSEC, COMSEC, and CS Training outline specific actions to protect classified and sensitive unclassified information, activities and operations during the course of the contract.

4.4.4 The contractor shall be compliant to National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 in accordance with DFARS, Clause 252.204-7008.

4.4.5 The contractor will notify the Government Contracting Activity and the Government Security Manager within 48 hours of any incident involving the actual or suspected compromise/loss of classified information to enable the Government to conduct immediate assessment of potential impact pending formal inquiry/investigation. Actual or suspected compromise of Covered Defense Information will be reported IAW DFARS Clause 252.204- 7012.

4.4.6 Reserved

4.4.7 Reserved

(CDRL A037, Reserved)

7 | P a g e

Distribution Statement C

APPENDICES

Appendix A- Documents

PUBLICATION TITLE

DATE OF

PUBLICATION

NIST SP 800-171 Rev. 1 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

December 2016 Includes updates as of 06-07-2018

NIST SP 800-53 Rev. 4 Security and Privacy Controls for Federal Information Systems and Organizations

April 2013 Includes updates as of 01-22-2015

NIST SP 800-160

Systems Security Engineering : Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems

November 2016 Includes updates as of 03-21-2018

DoDI 8500.01 Cybersecurity

14 March 2014 Incorporating Change 1, Effective October 7, 2019

DoDI 5200.44 Protection of Mission Critical Functions to Achieve Trusted Systems and Networks (TSN)

5 November Incorporating Change 3, October 15, 2018

CNSSI 1253

SECURITY CATEGORIZATION AND CONTROL

SELECTION FOR

NATIONAL SECURITY SYSTEMS

27 March 2014

DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT)

12 March 2014 Incorporating Change 2, July 28, 2017

DoDD 8140.01 Cyberspace Workforce Management

August 11, 2015 Incorporating Change 1, July 31, 2017

DoDI 8570.01-M Information Assurance Workforce Improvement Program

19 December Incorporating Change 4 Nov 10, 2015

AFMAN 17-1303 Cybersecurity Workforce Improvement Program 9 August 2019

AFI 17-101

Risk Management Framework (RMF) for Air Force Information Technology (IT)

2 February 2017

8 | P a g e

Distribution Statement C

DFARS

252.239-7001 Information Assurance Contractor Training and Certification

SUBPART 204.73--SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER

INCIDENT REPORTING

252.204-7000 Disclosure of Information.

252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.

252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.

252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.

252.239-7017 Notice of Supply Chain Risk (DEVIATION 2018-O0020).

252.239-7018 Supply Chain Risk (DEVIATION 2018-O0020).

252.246-7007 Contractor Counterfeit Electronic Part Detection and Avoidance System.

252.246-7008 Sources of Electronic Parts.

File details come from the government source that posted it. Updated .