SOW SSE NP2K-EPCS_9Mar2020.pdf
PDF 203 KB Posted
- Attached to
- System Security Engineering Services for Electronic Propeller Control System and NP2000 8-Bladed Propeller Federal contract opportunity
- Solicitation number
- FA8504-20-R-0007
About this file
This statement of work defines system security engineering services required for sustainment of the NP2000 Propeller System and Electronic Propeller Control System on DoD aircraft operated by the United States Air Force. Key requirements include conducting engineering to study, generate, document, test, integrate and deliver artifacts aligned with the program protection implementation plan. Additional work involves reviewing and analyzing cybersecurity requirements for compliance with statutory and regulatory mandates, and providing risk assessment and mitigation related to vulnerabilities in services, design, supply chain compromise, and cyber or advanced persistent threats throughout the system lifecycle. The government will sole source this one-year basic contract without options to Hamilton Sundstrand Corporation under authority that only one responsible source can satisfy agency requirements.
View the file
Other files for this federal contract opportunity
Show all 25
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
1 | P a g e FD2060-20-30611/FD2060-20-30952 Rev: Basic Distribution Statement C
STATEMENT OF WORK (SOW)
For
Electronic Propeller Control System (EPCS) and NP2000 8-Bladed Propeller
System Security Engineering (SSE) Services
Collins Aerospace
PR: FD2060-20-30611
PR: FD2060-20-30952
Date: 9 March 2020
Prepared by:
AFLCMC/WLNC
235 Byron Street, Suite 19A
Robins AFB, GA 31098-1670
Procurement Contract Officer:
Erin Taylor, AFLCMC/WLNK
Program Manager:
Lt Jordan Hanlin, 1st Lt, USAF
Phone: (478) 926-3470
DSN: 468-3470
Distribution Statement C: Distribution is authorized to U.S. Government agencies and their Contractors (administrative or operational use; 01-11-27). Other requests for this document shall be referenced to AFLCMC/WLNC, Robins AFB, GA 31098-1670
2 | P a g e
Distribution Statement C
Table of Contents
1.0 SCOPE
1.1 BACKGROUND
2.0 APPLICABLE DOCUMENTS
3.0 PERIOD OF PERFORMANCE
3.1 Place of Performance
4.0 SYSTEM SECURITY ENGINEERING
4.1 Program Protection
4.2 Cybersecurity and Trusted Systems and Networks
4.3 Reserved
4.4 Security Management
APPENDICES
3 | P a g e
Distribution Statement C
1.0 SCOPE
This Statement of Work (SOW) defines the effort required to identify, correct and consolidate the changes into a final government approved deliverable Technical Data Package (TDP) for the EPCS (54H60) and NP2000 systems on the United States Air Force (USAF) C-130H aircraft.
This includes associated program management and support planning requirements.
1.1 BACKGROUND
The NP2000/EPCS program has been initiated to design, develop, produce and deploy a modernized propeller system that replaces the existing Mechanical Valve Housings and Propeller Synchrophaser currently in use on turboprop aircraft. The EPCS was designed to improve propeller reliability and maintainability with primary upgrade benefits for all C-130 aircraft.
This also allows for the future upgrade to the NP2000.
2.0 APPLICABLE DOCUMENTS
See Appendix A – Documents
3.0 PERIOD OF PERFORMANCE
The period of performance for all tasks shall be 395 days After Contract Award (ACA).
3.1 Place of Performance
All required tasks will be performed at the contractors’ facilities.
4.0 SYSTEM SECURITY ENGINEERING
4.1 Program Protection
The contractor shall deliver a Program Protection Implementation Plan (PPIP). The contractor shall integrate the PPIP activities in the Integrated Master Plan (IMP)/Integrated Master Schedule (IMS). The contractor shall derive requirements from the PPIP and put into specification(s), trace, and verify through the Systems Engineering processes. Program Protection includes the following areas: Cybersecurity to include Trusted Systems and Networks (TSN), Cyber Resiliency, and Information Protection. All paragraphs below shall be contained in the PPIP. The government shall be able to participate in all testing.
(CDRL A001, DI-ADMN-81306, PPIP)
(CDRL A002, DI-SDMP-81493A, Program-Unique Specification Document) (CDRL A003, Reserved) (CDRL A004, Reserved) (CDRL A005, DI-NDTI-81284, Test and Evaluation Program Plan (TEPP)) (CDRL A006, Reserved) (CDRL A007, Reserved) (CDRL A008, DI-IPSC-81440A, Software Test Report (STR)) (CDRL A009, Reserved) (CDRL A010, DI-SESS-81248B, Interface Control Document (ICD)) (CDRL A011, Reserved)
4.1.1 The contractor shall perform a Program Protection/System Security Risk Assessment of the requirements per section 1.10 Risk Management of the USAF System Security Engineering
4 | P a g e
Distribution Statement C
Acquisition Guidebook, utilizing the System Security Working Groups. These risks shall be part of the program risks. In addition, the contractor shall provide risk mitigation steps to alieve risks.
(CDRL A012, DI-MGMT-81808, Contractor’s Risk Management Plan) (CDRL A013, Reserved) (CDRL A014, DI-MISC-80508B, Risk Assessment Report)
4.1.2 Reserved
(CDRL A015, Reserved)
4.1.3 Reserved
4.1.4 Reserved
4.2 Cybersecurity and Trusted Systems and Networks
4.2.1 The contractor shall provide the Cybersecurity Plan (to include TSN and Cyber Resiliency) and data to support the development of the Security Plan. The contractor shall provide a Security Assessment Plan, a Security Assessment Report, and a Plan of Action and Milestones (POA&M). The contractor shall ensure the weapons system’s configuration has been baselined and documented to meet the cyber requirements.
(CDRL A016, DI-MISC-80508B , Cybersecurity Plan) (CDRL A017, DI-MISC-80508B , Security Plan) (CDRL A018, DI-MISC-80508B, Security Assessment Report)
(CDRL A019, DI-MISC-80508B, POA&M)
4.2.2 The contractor shall provide the Criticality Analysis for Safety Critical Functions and Mission Critical Functions thread IAW DoDI 5200.44, 5200.47 and 5000.39, Airworthiness Circular AC-17-01, and the USAF Combined Process Guide for CPI and Critical Component (CC) Identification. In addition, the Contractor shall ensure the Failure Modes, Effects Analysis (FMEA) trace to the Criticality Analysis, which are documented in the Failure Modes, Effects, and Criticality Analysis (FMECA). The contractor shall design the system with redundant capability(ies) to reduce and eliminate single point of failure of all safety critical functions and mission critical functions based on risk.
(CDRL A020, DI-MISC-80508B, Criticality Analysis)
(CDRL A021, DI-MISC-80508B, FMEA)
(CDRL A022, Reserved)
4.2.3 Reserved
4.2.4 The contractor shall allocate system security and resiliency requirements to architectural entities and system elements. The contractor shall trace system architecture design to the requirements derived from the agreed to SCTM NIST 800-53R4 controls (SP/SAP) IAW DoDI
8500.01 and DoDI 8510.01 and TSN per DoDI 5200.44, and Resiliency requirements. The contractor shall allocate requirements to the Safety Critical Functions (SCFs) and Mission Critical Functions (MCFs) commensurate with operational risk categorization. The contractor shall utilize the lower level requirements located in attachment 1 of the USAF Systems Security Engineering Acquisition Guidebook, and provide a requirements traceability matrix. The
5 | P a g e
Distribution Statement C contractor shall ensure integration and verification that SCFs and MCFs have the appropriate segregation and diverse redundancy in the architecture to complete the mission (resiliency), see requirement section for more information. In addition, the Architect Design Document shall include an analysis of any other systems’/subsystems’ interconnects/interfaces that are not SCF and MCF. If there are interconnects/interfaces, the Architect Design Document shall ensure the appropriate segregation and diverse redundancy is maintained for the SCF and MCF.
(CDRL A023, DI-MISC-80508B, Traceability Matrix) (CDRL A024, DI-MISC-80508B, Architect Design Document)
4.2.5 The contractor shall ensure all hardware with special emphasis on lowest CCs are from trusted sources and are manufactured by approved personnel as documented in the Security Plan.
The contractor shall develop and implement a Counterfeit Parts Prevention program in compliance DFARS 252.246–7007 Contractor Counterfeit Electronic Part Detection and Avoidance System using SAE AS5553, SAE AS6171, SAE AS6081, and IDEA-STD-1010B or similar practices to prevent the inclusion of counterfeit parts or parts with malicious logic. The contractor shall ensure that no critical components procured are on the section 806 List in the Supplier Performance Risk System (SPRS). The contractor shall develop a Supply Chain Risk Management (SCRM) plan documented in the Security Plan IAW the current version of CNSSD No. 505 and NIST SP 800-160 to mitigate supply chain risk. The contractor shall perform acceptance testing on lowest CCs.
(CDRL A025, DI-MGMT-81763, Customized Microelectronics Devices Source Protection Plan) (CDRL A026, DI-MISC-81832, Counterfeit Prevention Plan) (CDRL A027, DI-QCIC-80125B, Government Industry Data Exchange Program (GIDEP) Alert/Safety Alert Report)
4.2.6 The contractor shall ensure software assurance IAW the current version of Software Assurance Countermeasures in Program Protection Planning IAW table 5.3.3-1 of the Office of Secretary of Defense (OSD) Program Protection Plan (PPP) Outline & Guidance, dated July 2011. The contractor shall provide a Software Development Plan and the source code to complete software assurance independently for all safety critical and functions . In addition, the software development plan shall include an analysis of any other systems that are not SCF and MCF of interconnects. If there are interconnects/interfaces, the software development plan shall ensure the software assurance is maintained for the SCF and MCF.
(CDRL A028, DI-MISC-80508B, Security Assessment Plan) (CDRL A029, Reserved) (CDRL A030, DI-IPSC-81433A, Software Requirements Specification) (CDRL A031, DI-IPSC-81441A, Software Product Specification) (CDRL A032, Reserved) (CDRL A033, Reserved) (CDRL A034, DI-IPSC-81435A, Software Design Description)
4.2.7 Reserved
4.2.8 Reserved
4.2.9 Reserved
6 | P a g e
Distribution Statement C
4.3 Reserved
(CDRL A035, Reserved )
4.4 Security Management
4.4.1 The contractor shall establish and maintain a security program to comply with requirements of the Government-provided Contract Security Classification Specification, DD Form 254, and other security-related contractual requirements as indicated in all Request for Proposal (RFP)/Statement of Work (SOW) documents.
4.4.2 The contractor shall apply Operations Security (OPSEC) in their management of the Program IAW AFI 10-701 Operations Security and the OPSEC Plan and program’s Critical Information List provided by the Government program office.
(CDRL A036, DI-MGMT-80934C, OPSEC Plan)
4.4.3 The contractor shall provide Operations Security (OPSEC), Communications Security (COMSEC) and Cybersecurity (CS) Training as part of its overall training requirements.
OPSEC, COMSEC, and CS Training outline specific actions to protect classified and sensitive unclassified information, activities and operations during the course of the contract.
4.4.4 The contractor shall be compliant to National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 in accordance with DFARS, Clause 252.204-7008.
4.4.5 The contractor will notify the Government Contracting Activity and the Government Security Manager within 48 hours of any incident involving the actual or suspected compromise/loss of classified information to enable the Government to conduct immediate assessment of potential impact pending formal inquiry/investigation. Actual or suspected compromise of Covered Defense Information will be reported IAW DFARS Clause 252.204- 7012.
4.4.6 Reserved
4.4.7 Reserved
(CDRL A037, Reserved)
7 | P a g e
Distribution Statement C
APPENDICES
Appendix A- Documents
PUBLICATION TITLE
DATE OF
PUBLICATION
NIST SP 800-171 Rev. 1 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
December 2016 Includes updates as of 06-07-2018
NIST SP 800-53 Rev. 4 Security and Privacy Controls for Federal Information Systems and Organizations
April 2013 Includes updates as of 01-22-2015
NIST SP 800-160
Systems Security Engineering : Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
November 2016 Includes updates as of 03-21-2018
DoDI 8500.01 Cybersecurity
14 March 2014 Incorporating Change 1, Effective October 7, 2019
DoDI 5200.44 Protection of Mission Critical Functions to Achieve Trusted Systems and Networks (TSN)
5 November Incorporating Change 3, October 15, 2018
CNSSI 1253
SECURITY CATEGORIZATION AND CONTROL
SELECTION FOR
NATIONAL SECURITY SYSTEMS
27 March 2014
DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT)
12 March 2014 Incorporating Change 2, July 28, 2017
DoDD 8140.01 Cyberspace Workforce Management
August 11, 2015 Incorporating Change 1, July 31, 2017
DoDI 8570.01-M Information Assurance Workforce Improvement Program
19 December Incorporating Change 4 Nov 10, 2015
AFMAN 17-1303 Cybersecurity Workforce Improvement Program 9 August 2019
AFI 17-101
Risk Management Framework (RMF) for Air Force Information Technology (IT)
2 February 2017
8 | P a g e
Distribution Statement C
DFARS
252.239-7001 Information Assurance Contractor Training and Certification
SUBPART 204.73--SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER
INCIDENT REPORTING
252.204-7000 Disclosure of Information.
252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
252.239-7017 Notice of Supply Chain Risk (DEVIATION 2018-O0020).
252.239-7018 Supply Chain Risk (DEVIATION 2018-O0020).
252.246-7007 Contractor Counterfeit Electronic Part Detection and Avoidance System.
252.246-7008 Sources of Electronic Parts.
File details come from the government source that posted it. Updated .