Statement of Work - DO 1 - Infrastructure and Maintenance.pdf

PDF 364 KB Posted

Attached to
Cyber TRIDENT Federal contract opportunity
Solicitation number
W900KK-20-R-0001
Issued by
Department of the Army Materiel Command Contracting Command Orlando Contracting Center

About this file

This statement of work and related federal contract opportunity document outline requirements for infrastructure and maintenance support of the Persistent Cyber Training Environment platform. The statement of work requires the contractor to provide program management, operations and maintenance support, cybersecurity services, and logistics functions. Specific requirements include hosting program reviews, conducting infrastructure maintenance and support, managing the risk management framework and system authorization process, providing tier 3 technical support, conducting property management, and managing software licensing and obsolescence. The related federal contract opportunity indicates the solicitation is for the Cyber Training, Readiness, Integration, Delivery and Enterprise Technology indefinite delivery/indefinite quantity contract which will provide acquisition life cycle support and further evolution of the Persistent Cyber Training Environment platform to support cyber training needs for the Army, Navy, Marine Corps, Air Force, National Guard, and other defense and government organizations.

View the file

Other files for this federal contract opportunity

Other files attached to Cyber TRIDENT, newest first.
File Type Posted
TO 0001-Order-SOW-CDRLs.pdf PDF
TO 0002-Order-SOW-CDRLs.pdf PDF
Slides - Industry Day - Pre-Solicitation Briefing Slides Contracts - 4-30-20.pptx PPTX presentation
DO 0003-Order-SOW-CDRLs.pdf PDF
CDRL_Base_SOW.pdf PDF
RFP - W900KK-20-R-0001 DRAFT 30 Apr 2020 Updated.pdf PDF
SOW - DO 3 CYBER TRIDENT DO 3 SOW - 29 Apr 2020 Updated.pdf PDF
SOW - TO 1 CYBER TRIDENT TO 1 SOW - 29 Apr 2020 Updated.pdf PDF
Attach 17 - Proposal Cost Price Workbook 4-30-20 Updated.xls XLS spreadsheet
SOW - TO 2 CYBER TRIDENT TO 2 SOW - 29 Apr 2020 Updated.pdf PDF
Attach 18 - Past Perf Questionnaire - Cyber TRIDENT - 4-15-20 Updated.docx DOCX document
Attach 1 - SOW - Base CYBER TRIDENT Base SOW - 29 Apr 2020 Updated.pdf PDF
Attach 4 - RCS Price List - 4-24-20 Updated.docx DOCX document
Consolidated Industry Questions 1-200 4-30-2020 Posted (2).pdf PDF
Consolidated Industry Questions 1-200 4-30-2020 Posted.pdf PDF
Consolidated Industry Questions-Answer 1-74.pdf PDF
Q_A from Draft RFP.pdf PDF
Q-As -Cyber TRIDENT W900KK-20-R-0001 27 Mar 2020.pdf PDF
Instructions for Obtaining Distribution D Document - 13 Mar 2020.pdf PDF
Distribution Agreement - Cyber TRIDENT Solicitation -Final 13 Mar 2020.pdf PDF
List of Attachments - 13 Mar 2020.pdf PDF
Attach 19 - Q-A Spreadsheet-12 Mar 2020.xlsx XLSX spreadsheet
Attach 5 Small Business Participation Proposal Form.DOCX DOCX document
Attach 1 - Statement of Work - Basic Contract - Cyber TRIDENT.pdf PDF
00 Solicitation Attachment List.pdf PDF
Attach 18 - Past Perf Questionaire - Cyber TRIDENT.docx DOCX document
Attach 2 -Contract Labor Rates.docx DOCX document
Attach 15 - Pre-Award Survey of Prospective Contractor Acctg System Checklist.pdf PDF
RFP - W900KK-20-R-0001 DRAFT 10 Mar 2020.pdf PDF
Statement of Work - DO 2 - Integraton Factory.pdf PDF
Statement of Work -DO 3 - Platform Capability Production.pdf PDF
Attach 14 - PCTE DD254.pdf PDF
Instructions to Obtain Distribution D Documents.docx DOCX document
Attach 16 - SF1408 - Pre-Award Suvey of Prospective Contractor Acctg System.pdf PDF
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOW-2020-011-01

STATEMENT OF WORK

for the

Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT)

Delivery Order One (1) - Persistent Cyber Training Environment (PCTE) Infrastructure and Maintenance

U.S. Army Program Executive Office for Simulation, Training, and Instrumentation (PEO STRI)

12211 Science Drive Orlando, FL 32826-3276

Revision Number Date Log of Changes Made and Description of

Reason Changes Approved By

Table of Contents

1. SCOPE

1.1 Introduction

1.2 Goals and Objectives

2. APPLICABLE DOCUMENTS

3. REQUIREMENTS

3.1 Program Management

3.1.1 Monthly Report

3.1.2 Associate Contractor Agreements (ACAs)

3.1.3 Schedule

3.1.4 Risk Management

3.1.5 Program Management Reviews (PMRs)

3.1.6 Facilities

3.1.6.1 Contractor’s Developmental/Test Facilities

3.1.6.2 Sensitive Compartmented Information Facility (SCIF)

3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions

(CHESS) Program

3.2 Operations

3.2.1 PCTE Maintenance and Support

3.2.2 Infrastructure Tier 3 Technical Support

3.3 Cybersecurity

3.3.1 Risk Management Framework (RMF)

3.3.1.1 Cyber Reports and Tasks Schedules

3.3.1.2 Cyber Technical and Meeting Support

3.3.2 Army Training and Certification Tracking System (ATCTS) Training

3.3.3 OPSEC Clauses/COMSEC/Declassification

3.3.3.1 Requirements for OPSEC Training:

3.3.3.2 Anti-Terrorist Training (AT Level 1)

3.3.3.3 Active Shooter Training

3.3.3.4 Access to Government Information Systems

3.3.3.5 Professional Training and Certification

3.3.3.6 Personal Identifiable Information (PII)

3.3.3.7 Security and Access Controls

3.3.3.7.1 General Security

3.3.3.7.2 Security Clearances

3.3.3.7.3 Access and General Protection/Security Policy and Procedures

3.3.3.7.4 Handling or Access to Classified Information

3.3.3.7.5 Disclosure of Information

3.3.3.7.6 Effective Use of Controls

3.3.3.7.7 System Security Plan (SSP)

3.4 Logistics

3.4.1 Maintenance Support

3.4.2 Property Accountability and Management

3.4.2.1 Inventory Support

3.4.3 Supply Management

3.4.4 Licensing and Warranty Management

3.4.5 Supportability

3.4.6 Software Asset Management

3.4.7 Obsolescence Management/Diminishing Manufacturing Sources and

Material Shortages (DMSMS)

3.4.8 Item Unique Identification (IUID)

4. ADDITIONAL CONTRACTOR REQUIREMENTS

4.1 The Enterprise-Wide Contractor Manpower Reporting Application

(eCMRA)

Statement of Work

SOW-2020-011-01

Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT)

Delivery Order One (1) - Persistent Cyber Training Environment (PCTE) Infrastructure and Maintenance

1. SCOPE

This Statement of Work (SOW) defines the scope of the Project Manager Cyber Test and Training (PM CT2) Product Manager Cyber Resiliency and Training (PdM CRT) Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT) Delivery Order One (1). The Cyber TRIDENT Indefinite Delivery/Indefinite Quantity (IDIQ) is utilized by Department of Defense (DoD) organizations and other non-DoD agencies that have related cyber training needs. The Cyber TRIDENT IDIQ provides the management, integration, maintenance, and evolution for the PCTE platform, and provides total system/subsystem acquisition life cycle support for the PCTE system baseline.

This Delivery Order One (1) SOW defines the detailed requirements that PdM CRT requires to have performed under the Cyber TRIDENT IDIQ contract in support of PCTE Infrastructure and Maintenance for the PCTE platform. PM CT2 defines the Infrastructure and Maintenance of the PCTE platform under Cyber TRIDENT Delivery Order One (1) to include:

• Cybersecurity Maintenance and Compliance

• Information Technology (IT) Support

• Facilities

• Development Regional Compute and Storage (RCS), Production RCS Support

• Tier 3 Infrastructure Technical Support

• Sensitive Compartmented Information Facility (SCIF) Operations

• License Procurement and Management

• Logistics

• Property Management

1.1 Introduction

Delivery Order One (1) will provide the necessary contractor support for Infrastructure and Maintenance of the PCTE platform. This covers the various hardware and software platforms, networks, and security operations across the fielded sites of PCTE.

1.2 Goals and Objectives

The objective of Cyber TRIDENT Delivery Order One (1) is to provide Infrastructure and Maintenance for the evolving PCTE Platform. Cyber TRIDENT Delivery Order One (1) will specifically support the PCTE solution evolving infrastructure and the required maintenance of the infrastructure along with the security operations to comply with all Army and DoD regulations and policies.

2. APPLICABLE DOCUMENTS

The applicable documents listed in the Base SOW are applicable to Delivery Order 1. Reference Section 2 of the Base SOW for full list.

3. REQUIREMENTS

The contractor shall provide Infrastructure and Maintenance support of the PCTE capabilities.

The contractor shall deliver platform capabilities for integration, to include performing testing prior to fielding the platform. This will require such activities that include IAVA management, IT Support, Facilities, Development RCS, Production RCS, Help Desk, JDIF/SCIF Operations, License Procurement and Management, Logistics, Property Management, Risk Management Framework (RMF)across the PCTE RCS fleet. The contractor shall provide engineering, materials, equipment, testing, technical and operations support for the PCTE as described in this Delivery Order One (1) SOW. The work scope of DO 1 shall be managed and tracked within the visibility and construct of the Delivery Order 2 established agile ceremonies.

3.1 Program Management

The contractor shall provide the overall management and administrative effort necessary to ensure that the requirements of this Delivery Order One (1) are accomplished. The contractor shall track Delivery Order (DO) progress and deliverables, utilizing data driven metrics to inform the Government of the delivery order status. The contractor shall participate, contribute, and execute as an attendee in the Delivery Order 2 hosted agile ceremonies, design reviews, product demonstrations, Integrated Product Team (IPT) meetings, partnering, transition meetings, conferences, installations, post installation assessments, and life cycle planning of current and future systems/software releases.

3.1.1 Monthly Report

The contractor shall submit a Contractors Progress, Status and Management Report that provides information to include but not limited to schedules, accomplishments, metrics, risks, issues, problems, and deficiencies related to this DO’s activities. The monthly report shall include, but not be limited to, status on the below requirements. The contractor shall propose additional metrics to better inform the Government on delivery order status.

• Property Management

• License Procurement

• Help Desk Metrics

• Infrastructure Availability and Uptime Metrics (calculated on a monthly basis)

CDRL Number CDRL Name CDRL A101 Contractors Progress, Status and Management Report, DI-MGMT-80227

3.1.2 Associate Contractor Agreements (ACAs)

The contractor shall implement ACAs with other PCTE and third-party contractors as required for exchanging data, accessing and using third party software and equipment, receiving technical support, working interface and integration issues, and DoD cyber user event planning and execution. The contractor shall ensure that ACAs are maintained to achieve development of the platform and maintain PCTE interoperability and event planning and execution, as applicable.

ACAs shall provide for and permit the complete and unbiased exchange of technical information and data relating to PCTE integration, development and deployment. Agreements shall be structured so that all Cyber TRIDENT and PCTE contractors are obligated to protect proprietary data and classified information from all unauthorized use or disclosure. ACAs shall be submitted to the Contracting Officer for review prior to execution.

3.1.3 Schedule

The contractor shall document the planned events and milestones, accomplishments, and activities based on supporting other active DOs. The schedule shall include a detailed account of all tasks necessary to support schedule, goals, and objectives of other active DOs. The contractor shall demonstrate that schedule activities are synchronized across all other active DOs, and available for Government review.

3.1.4 Risk Management

The contractor shall promptly notify the Government of contract performance risks, issues, problems, and deficiencies. In accordance with the contractor’s risk management plan, implement risk detection and identification, assignment of risk categories, risk mitigation planning, mitigation plan implementation, corrective action, tracking of compliance, reporting of status and planning for risk abatement. The contractor shall promptly provide and execute corrective actions plans, in consultation with the Government. The contractor shall include in each Contractor Monthly Progress, Status and Management Report the status of all outstanding contract performance risks, issues, problems, and deficiencies, as well as corrective actions with respect thereto.

3.1.5 Program Management Reviews (PMRs)

The contractor shall host Program DO Review quarterly (per year) to inform the Government of DO risks and issues. The contractor shall conduct Technical Interchange Meetings (TIMs) and In Progress Reviews (IPRs) as directed by the Government. The reviews shall provide a forum for IPT members to clarify the following areas of this DO to include but not limited to:

• Cybersecurity Management and Compliance

• IT Support

• Facilities

• Development RCS, Production RCS

• Logistics

The meetings shall be conducted at the contractor’s facility. PMR shall cover DO program risks and issues that can affect the entire Cyber TRIDENT portfolio, including parallel DOs-specific issues and risks as appropriate. The contractor shall post agendas and meeting minutes to established web portals or SharePoint sites.

CDRL Number CDRL Name CDRL A102 Report, Record of Meeting/Minutes, DI-ADMN-81505

3.1.6 Facilities

3.1.6.1 Contractor’s Developmental/Test Facilities

The contractor shall operate and maintain a facility that supports all PCTE Delivery/Task Orders (TO/DO), to include TO 0002 and DO 0003 operations at the Unclassified, Secret, and Top- Secret classification levels with the ability to incorporate PCTE end users to include Government, Industry, and coalition partners. The PCTE program has implemented an Agile software development methodology requiring active and daily on-site Government presence to conduct the various Agile ceremonies including daily standup meetings, weekly Architectural meetings, monthly sprint planning meetings, and release planning workshops. As a result of this active and daily Government presence and to facilitate Government testing and collaboration, the facility shall be located no more than ten (10) miles from PEO STRI at 12211 Science Dr, Orlando, FL 32826. This facility will include the Government provided PCTE RCS infrastructure to be used as a test bed for system configuration and software development to enable support of the PCTE Production and Development RCS. The facility equipment provided by the Government must be dedicated to PCTE activities and tasks.

The contractor shall provide the necessary physical space, power, cooling, and network connectivity needed to house the Government Furnished Equipment (GFE) hardware, software, and networking components (see Attachment 005). The RCS equipment includes a PCTE development RCS and the facility shall be able to support the build out of RCS configurations.

The contractor shall provide physical space, power and Heating, Ventilation, Air Conditioning (HVAC) in accordance with specifications (see Attachment 001, Appendix 3). The contractor shall provide connectivity to the equipment with appropriate bandwidth to support PCTE’s RCS fleet across multiple classification levels.

The contractor shall establish and enforce security procedures in accordance with (IAW) security classification of products and services and the Contracts Security Classification Specifications, DD Form 254 and addendum sheets for Delivery Order One (1) according to the National Industrial Security Program Operating Manual (NISPOM) requirements.

The contractor shall provide and manage an integration factory which includes but is not limited to a collaborative meeting space, development environment (i.e., Remote, Compute, and Storage), and tools. The collaborative meeting space shall include but not be limited to the following features:

• A core meeting space that supports as least one hundred (100) participants for conducting Agile Ceremonies, traditional Government Ceremonies, and any other ceremonies/meetings required by the contractor’s Agile system engineering process.

• At least five (5) break-out rooms that accommodate at least twenty (20) participants per room.

• Video and audio teleconferencing tools for remote participants in each space / room.

• Video projection system in each space / room.

• Internet and power access for attendees in each space / room.

• Audio system and microphones for projecting participants voice in each meeting space / room.

• Whiteboards and office supplies in each space/room to support Agile Ceremonies, traditional Government Ceremonies, and any other ceremonies/meetings required by the contractor’s Agile system engineering process.

3.1.6.2 Sensitive Compartmented Information Facility (SCIF)

The contractor shall operate a SCIF located at the Government site at PEO STRI Orlando, FL for all XXXX activities with all required clearance (Top Secret/SCI) for employees for access. See attachment 001, Appendix 4 for SCIF facility details. Upon completion of contactor provided accredited SCIF, the contractor shall operate and maintain the SCIF XXX activities at the contractor’s SCIF facilities as required to maintain accreditation. The contractor shall utilize the Government provided SCIF until the contractor provided SCIF is completed and accredited.

3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions (CHESS) Program The contractor shall procure hardware, software, and licensing to support the Delivery Order 1 activities to include infrastructure and maintenance related procurements. The contractor shall comply with the Army’s CHESS program when making procurements. Under Program Executive Office Enterprise Information Systems (PEO EIS), CHESS is the mandatory source for commercial Information Technology (IT) purchases. CHESS contracts provide IT products and services that comply with U. S. Army Network Enterprise Technology Command (NETCOM), Army and DoD policy and standards. Purchasers of commercial hardware and software must satisfy IT requirements by utilizing CHESS contracts and DoD Enterprise Software Initiative agreements first, regardless of dollar value. Any purchase made outside of CHESS contracts requires a waiver. A complete list of CHESS contracts and the on-line waiver process can be found at:

https://protectus.mimecast.com/s/yDPLCR6K3OIrGJ7iqywOR?domain=chess.army.mil

3.2 Operations

The contractor shall manage PCTE platform operations to ensure a system availability for a high quality, persistent user experience. The work tasks described in this DO are intended to address the core functionalities of capability operations. The contractor shall perform all of the required tasks necessary to ensure the continued functions to support the capability. PCTE will be located at a number of sites enabling cyber range transport capabilities and existing emulated network environments (maneuver areas). The current PCTE sites include:

1. Fort Gordon, GA

2. Ft. Meade, MD

3. Suffolk, VA

4. Joint Base San Antonio, TX

5. Oahu, HI

6. Orlando, FL

3.2.1 PCTE Maintenance and Support

The contractor shall manage the maintenance for PCTE infrastructure (all RCS nodes). This includes but is not limited to the following:

• Shall provide a 95% availability of the PCTE infrastructure calculated on a monthly basis. The availability time is 24 hours a day, 7 days a week. Unavailability of RCS fielded facilities, networks connectivity, or awaiting Government provided replacement parts is deleted from the platform availability time.

• Coordinate with Government site representatives to facilitate PCTE release deployment schedule and maintenance tasks to not impact PCTE operations

• Assist, maintain, and update Memorandums of Agreement (MOAs) and Inter-Agency Service Agreements (ISAs)

• Perform on-going test and performance validation of the PCTE RCS at designated sites

• Activate and perform ongoing maintenance and monitoring of RCS nodes in accordance with Program Management Office Technical Operations Management (TOM) guidelines to maintain availability of the system

• Regularly apply software patches and updates for any COTS/GOTS products utilized on the PCTE RCS platform

The contractor shall provide on-site maintenance for the PCTE platform for all equipment listed in Appendix 2 of the Base SOW. The contractor shall maintain RCS nodes in a variety of security enclaves. This includes but is not limited to unclassified, secret, and TS/SCI. The contractor shall develop, maintain, and plan technical patches of the platform for the RCS software, hardware, and network configuration.

CDRL Number CDRL Name CDRL B101 Maintenance Plan, DI-MISC-80711A

3.2.2 Infrastructure Tier 3 Technical Support

PCTE has a multi-tier support structure that is enabled through the Tier 0-3 levels. Tier 0 is the unit providing initial support. Tier 1 is Government provided through the Joint Cyber Training Enterprise (JCTE). Tier 2 is PCTE PM supported. Tier 3 is the Cyber TRIDENT contractor for PCTE Infrastructure related trouble tickets and the PCTE CIC vendors are responsible to cyber training platform software related trouble tickets.

The contractor shall design and implement a Tier 3 Technical Support capability to provide support for escalated PCTE platform and infrastructure related trouble tickets as coordinated from Tier 2. The contractor shall provide technical and subject matter expertise that matches the current baseline and future updated capabilities of PCTE to diagnose and resolve problems identified by Tier 2 and documented in trouble tickets. Tier 3 Technical Support includes resolution of infrastructure problems such as connectivity, diagnostics, interface problems, and performance-related problems. The contractor shall have 24 hours from the point of Tier 3 notification of a trouble ticket to resolve the action. The Tier 3 Technical Support function provides Tier 2 point of access to request help in identification and resolution of enterprise application infrastructure-related problems. The Tier 3 Technical Support function shall maintain support communications through a phone line, dedicated email address, channels on the PCTE platform’s onboard chat capability, and leverage the existing enterprise-wide Trouble Ticketing/Problem Reporting System (TTPRS) accessible from the PCTE platform. The Tier 3 Technical Support shall be staffed in order to provide customer support 24 hours a day, seven (7) days a week.

CDRL Number CDRL Name CDRL B102 Trouble Ticketing/Problem Reporting Plan, DI-MISC-80711A

3.3 Cybersecurity

The contractor shall adhere to the PCTE approved type accreditation. The contractor shall monitor the accreditation compliance of cybersecurity at a number of classification levels and environments to include Closed, Restricted Networks (CRNs), Open Secret Internet Protocol (IP) Router (SIPRNET), Open Non-Classified IP Router (NIPRNET), and Top Secret/Sensitive Compartmented Information (SCI).

The Contractor shall monitor accreditation compliance of the Army Best business Practices Federal Information System Management Act (FISMA) security requirements, Appendix II of OMB A-130, to include the configuration of systems to Security Technical Implementation Guides (STIGs) compliance, patch management, Information Assurance Vulnerability Management (IAVM), AR 380-5, National Security Telecommunications and Information Systems Security Policy (NSTISSP), No. 11 with revisions, “ National Policy Governing the Acquisition of Information Assurance (IA) and IA-enabled Information Technology Product,” DoDI 8500.01, and must be compliant with all NETCOM Tactics Techniques Plans (TTPs) which can be found at Risk Management Framework (RMF) Knowledge website cyclical support to remediate or mitigate know critical issues, and other Information Assurance functions.

1. The contractor shall also ensure that the software, components, and services maintained within PCTE are in accordance with DISA STIG compliance. The contractor shall monitor the DISA STIGs implementation for the IT technology developed and configuration manage the Delivery Order 2 completed STIG checklists to enforce compliance.

2. The contractor shall ensure compliance of the Cybersecurity/RMF process to guide management and design actions, document RMF decisions and certification efforts, specify and track RMF requirements, identify possible Cybersecurity solutions, synchronize RMF with CM activities, and maintain operational systems security.

3. The contractor shall conduct assessments of the PCTE supporting infrastructure for security vulnerabilities and weaknesses. The contractor shall report and ensure compliance with protective measures in accordance with the PCTE accreditation to address identified vulnerabilities and weaknesses to the Government.

4. The contractor shall continually evaluate the security of the system, both physical and logical, identifying exposures and providing protective options for reducing security risk.

5. The contractor shall ensure protective measures are maintained to provide Information Security. When Classified or Controlled information is introduced into the PCTE, the contractor shall adhere to the provisions within AR 380-5 regarding the classification, transmission, transportation, and safeguarding of this information. Cryptography shall be Federal Information Processing Standards (FIPS) 140-2 compliant. There shall be a mechanism established to ensure encrypted data can be recovered in the event the primary encryption system fails.

6. The contractor shall maintain protective mechanisms into the system and applications to provide identification and authentication, access control, accountability, availability, confidentiality, privacy, data integrity, and non-repudiation.

7. The contractor shall use Government approved assessment tools to perform cyber security testing to document, verify, and validate each applicable operating system security configuration.

8. The contractor shall provide input into the documentation of the unincorporated security controls defined in the applicable STIG and unincorporated IAVA’s in the Plan of Action and Milestones (POA&M) document to ensure future compliance with the ATO is maintained.

3.3.1 Risk Management Framework (RMF)

The Contractor shall maintain the current PCTE RMF accreditation and perform reaccreditation tasks at the time of recertification. The Contractor shall adhere and ensure compliance with the RMF documentation and participate in the necessary milestones to include, but not limited to, the System Registration Review (SRR), System Security Plan (SSP), System Contingency Plan (SCP), System Configuration Management Plan (SCMP), systems Plan of Action and Milestones (POA&M), Information Assurance Vulnerability Alert (IAVA) Reports, STIG Deviation Reports, STIG Checklists, Accreditation and Data Flow Boundaries, Software and Hardware Lists for each system configuration.

The Contractor shall ensure the system remains in a configuration compliant with the current type accreditation Authority to Operate (ATO) certification to the RMF Confidentiality, Integrity, and Availability (CIA) and Certification Level (CL) of all levels at moderate. The contractor shall report any ATO waivers or deviations to the PM through the Configuration Management process.

The Contractor shall support Assessment and Authorization associated activities to use a third-party validator to scan the system for IA vulnerabilities. The Contractor shall provide Cybersecurity Subject Matter Expertise (SME) to support the annual review of each accredited system/sub-system’s IA controls according to Federal Information Security Management Act (FISMA) guidance in conjunction with the Information Systems Security Officer (ISSO) and the Information System Security Manager (ISSM) and /or PEO STRI IA designee. The Contractor shall conduct quarterly IA scans on Government Furnished Equipment (GFE) and provide to the Government as part of the annual review.

The Contractor shall follow production specification and evaluation requirements of the National Institute of Standards and Technology (NIST), Special Publications (SP) 800.53 Security and Privacy Controls for Federal Information Systems and Organizations, Committee on National Security Systems Instruction (CNSSI) 4009, CNSS, Glossary, Common Criteria, and National Information Assurance Partnership (NIAP) Approved Product List (APL). All incorporated IA products, and IA-enabled IT products that require use of the product’s IA capabilities, acquired under the contract, shall comply with the National Telecommunications and Information Systems Security Policy (NTSISSP) No. 11 “National Policy Governing Acquisition Assurance (IA) and IA-enabled Technology Product.”

3.3.1.1 Cyber Reports and Tasks Schedules

The Contractor shall complete the following requirements and report:

• Quarterly Reports o IAVA Reports o Vulnerability Scan Reports

ACAS/Nessus Scans SCAP Scan Reports on all COTS Software and Hardware STIG Checklists STIG Deviation Reports Software Security Reports for any developmental software Updated Configuration Drawings Updated Software and Hardware Reports

POA&M

• FISMA Annual Review Report o ACAS/Nessus Scans o SCAP Scan Reports on all COTS Software and Hardware o STIG Checklists o STIG Deviation Reports o Software Security Reports for any developmental software o Updated Configuration Drawings o Updated Software and Hardware Reports o POA&M

3.3.1.2 Cyber Technical and Meeting Support

The cybersecurity team should be integrated in the agile ceremonies and shall attend and support various meetings to include, but not limited to:

• Integrated Product Team (IPT) Meetings

• Program Management Reviews (PMR’s)

• System Testing and/or Integration Events

• Technical Interchange Meetings (TIM)

• Training Events

• Cyber Meetings

• Configuration Management Board Meetings

3.3.2 Army Training and Certification Tracking System (ATCTS) Training The Contractor shall require that lead and support personnel performing Cybersecurity job functions possess the Information Assurance Management (IAM) or Information Assurance Technical (IAT) certification relevant to their role within the execution of this contract and IAW DoDD 8140.01, DoD 8570.01-M, AR 25-2 (4-3 Information Assurance Training), and Army BBP 05-PR-M-002. IA engineers, analysts, and technicians shall complete the required “IA Awareness Training.” Method of training for “IA Awareness training” is https://cs.signal.army.mil/default.asp “DoD Cyber Awareness Mandatory IA Training,” The Contractor’s IA Team shall complete the required “Information Assurance Fundamentals Training.”

1. This shall include the methods, skills, use, and mechanisms to maintain the level of security of the IS.

2. The training shall be geared toward the audience and their roles and responsibilities with respect to the system’s operation and maintenance (i.e., system administrator, network administrator, hardware maintenance, etc.).

3. The contractor shall utilize DOD 8570.01-M as a guide in the development of the IA

Training content.

3.3.3 OPSEC Clauses/COMSEC/Declassification

The contractor shall ensure this Delivery Order is in compliance with the base contract existing OPSEC Standing Operating Procedure/plan within ninety (60) calendar days of DO award making any necessary updates, to be reviewed and approved by the responsible Government OPSEC officer. The plan’s updates shall include a process to identify critical information, where it is located, who is responsible for it, how to protect it, and why it needs to be protected. The contractor shall implement OPSEC measures as ordered by the Government. In addition, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1.

3.3.3.1 Requirements for OPSEC Training:

Per AR 530-1, Operations Security, new contractor employees must complete Level I OPSEC training within thirty (30) calendar days of their reporting for duty. The contractor shall ensure all applicable employees have completed OPSEC initial training, annual refresher training, and shall certify their work force has completed the training through the submission of completion certificates(s) to the COR, or the Contracting Officer when a COR is not assigned, within thirty

(30) days of arrival on the installation. OSPEC training can be accomplished at the Defense Security Services website at: https://securityawareness.usalearning.gov/opsec/

3.3.3.2 Anti-Terrorist Training (AT Level 1)

All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete AT Level I awareness training within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR or to the Contracting Officer within 30 calendar days after completion of training by all contractor employees and subcontractor personnel. AT Level I awareness training is available at the following website: https://atlevel1.dtic.mil/at or other Service specific websites.

The contractor shall ensure all US based Contractor employees and associated subcontractor employees to make available and to receive Government provided area of responsibility (AOR) specific AT awareness training as directed by applicable DoD, Service policy and regulations.

Specific AOR training content is directed by the Combatant Commander with the unit Anti- Terrorism Officer (ATO) being the local point of contact.

3.3.3.3 Active Shooter Training

All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete active shooter training as directed by applicable DoD, Service policy and regulations within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/ACOR or to the Contracting Officer within thirty (30) calendar days after completion of training by all contractor employees and subcontractor personnel.

3.3.3.4 Access to Government Information Systems

All contractor employees with access to a Government Information System must be registered in the applicable Service training and certification system at commencement of DO performance and must successfully complete DoD Information Assurance Awareness training prior to being granted access to information systems (IS) and then annually thereafter.

3.3.3.5 Professional Training and Certification

The contractor shall be responsible to ensure that employees, to include subcontractor employees, at all times maintain the required professional training and certifications required for their job description(s) and role(s).

Per DoD 8570.01-M, DoDD 8140.01, Defense Federal Acquisition Regulation Supplement (DFARS) 252.239.7001 and applicable Service regulations, the contractor employees supporting Cybersecurity/IT functions shall be appropriately certified upon DO award. The baseline certifications as stipulated in DoD 8570.01-M for specific positions shall be completed upon DO award.

3.3.3.6 Personal Identifiable Information (PII)

All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete training in the handling and protection of PII as directed by applicable DoD, Service policy and regulations within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/ACOR or to the Contracting Officer within thirty (30) calendar days after completion of training by all contractor employees and subcontractor personnel. PII training is available at https://securityawareness.usalearning.gov/piiv2.

3.3.3.7 Security and Access Controls

3.3.3.7.1 General Security

The contractor shall ensure that personnel at all times comply with applicable Government security policies and procedures. In addition, to ensure expedited reporting, the contractor shall ensure that required security reporting is implemented in a manner that does not require contractor employees to notify contractor management chains of a reportable security situation prior to them reporting it to the appropriate Government channels.

3.3.3.7.2 Security Clearances

The contractor shall issue security clearances only to those contractors who will have access to classified information up to the TS/SCI level for PCTE. Some positions/duties may not require a clearance, but all positions/duties will require investigation for duties and access to U.S.

Government systems and technical information. The Contractor shall ensure that employees performing under this contract have the appropriate clearance not to exceed the requirements supported.

3.3.3.7.3 Access and General Protection/Security Policy and Procedures Contractor and all associated subcontractor employees shall comply with applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by Government representative). The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by installation authorities. Contractor workforce shall comply with all personal identity verification requirements as directed by applicable DoD, Service and local policy. In addition to the changes otherwise authorized by the changes clause of this DO, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.

The Common Access Card (CAC) shall be the principal identity credential for supporting access to DoD installations, facilities, buildings, controlled spaces, and access to U.S. Government information systems. A National Agency Check with Inquiries (NACI) or equivalent national security clearance [e.g. National Agency Check with Local Agency Checks including Credit Check (NACLC)] will be required for permanent issuance of the credential. The Government may issue the credential upon favorable return of the Federal Bureau of Investigations (FBI) fingerprint check, pending final favorable completion of the NACI or equivalent. There shall be no additional NACI or equivalent submission for an individual holding a valid national security clearance.

The contractor shall account for all forms of U.S Government-provided identification credentials issued to contractor employees in connection with the performance of this DO. The contractor shall return such identification credentials to the issuing agency at the earliest of any of the circumstances listed below, unless otherwise determined by the U.S. Government. The Contracting Officer may delay final payment under an individual DO if the Contractor fails to comply with these requirements. The contractor and all associated subcontractors shall return all identification credentials when:

a. No longer needed for DO performance.

b. Completion of contractor employee’s employment.

c. DO completion or termination.

For all contractors and associated subcontractor employees who do not require a CAC, they must comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB), applicable

Service, installation, facility and area Commander installation/facility access and local security policies and procedures (provided by Government representative), or, at OCONUS locations, in accordance with status of forces agreements (SOFA) and other theater regulations.

3.3.3.7.4 Handling or Access to Classified Information

The contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified "Confidential," "Secret," or "Top Secret". The contractor shall comply with (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DOD 5220.22-M), (2) any revisions to DOD 5220.22-M, and (3) Contract Security Classification Specification (DD Form 254).

3.3.3.7.5 Disclosure of Information

The contractor shall comply with the protection standards and guidance described in DoD Manual 5200.1 to prevent foreign intelligence collection and/or the unauthorized disclosure of information.

3.3.3.7.6 Effective Use of Controls

The contractor shall screen all electronic deliverables or electronically provided information for malicious code using DoD approved anti-virus software prior to delivery to the Government. The contractor shall utilize appropriate controls (firewalls, password protection, encryption, digital certificates, etc.) at all times to protect DO related information processed, stored or transmitted on the contractor’s and Government’s computers/servers to ensure confidentiality, integrity, availability, authentication and non-repudiation. The contractor shall ensure provisions are in place that will safeguard all aspects of information operations pertaining to this DO in compliance with all applicable SOW references

3.3.3.7.7 System Security Plan (SSP)

The contractor shall safeguard covered defense information that resides on their internal unclassified information systems and networks to satisfy the security requirements of DFARS 252.204-7012, and in accordance with NIST SP 800-171 (Protecting Unclassified Information in Nonfederal Information Systems and Organizations). The contractor shall update the approved system security plan (SSP) with any new information from this DO that addresses implementation of the NIST SP 800-171 security requirements to include any associated plans of action for each of the contractor’s tier one level subcontractor(s), vendor(s), and/or supplier(s), and the subcontractor’s tier one level subcontractor(s), vendor(s), and/or supplier(s), who process, store, or transmit covered defense information associated with the execution and performance of this DO.

3.4 Logistics

The contractor shall perform the necessary tasks and activities for logistics and maintenance of the infrastructure for PCTE.

3.4.1 Maintenance Support

The contractor shall be responsible for the end-to-end lifecycle maintenance and support of the PCTE platform. The contractor shall provide applicable, commercial software licensing for continued system maintenance and services for the system life cycle. The contractor shall be responsible for all repairs and coordinate with vendors to keep the capabilities fully operational.

3.4.2 Property Accountability and Management

The contractor shall ensure 100% accountability for all government property to include PCTE infrastructure hardware, supplies, GFP, and maintenance parts. The Contractor shall establish and implement a Property Management System consist with FAR Clause 52.245-1 requirements for all Government Furnished Property (GFP) provided under this contract. The contractor shall establish and maintain procedures necessary to assess its Property Management System effectiveness and shall perform periodic internal reviews, surveillances, self-assessments, or audits. Significant findings or results of such reviews and audits pertaining to Government property shall be made available to the Contracting Officer/Contracting Officer’s Representative/Program Logistician. The contractor’s system shall be adequate to satisfy the requirements of FAR Clause 52.245-1. In doing so, the contractor shall initiate and maintain the processes, systems procedures, records and methodologies necessary for effective and efficient control of Government property. The contractor shall disclose any significant changes to its property management system to the Government to implementation of the changes. The contractor may employ customary commercial practices, voluntary consensus standards, or industry-leading practices and standards that provided effective and efficient Government property management that are necessary and appropriate for the performance of this contract (except where inconsistent with law or regulation).

CDRL Number CDRL Name CDRL C102 Property Management System Plan, DI-MISC-80711A

3.4.2.1 Inventory Support

The contractor shall conduct annually joint inspection and inventory of all PCTE equipment to include RCS installed sites, support facilities, development environments, and other contractor support locations. The contractor shall, in conjunction with a Government representative, conduct a physical inventory of spares, racks, data centers, servers, switches, computers and equipment. The contractor shall prepare a Materiel Component List (MCL) providing a logical listing of major subassemblies, and their non-expendable and discrete components data needed to build a Component Hand Receipt (CHR). Upon completion of the inventory, representatives shall sign a hardcopy of the inventory in the form of a DA Form 3161.

CDRL C101 PCTE Consolidated GFE Report, DI-MGMT-80269

3.4.3 Supply Management

The contractor shall establish and maintain an automated supply system that accounts for PCTE organizational and installation supplies and equipment. The contractor’s automated supply system shall include policies and procedures for the reception, inspection, inventory, loading and unloading, storing, issuing, and delivery of supplies and equipment. The contractor shall track supplies and equipment by part number, serial number and quantity, ensuring 100% accountability is achieved monthly. The contractor shall report the inventory monthly detailing any discrepancies and actions taken to correct property accountability problems.

CDRL C104 Logistics Product Data, DI-SESS-81758

3.4.4 Licensing and Warranty Management

The contractor shall only install software updates for licensed software. The contractor shall support maintenance packages with the licensed software. The contractor shall not violate any rules or laws with software license agreements. The Contractor shall stay in compliance with all software license agreements. The contractor shall provide software license agreement management to include inventory, tracking, accounting for and monitoring all types of software license agreements. The contractor shall be responsible for installing all updates and installation for all systems that require necessary upgrades. The contractor shall provide detailed lists of all software to include licensing agreements and schedule updates.

3.4.5 Supportability

The contractor shall conduct repair analyses, develop diagnostic, preventative maintenance and repair procedures, conduct facilities analyses, refine hardware and software maintenance and support concepts, and identify support resource requirements including required spares and support equipment. The contractor shall develop a listing of which items should be repaired and which should be discarded or return to the vendor. The contractor shall develop cataloging data to allow the Government to catalog all delivered hardware, spares, and support equipment.

CDRL C103 Priced Bill of Materials, DI-MGMT-81994

3.4.6 Software Asset Management

The contractor shall maintain all information, terms and conditions on data rights for technical data and documentation applicable to both software and hardware. This includes, but is not limited to, software rights, data, source codes, drawings, and warranties. The contractor shall provide and maintain a current Software Asset Management (SAM) Assessment to assess the current state of PCTE licensing compliance. The contractor will leverage existing data, software assets, hardware assets, procurement data, and existing SAM methodology to assess the maturity of the current SAM program and make recommendations for optimization by incorporating best practices and determine regulatory compliance requirements.

CDRL Number CDRL Name CDRL C105 Commercial Off-The-Shelf (COTS) Manuals and Associated

Supplemental Data, DI-TMSS-80527C

3.4.7 Obsolescence Management/Diminishing Manufacturing Sources and Material Shortages

(DMSMS)

The contractor shall establish an obsolescence management program. The obsolescence management includes an ongoing review and identification of actual and potential obsolescence issues including, but not limited to, obsolescence of components, assemblies, sub-assemblies, piece parts, and material through the systems life cycle. The contractor shall be responsible for identification for all DMSMS/Obsolescence/Producibility issues associated with production and delivery of hardware under this Delivery Order. The identification of DMSMS/Obsolescence/Producibility issues and the necessary resolution and implementation thereof shall be performed on a separate DO as per Government direction.

3.4.8 Item Unique Identification (IUID)

The contractor shall provide IUID or a DoD recognized unique identification equivalent for all delivered items for which the Government’s unit acquisition cost is $5000 or as directed by the program office.

4. ADDITIONAL CONTRACTOR REQUIREMENTS

4.1 The Enterprise-Wide Contractor Manpower Reporting Application (eCMRA).

The contractor shall ensure ALL contractor labor hours (including subcontractor labor hours) required for the performance of services provided under this contract are reported via a secure data collection site. The contractor (and all subcontractors providing direct labor under this contract) shall report complete and accurate data for the labor executed during the period of performance during each Government fiscal year (FY), which runs from October 1 to September

30. The Contractor shall input the data into the appropriate eCMRA reporting tool, which can be accessed via a secure web site at http://www.ecmra.mil/. There are four separate eCMRA tools:

Army, Air Force, Navy and All Other Defense Components. The appropriate eCMRA reporting tool to use is determined by the requiring activity being supported. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year.

The contractor shall completely fill in all required data fields. The contractor shall enter initial data into the appropriate eCMRA tool to establish the basic contract record no later than 15 working days after receipt of contract award or contract modification incorporating this clause.

The contractor shall notify the COR when the basic contract record has been established in the appropriate eCMRA tool. eCMRA User Manuals and Frequently Asked Questions (FAQs) are available at http://www.ecmra.mil/. Contractors may direct technical questions to the eCMRA help desk at dodcmra@pentagon.af.mil.

File details come from the government source that posted it. Updated .