TBMCS PWS - RFI M67854-23-I-0067 (20230427).docx
DOCX document 95 KB Posted
- Attached to
- Theater Battle Management Core Systems (TBMCS) Software Sustainment Engineering Support Federal contract opportunity
- Solicitation number
- M67854-23-I-0067
- Issued by
- United States Marine Corps
About this file
This performance work statement outlines the requirements for Theater Battle Management Core Systems software sustainment support services for the United States Marine Corps. The contractor shall provide quarterly software releases to maintain the current TBMCS baseline, with each release addressing cybersecurity vulnerabilities. The contractor must implement a software development process in accordance with CMMI Level 3, conduct unit and system testing of each release, and support government acceptance testing at multiple sites. Help desk support is required to resolve any issues with the current TBMCS software baseline. The contractor shall also establish a secure classified environment to perform the work and ensure all personnel meet cybersecurity certification and security clearance requirements. The anticipated one-year base period of performance includes two in-person meetings at Marine Corps bases and four government security assessments at another base.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| M67854-23-I-0067 - RFI Letter for TBMCS Replacement v3.docx | DOCX document | |
| M67854-23-I-0067 - RFI Letter for TBMCS Replacement v2.docx | DOCX document | |
| M67854-23-I-0067 - RFI Letter for TBMCS Replacement v2.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1
Performance Work Statement (PWS)
SCOPE
This Performance Work Statement (PWS) specifies the programmatic, technical, and logistics requirements, for the United States Marine Corps (USMC) Theater Battle Management Core Systems (TBMCS) Software Sustainment Support effort. This includes the engineering and implementation of solutions for the sustainment of USMC-specific configuration items identified in this PWS into products fully interoperable with the current joint TBMCS service maintenance release and future maintenance release baselines.
Background
The TBMCS, a United States Air Force (USAF) led program with Joint interest, serves as the focal point for Joint Air Warfare Command and Control (C2), integrating systems for planning, tasking, intelligence-gathering, and execution into a single, common interface. The TBMCS is the primary system for planning, managing, and executing the air battle; and for feeding real-time, decision-quality information to users in the Joint Forces Air Component Commander (JFACC) the staff at the Air Operations Center (AOC), and to pilots, navigators, and weapons control officers on the battlefield. The TBMCS links the command and control systems for the USAF, United States Navy (USN), and USMC, and integrates with United States Army (USA) ground systems, enabling coordinated, synchronized air battle management. The TBMCS is post Milestone C, in sustainment.
The USMC TBMCS Program is managed by the Program Manager (PM) Air Command and Control and Sensor Netting (AC2SN) Program Management Office (PMO) under the Program Executive Officer Land Systems (PEO LS), henceforth known as “Government”. The Government is responsible for the refresh and sustainment of USMC system (hardware and software) and associated training and documentation. The USMC TBMCS operational software requires specific support activities to include a release every quarter (90 days), that complies with the Government’s Cybersecurity Compliance requirements outlined in section 3.3.2 Cybersecurity Program and Requirements.
APPLICABLE DOCUMENTS
The following documents form a part of this PWS to the extent specified herein. The most recent revision of the referenced document at the time of contract award shall be used unless otherwise specified in a contract modification. In the event of conflict between the applicable documents and this PWS, the PWS shall take precedence. All second tier and below references cited in mandatory compliance documents shall be considered as guidance only. Nothing in this PWS, supersedes applicable laws and regulations unless a specific exemption has been obtained.
The specifications, standards, plans, drawings, data item descriptions, and other pertinent documents cited in this solicitation can be obtained from the online Acquisition Streamlining and Standardization Information System (ASSIST), http://quicksearch.dla.mil/qsSearch.aspx. Department of Defense (DoD) directives and instructions can be found at: http://www.esd.whs.mil/Directives/issuances/dodd/.
(Copies of ISO/IEC/IEEE/EIA 12207 and 15289 are available from www.ieee.org or www.iso.org)
Government Documents
| CCMB-2017-04-001 | Common Criteria for Information Technology Security Evaluation v3.1 R5 |
| CJCSI 6211.02D | Defense Information System Network (DISN) Responsibilities, 24 Jan 12 (current 4 Aug 15) |
| CJCSI 6510.01F | Information Assurance (IA) and Support to Computer Network Defense (CND), dtd 09 Feb 11 (current 9 Jun 15) |
| CNSSI 1253 | Security Categorization and Control Selection for National Security Systems, dtd 27 Mar 14 |
| CNSSP 11 | Committee on National Security Systems Policy - National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology Products, dtd 10 Jun 13 |
| DoD CIO Memo | DoD's Migration to Use of Stronger Cryptographic Algorithms, dtd 14 Oct 10 |
| DoDD 8140.01 | Cyberspace Workforce Management, dtd 5 Oct 20 |
| DoDI 5200.01 | DoD Information Security Program and Protection of Sensitive Compartmented Information (SCI), dtd 21 Apr 16 |
| DoDI 8140.02 | Identification, Tracking, and Reporting of Cyberspace Workspace Requirements, dtd 21 Dec 21 |
| DoDI 8500.01 | Cybersecurity, with Ch 1, dtd 07 Oct 19 |
| DoDI 8510.01 | Risk Management Framework (RMF) for DoD Systems, dtd 19 Jul 22 |
| DoDI 8520.02 | Public Key Infrastructure (PKI) and Public Key (PK) Enabling, dtd 24 May 11 |
| DoDI 8580.1 | Information Assurance (IA) in the Defense Acquisition System, dtd 9 Jul 04 |
| DoDM 5200.01-V1 | DoD Information Security Program: Overview, Classification, and Declassification, with Ch 2, dtd 28 Jul 20 |
| DoDM 5200.01-V2 | DoD Information Security Program: Marking of Information, with Ch 4, dtd 28 Jul 20 |
| DoDM 5200.01-V3 | DoD Information Security Program: Protection of Classified Information, with Ch 3, dtd 28 Jul 20 |
| DoD 5220.22-M | National Industrial Security Program Operating Manual |
| DoDM 8140.03 | Cyberspace Workforce Qualification and Management Program, dtd 15 Feb 23 |
| ECSM-018 | Marine Corps Assessment and Authorization Process, Version 6, dtd 06 Jun 20 |
| ECSM-021 | Ports, Protocols, and Services Management (PPSM), Version 1.0, dtd 15 May 12 |
| FIPS PUB 140-2 | Federal Information Processing Standards Publication – Security Requirements for Cryptographic Modules, dtd 3 Dec 02 |
| FIPS PUB 201-3 | Personal Identity Verification (PIV) of Federal Employees and Contractors, dtd Jan 22 |
| HSPD-12 | Homeland Security Presidential Directive – 12: Policy for a Common Identification Standard for Federal Employees and Contractors, https://www.dhs.gov/homeland-security-presidential-directive-12, dtd 27 Aug 04 |
| MARADMIN 371/13 | Requirement for Registration of Ports, Protocols, and Services Operating on the Marine Corps Enterprise Networks, dtd 24 Jul 13 |
| MARADMIN 051/16 | DoD Cybersecurity Scorecard: Updated Policy for Public Key Enablement (PKE) of All Marine Corps Enterprise Network (MCEN) Authorized Users, System Administrators, Privileged Users, and Non-Person Entities, dtd 2 Feb 16 |
| MARADMIN 185/16 | Updated Policy for Public Key Enablement (PKE) of all Marine Corps Enterprise Network (MCEN) Authorized Users and Privileged Accounts, dtd 01 Apr 16 |
| MIL-HDBK-61B (SE) | Configuration Management Guidance, dtd 7 Apr 20 |
| NISPOM | National Industrial Security Program Operating Manual, dtd 19 Aug 21 |
| NIST SP 800-30 R1 | Guide for Conducting Risk Assessments, dtd Sep 12 |
| NIST SP 800-53 R4 | Recommended Security Controls for Federal Information Systems and Organizations, dtd 22 Jan 15 |
| NIST SP 800-53A R4 | Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans, dtd 18 Dec 14 |
| NIST SP 800-60 Vol.1 R1 | Guide for Mapping Types of Information and Information Systems to Security Categories, dtd Aug 08 |
| NIST SP 800-60 Vol.2 R1 | Guide for Mapping Types of Information and Information Systems to Security Categories - Appendices, dtd Aug 08 |
| NIST SP 800-78-4 | Cryptographic Algorithms and Key Sizes for Personal Identity Verification, dtd May 15 |
| NIST SP 800-147 | BIOS Protection Guidelines, dtd Apr 11 |
| NIST SP 800-147B | BIOS Protection Guidelines for Servers, dtd Aug 14 |
| NIST SP 800-171 R2 | Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, dtd 28 Jan 21 |
| OMB M-11-11 | MEMO: Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, dtd 03 Feb 11 |
| SIAT-HDBK-003 | Marine Corps Systems Command Configuration Management Implementation Handbook, dtd 25 Feb 14 |
| PM AC2SN CMP | Configuration Management Plan dtd 20 May 22 (TBMCS Addendum) |
| TBMCS ISCM | Information System Continuous Monitoring Strategy Version 1.1.X, dtd Aug 20 |
| TBMCS-FL SCG | (CUI) TBMCS-Force Level (FL) Security Classification Guide, dtd 25 Jan 21 |
Non-Government Documents
ISO/IEC/IEEE 12207:2017(E) International Standard – Systems and Software Engineering – Software Life Cycle Processes, dtd Nov 17
Business Relations
The Contractor shall identify all key personnel and their responsibilities for the conduct of activities required under this contract. The Contractor shall assign responsibilities and define clear lines of authority for determining and controlling the resources necessary to deliver the requirements for this contract. The Contractor agrees to assign qualified personnel to the Key Personnel positions. No substitutes shall be made to Key Personnel without prior Government approval in accordance with section G.8. The key personnel positions are listed in section G.8.
REQUIREMENTS
Program Management/Data Requirements
Contract Data
The Contractor shall provide data items in accordance with (IAW) the DD1423s, Contract Data Requirements List (CDRLs), identified in the applicable paragraph in this PWS and listed in Section J of the contract.
Program Management
The Contractor shall establish and maintain program management practices throughout the life of this contract. These program management practices shall include, but not be limited to, visibility into the Contractor’s organization and techniques used in management of the program, including subcontractor and data management.
The Contractor shall plan and monitor the execution of all program tasks and shall maintain regular communications to keep the Government apprised of all program issues and status. The Contractor shall be accountable for ensuring all subcontractors are compliant with the terms and conditions of this contract. The Contractor shall submit a Monthly Status Report (MSR), to include the status of all action items from previous In-Process Reviews (IPRs) and/or Technical Interchange Meetings (TIMs) IAW CDRL B001.
CDRL B001, Contractor’s Monthly Status Report
Post Award Conference
The Contractor shall host a Post Award Conference (PAC) at the Contractor’s facility no later than 30 calendar days after Contract Award for the base year. Specific time and date for the PAC shall be coordinated with the Contracting Officer. During the PAC, the Contractor shall introduce key personnel, provide a thorough understanding of the schedule, present an understanding of the PWS and CDRLs, and identify areas that require clarification. The Contractor shall provide an agenda prior to the PAC, IAW CDRL B002, prepare briefing material IAW CDRL B003, and provide meeting minutes IAW CDRL B004.
CDRL B002, Conference Agenda CDRL B003, Briefing Material CDRL B004, Meeting Minutes
Integrated Master Schedule (IMS)
The Contractor shall maintain and deliver a contract level IMS for all efforts performed under this contract. The Contractor shall provide the IMS, to the Government for review and approval IAW CDRL B005. The IMS shall be baselined no later than 30 calendar days following completion of the PAC. The draft IMS shall be revised and presented at the PAC. The Government will provide key milestones from the Government IMS to the Contractor. After baseline, the IMS will be delivered monthly for Government review in conjunction with the Contractor’s Monthly Status Report. Changes to the Government test and field kit delivery milestones in the baseline IMS will be made only with Contracting Officer Representative (COR) approval. All contract tasking shall be managed using the IMS.
CDRL B005, Integrated Master Schedule (IMS)
Contractor Meeting Facilities
The Contractor shall provide CLASSIFIED and UNCLASSIFIED meeting facilities. The meeting facility shall accommodate up to 20 participants, be capable of projecting SECRET briefings, and provide secure storage for laptops, cell phones, and other UNCLASSIFIED electronic devices outside of the CLASSIFIED meeting room. The Contractor shall provide Defense Information Security System (DISS)/Security clearance verification and provide sign-in/attendance roster for all participants.
Contractor Participation in Meetings
The Contractor shall host, support, and participate in program status update teleconferences, IPRs, TIMs, Cyber Adjudication Meetings (CAM), Software Build Status Review, and Software/System Change Review Board (SCRB) meetings. The Contractor shall support and participate in USMC TBMCS Configuration Control Boards (CCBs), Engineering level IPTs, Test Readiness Review (TRR), and Discrepancy Test Review Groups (DTRG).
Program Status Update Teleconferences
The Contractor shall host program status update teleconferences every other week, planned to be no longer than one hour and shall provide the phone bridge. More frequent program status update teleconferences may be required for special interest projects. The day of the week for the teleconferences will be determined during the PAC. Program status update teleconferences shall focus on ensuring an understanding of the current Cybersecurity requirements and current status of software sustainment efforts. Program status update teleconferences shall address implementation approaches for software updates, including relevant Engineering Change Proposals (ECPs), the status of action items from quarterly IPRs and TIMs, and Helpdesk activity status updates. Action items resulting from the program status update teleconference shall be included in the contractor’s MSR, CDRL B001.
CDRL B001, Contractor’s Monthly Status Report
In-Process Reviews (IPRs)
IPRs shall be held quarterly at dates and locations agreed to in advance by the Government. The initial IPR shall be conducted at the Contractor’s facility no later than 90 days after PAC. Subsequent IPRs are anticipated to be conducted equally between the Contractor’s facility and the Government’s designated location. The areas addressed at the IPR shall include, but not be limited to, schedule and performance, management issues, risk (schedule and performance) identification and resolution, opportunities, and Integrated Product Team results. The agenda will be approved by the Government in advance. Additionally, Government representatives will conduct Government-Furnished Property (GFP) inventory inspections during IPR visits to the Contractor facility. The Contractor shall provide a phone bridge capable of accommodating a minimum of 10 users. The Contractor shall provide an agenda prior to each IPR IAW CDRL B002, prepare briefing material IAW CDRL B003, and plan a review of the latest version of the IMS IAW CDRL B005, and provide meeting minutes for each review IAW CDRL B004. The Contractor shall track Action Items in the MSR IAW CDRL B001.
CDRL B001, Contractor’s Monthly Status Report CDRL B002, Conference Agenda CDRL B003, Briefing Material CDRL B004, Meeting Minutes CDRL B005, Integrated Master Schedule (IMS)
Technical Interchange Meetings (TIMs)
The Contractor shall conduct TIMs quarterly, TIMS and IPRs shall be held together whenever possible. Meetings may be held at either Contractor or Government designated facilities or may be conducted by telephone. The purpose of a TIM is to discuss specific technical activities, including action items, test plans, test results, design issues, technical decisions, cybersecurity issues, and implementation concerns to ensure continual visibility by the Government into the Contractor’s technical progress. The Contractor shall provide an agenda prior to each TIM IAW CDRL B002, prepare briefing material IAW B003 (when the topic of discussion is of a complex technical nature per the government), and provide meeting minutes for each meeting IAW CDRL B004. The Contractor shall track Action Items in the MSR IAW CDRL B001.
CDRL B001, Contractor’s Monthly Status Report CDRL B002, Conference Agenda CDRL B003, Briefing Material CDRL B004, Meeting Minutes
Cybersecurity Adjudication Meetings (CAMs)
The Contractor shall conduct CAMs 20 business days after the completion of every Government Security Assessment (SA). Meetings will be held at Contractor facilities at the appropriate classification level per the Security Classification Guide (SCG). The purpose of the CAM is to review cybersecurity vulnerabilities for resolution and to identify a specific software release for each fix to be applied. The Government shall provide an updated Living Plan of Action and Milestones (POA&M) no later than 10 business days prior to the CAM. The Contractor shall review the Living POA&M and provide mitigation statements, comments, and proposed software release for fix to be applied for reviewed during the CAM. The Contractor shall deliver an updated copy of the Living POA&M IAW CDRL A001 to the Government at the conclusion of each CAM.
CDRL A001, Living POA&M
Configuration Control Board (CCB)
The Contractor shall support and participate in monthly CCB meetings via teleconferences by providing a non-voting member to the CCB. More frequent CCB meetings may be required for emergent issues that need to be addressed between the scheduled monthly CCB meetings. The Contractor support and contributions to the CCB shall focus on software bugs and change requests originating from software Bugs/Change Requests, Test Problem Reports (TPRs), Baseline Change Requests (BCRs), or Problem Change Requests (PCRs) submitted to the CCB. The Contractor shall also support CCB discussions regarding Engineering Change Proposals (ECPs) related to TBMCS software and hardware changes.
Software/System Change Review Board (SCRB)
The Contractor shall support and participate in a SCRB once per week. The Contractor shall chair the SCRB. The SCRB will address any deficiencies discovered during the development cycle of a software release. The Contractor shall use a defect tracking system to document and track all deficiencies discovered during the software development process.
Discrepancy Test Review Group (DTRG)
The Contractor shall support and participate in a DTRG in conjunction with the conduct of Government Acceptance Testing (GAT). The Government led DTRG will review and categorize all PCRs generated during a GAT, assigning category and priority numbers per the AC2SN Configuration Management Plan (CMP).
Configuration Management (CM)
The Contractor shall maintain configuration control for 1.1.X.X products developed under this contract. The Contractor’s Configuration Management (CM) process shall be implemented in accordance with the Contractor’s CM Plan incorporated by reference. The Contractor’s CM Plan shall align with the AC2SN CM Plan, SIAT-HDBK-003, and MIL-HDBK-61A.
Quality Assurance
The Contractor shall establish and implement a quality assurance program using best commercial practices that ensures quality throughout all areas of performance, to include inspection, test, maintenance, and preparation for delivery and shipping. The Performance Requirements Summary Matrix, contained in the Quality Assurance Surveillance Plan (QASP), (Section J Attachment 2), provides performance standards. The Government shall use these standards to determine contractor performance and shall compare contractor performance to the Acceptable Quality Level (AQL).
Data Management
The Contractor shall maintain and deliver a Data Accession List (DAL) to the Government IAW CDRL B006. The Contractor shall maintain DAL items and access throughout the life of the contract, to include but not be limited to, all necessary technical data (e.g., requirements, specifications, drawings [conceptual design, development design, product], engineering notebooks, parts lists, etc.), management plans and updates thereto, and delivered CDRLs. The Contractor will mark all media and documentation as US Only.
CDRL B006, Data Accession List
Government Furnished Property (GFP)
The Contractor shall account for all GFP, (Section J Attachment 3), IAW the requirements of the Defense Federal Acquisition Regulation Supplement (DFARS). The Contractor shall provide accurate accounting for tracking the movement, storage, and reporting of GFP using Procurement Integrated Enterprise Environment (PIEE). The Contractor shall assist the Responsible Officer (RO) / Responsible Individual (RI) with the acquisition, distribution, storage, and management of all GFP related to the TBMCS effort, including maintaining and updating GFP inventory records. All GFP shall be inventoried, inspected, cleaned, stored, and accounted for in the GFP module in Procurement Integrated Enterprise Environment (PIEE) and in a manner consistent with Federal Acquisition Regulation (FAR), clause 52.245-1 (f) (iii).
The Contractor shall conduct a quarterly GFP inventory and report any changes. The contractor shall support an annual physical inventory of all GFP with the Responsible Officer (RO) / Responsible Individual (RI). Preventive maintenance and inspection shall be performed IAW applicable technical manuals (TMs) and/or industry accepted practices. The Contractor shall submit a quarterly GFP report IAW CDRL D001. The GFP report shall contain the information required by the Federal Acquisition Regulation (FAR), clause 52.245-1 (f) (iii). Inventory lists of GFP shall be submitted in separate categories as set forth in the FAR/DFARS, including separate lists for controlled cryptographic equipment items. The Contractor shall identify and report any discrepancies and/or deficiencies, to include associated costs (materials, labor and test, if applicable) for repair of the GFP to the Government and as part of the quarterly GFP report. The Government will be responsible for providing direction on approach for any required repairs. The Contractor shall use Government property, either furnished or acquired under this contract, only for performing this contract, unless otherwise approved in a separate writing by the Contracting Officer’s Representative (COR).
CDRL D001, Status of Government Furnished Property (GFP) Report
Disposal of GFP
The contractor shall be responsible for disposal of GFP inventory as prescribed in DFARS 252.245-7004 (Deviation 2022-O0006). The Contractor shall provide disposition recommendations to the COR after conducting reviews of the TBMCS GFP inventory. In the event of a disposition, the Contractor should request direction from the Lead Logistician whether to use the Plant clearance disposition or to utilize DLA’s disposition services.
Upon approval, the Contractor will request documentation for Issue Release/Receipt documentation from the TBMCS Lead Logistician, currently USMC issued DD-1348(s). Upon receipt the Government will schedule a turn-in appointment with the approved Disposition Service. The Contractor shall prepare and affix any documentation requested by the Disposition Service, and the Contractor shall transport the assets to the approved facility at the scheduled date and time. Upon turnover of physical custody of assets, the Contractor will provide the signed DD-1348(s) to the TBMCS Lead Logistician within 3 business days of acceptance by the dispositioning activity.
Classified Laboratory Environment
The Contractor shall provide a SECRET CLASSIFIED laboratory environment IAW the DoD Contract Security Classification Specification (DD Form 254) (Section J Attachment 4) to support the specific tasks outlined in this contract.
Security Clearance and Access Requirements
Secret Facility Clearance
This contract will require the contractor to have a Secret Facility Clearance and will require certain contractors to obtain and maintain classified access eligibility. The contractor shall have a valid Secret Facility Clearance and a Secret Safeguarding Level prior to classified performance. The prime contractor and all sub-contractors (through the prime contractor) shall adhere to all aspects of 32 CFR Part 117 NISPOM. All personnel identified to perform on this contract shall maintain compliance with Department of Defense, Department of the Navy, and Marine Corps Information and Personnel Security Policy to include completed background investigations (as required) prior to classified performance. This contract shall include a DoD Contract Security Classification Specification (DD-254) as an attachment. Certain contractors will be required to perform IT-I/II duties that will require favorably adjudicated Tier 5/3 Level investigations. The Defense Counterintelligence and Security Agency (DCSA) will not authorize contractors to submit the necessary Tier Level investigations solely in support of IT level designation requirements but are required to submit investigations for those employees requiring both Secret access and IT-II designation. The Facility Security Officer (FSO) is however required to establish, populate, and own the DISS record of every contractor processed for and/or issued a Common Access Card (CAC) or submitted for IT level duties. The Government Contracting Activity Security Office (GCASO) is required to submit any required investigations in support of IT-I level designations. The contractor is required to provide a roster of prospective contractor employees performing IT-I duties to the MARCORSYSCOM Contracting Officer’s Representative (COR). This roster shall include full names, Social Security Numbers, e-mail address and phone number for each contractor requiring investigations in support of IT Level designations. The COR will verify the IT-I requirements and forward the roster to the GCASO. Contractors found to be lacking required investigations will be contacted by the GCASO.
In accordance with DoDI 5200.48, “Controlled Unclassified Information (CUI),” all contractors supporting MARCORSYSCOM who receive, store, or generate CUI are required to take the DoD Mandatory CUI Training, available on the Security Awareness Hub at: https://securityawareness.usalearning.gov/cui/index.html. Per DoDI 5200.48 and pursuant to contractual requirements, DoD contractors require initial CUI training and annual CUI refresher training. Additional MARCORSYSCOM specific CUI training and guidance can be attained by contacting the MARCORSYSCOM Security Classification Management Office at 703-432-3141 / 3140 or MCSC_ACSG2_SCMO@usmc.mil.
While performing aboard NAVY/USMC sites, the contractor shall comply with the provisions of DoD Directive 5205.02E, “DoD Operations Security (OPSEC) Program,” SECNAVINST 3070.2A, “Operations Security,” MCSCO 3070.1B, “Operations Security Program,” Marine Corps Order 3070.2A, “The Marine Corps Operations Security (OPSEC) Program,” and the MARCORSYSCOMO P5510.2C, “Security Manual,” at all other sites the contractor shall comply with the local command and/or program OPSEC plan. Contractor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information, personnel, facilities, equipment, and operations from compromise. All Contractors (including Subcontractors) shall supplement their current security practices by requiring any personnel involved in executing this contract to complete Government-sponsored and administered OPSEC training.
The FSO’s are responsible for notifying the MARCORSYSCOM Personnel Security (PERSEC) Office at 703-432-3952/3490/3374 if any contractor on this contract receives an unfavorable adjudication. Any issued CAC would need to be Revoked and Retrieved. Due to Insider Threat concerns, the FSO is also requested to notify the PERSEC Office, within 24 hours of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor performing on this contract, if they have been granted an IT designation, issued a CAC and/or a MARCORSYSCOM building badge. The FSO shall notify the Government (written notice) within 24 hours of any contractor personnel added or removed from the contract that have been granted IT designations, issued a CAC and/or a MARCORSYSCOM building badge.
SIPRNET will not be provided or required with the execution of this contract.
Common Access Cards (CACs)
The COR will identify and only approve those contractor employees performing on this contract that require a CAC in order to perform their job function. In accordance with Headquarters, United States Marine Corps issued guidance relative to Homeland Security Presidential Directive – 12 (HSPD-12), all personnel must meet eligibility criteria to be issued a CAC. In order to meet the eligibility criteria, contractor employees requiring a CAC must obtain and maintain a favorably adjudicated Personnel Security Investigation (PSI). Prior to authorizing a CAC, the employee’s Defense Information System for Security (DISS) record must indicate a completed and favorably adjudicated PSI or (at a minimum) that a PSI has been submitted and accepted (opened). The minimum acceptable investigation is a T-1 or a National Agency Check with Written Inquiries (NACI). If a contractor employee’s open investigation closes and is not favorably adjudicated, the CAC must be immediately retrieved and revoked. CACs are not issued for convenience.
Facility Security Officers (FSOs) are responsible for notifying the MCSC Personnel Security Office (PERSEC Office) at 703-432-3490/3952 if any contractor performing on this contract receives an unfavorable adjudication after being issued a CAC. Due to Insider Threat concerns, the Company is requested to notify the MCSC Personnel Security Office (PERSEC Office) at 703-432-3952/3490/3374, within 24 hours, of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor performing on this contract, if they have been issued a CAC and/or a MCSC Building Badge.
Each CAC is issued with a “ctr@usmc.mil” e-mail account that the individual contractor is responsible to maintain as active by logging in on a regular basis (at least twice a month), sending an e-mail and clearing any unneeded e-mails. Contractors issued a CAC are prohibited from “auto- forwarding” e-mail from their .mil e-mail account to their .com e-mail account. If the “ctr@usmc.mil” e-mail account is not kept active, G-6 will deactivate the account and the CAC will also lose its functionality. Contractor employees shall solely use their government furnished “ctr@usmc.mil” e-mail accounts for work supporting the USMC, conducted in fulfillment of this contract, and shall not use a contractor supplied or personal e-mail account to conduct official U.S. government business. The use of a contractor or personal e-mail account for contractor business or personal use is allowed, but only when using cellular or a commercial internet service provider.
If a contractor loses their eligibility for a CAC due to an adverse adjudicative decision, they have also lost their eligibility to perform on MCSC contracts.
Marine Corps Enterprise Network (MCEN) Computer Access Contractor personnel accessing Marine Corps Systems Command Information Systems must maintain compliance with United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide. Contractor personnel will submit a DD 2875 and a completion certificate for the CYBERC course located on MarineNet located at https://www.marinenet.usmc.mil. The CYBERC course consist of the DOD Cyber Awareness Challenge and the Department of the Navy Annual Privacy Training (PII). Contractors will have to create a MarineNet account in order to complete the required training.
MCEN IT resources, if provided, are designated for official use only and other limited authorized purposes. DOD military, civilian personnel, consultants, and contractor personnel performing duties on MCEN information systems may be assigned to one of three position sensitivity designations.
1) ADP-I (IT-1): Favorably adjudicated T-5, T5R, (formerly known as Single Scope Background Investigation (SSBI)/SSBI Periodic Reinvestigation (SBPR)/SSBI Phased Periodic Reinvestigation (PPR))
2) ADP-II (IT-2): Favorably adjudicated T-3, T3R, (formerly known as Access National Agency Check and Inquiries (ANACI)/ National Agency Check with Law and Credit (NACLC)/Secret Periodic Review (S-PR))
3) ADP-III (IT-3): Completed T-1, (formerly known as National Agency Check with Inquiries (NACI))
Privileged users must maintain the baseline Cyberspace Workforce Information Assurance Technical (IAT) or Information Assurance Manager (IAM) relating to the position being filled. Privileged users are defined as anyone who has privileges over a standard user account as in system administrators, developers, network administrators, code signing specialist and Service Desk technicians.
All MCEN users must read, understand, and comply with policy and guidance to protect classified national security information, Controlled Unclassified Information (CUI), and prevent unauthorized disclosures in accordance with United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide and CJCSI 6510.01F.
MCEN Official E-mail usage MCEN IT resources are provided for official government use only and other limited authorized purposes. Authorized purposes may include personal use within limitations as defined by the supervisor or the local Command. Auto forwarding of e- mail from MCEN-N to commercial or private domains (e.g., Hotmail, Yahoo, Gmail, etc.) is strictly prohibited. E-mail messages requiring either message integrity or non-repudiation are digitally signed using DOD PKI. All e-mail containing CUI, an attachment, or embedded active content must be digitally signed.
MCEN users will follow specific guidelines to safeguard CUI, which includes Personally Identifiable Information (PII) and Health Insurance Portability and Accountability Act (HIPAA) information. Non-official e-mail is not authorized for and will not be used to transmit any CUI. Non-official e-mail is not authorized for official use unless under specific situations where it is the only means for communication available to meet operational requirements. This can occur when the official MCEN provided e-mail is not available but must be approved prior to use by the Marine Corps Authorizing Official (AO).
All personnel will use DOD authorized PKI certificates to encrypt e-mail messages if they contain any of the following:
1. Controlled Unclassified Information (CUI).
2. Any contract sensitive information that normally would not be disclosed to anyone other than the intended recipient as this is considered CUI.
3. Any privacy data, PII, or information intended for inclusion in an employee’s personal file or any information that would fall under the tenets of MSGID: DOC/5 USC 552A. Personal or commercial e-mail accounts are not authorized to transmit unencrypted CUI.
4. Any medical or health data, to include medical status or diagnosis concerning another individual.
5. Any operational data regarding status, readiness, location, or deployment of forces or equipment.
Magnetic Hard Drive Storage Devices This paragraph covers the requirements of classified and unclassified internal and removable magnetic and solid state hard drives that store Government data. This includes, but is not limited to, storage area network (SAN) devices, servers, workstations, laptops/notebooks, printers, copiers, scanners and multi-functional devices (MFD) with internal hard drives, removable hard drives and external hard drives. Upon disposal, replacement, turn in of hard drives or completion of the contract, non-Government owned internal\external hard drives shall become the property of the U.S. Government in accordance with GENADMIN Processing of Magnetic Hard Drive Storage Media for Disposal.
Engineering
Software Engineering
The Contractor shall define a software engineering approach appropriate for TBMCS software sustainment activities to be performed under this contract. This approach shall be documented in a Software Development Plan (SDP) IAW CDRL A002. The SDP shall define the Contractor’s proposed life cycle model and the processes used as a part of the model. In this context, the term “life cycle model” is a defined in IEEE/EIA Std. 12207.2017(E). The SDP shall describe the overall life cycle and shall include primary, supporting, and organizational processes based on the work content of this PWS. In accordance with the framework defined in IEEE/EIA Std. 12207. 2017(E), the SDP shall define the processes, the activities to be performed as a part of the processes, the tasks supporting the activities, and the techniques and tools to be used in performing the tasks. In all cases, the level of detail shall be sufficient to define all software sustainment processes, activities, and tasks to be conducted. Information provided must include, at a minimum, the specific standards, methods, tools, actions, strategies, and responsibilities associated with software development and qualification.
CDRL A002, Software Development Plan (SDP)
Capability Maturity Model Integration Level (CMMI)
The Contractor shall, at a minimum, be certified and adhere to CMMI Level 3 standards at the facility where the work is being performed and the Contractor shall use existing Government standards that are referenced in PWS Section 2.0, Applicable Documents.
Software Releases
The current TBMCS software baseline is Version 1.1.6.X.X. The Contractor shall deliver the software releases on a quarterly release cycle (one release every 90 days). All software deliveries shall be cybersecurity compliant IAW with Section 3.3.2. The first software delivery shall be no later than 60 days after contract award.
The Contractor shall establish a battle rhythm of releasing software builds every 90 days. Each delivered software release shall contain segments of Cybersecurity updates to address Information Assurance Vulnerability Alerts/Information Assurance Vulnerability Bulletins (IAVA/IAVB), and Operational Directives (OPDIRs). Software deliveries shall include all software/firmware updates, including security patches, for all Operating Systems (OS), Commercial Off-The-Shelf (COTS), and Government Off-The-Shelf (GOTS) products unless said patches break system functionality. If a vendor update breaks system functionality, the Contractor shall provide a detailed explanation of what functionality was broken and why said update cannot be installed. Software kits, CDRL A003 shall be provided for each software release. Additionally, the contractor shall provide a Version Description Document (VDD) IAW CDRL Item A004. The contractor shall develop and provided a Network Design Document (NDD) IAW CDRL Item A005. The NDD shall include the Authorization Boundary Diagram. The Authorization Boundary Diagram shall include device labels, internal IP addresses, software (SW)/ firmware (FW)/internal operating system (IOS) versions, ports, protocols, and boundary labels, physical connections, logical connections, authorization boundary, date last updated, and a legend.
CDRL A003, Software Kit CDRL A004, Version Description Document CDRL A005, Network Design Document
Content for software releases shall be presented by the Contractor during a SCRB. The Contractor shall then assist the Government engineering team with the development of an Engineering Change Proposal (ECP) for presentation to a Government chaired CCB to attain prior approval of each proposed software build prior to commencement of development activities on subject software build. The Contractor will receive content approval at least one week prior to the planned IMS start date of the software release and upon approval from the Government’s CCB, the software release content will be locked down. The contractor shall minimize software installation times based upon mutually agreed to content and approval from the Government CCB.
The software releases shall not result in any Priority 1 or 2 deficiencies or a loss of capability from the current USMC TBMCS software baseline. The software shall retain existing backwards/forwards compatibility between the current USMC TBMCS software baseline and joint service TBMCS configurations. The Contractor shall execute all tasking in a manner that precludes degradation from current TBMCS system functionality and maintains all system interface exchange requirements. The software shall maintain releasable software status with the exception of products that have already been identified as US Only, as defined in the SCG.
Help desk tickets which require software fixes shall have a PCR generated. PCRs shall be categorized in accordance Table 3-1, Software Priority Definitions. Final categorization of PCRs will be determined by the Government through CCB action.
Related to PCRs identified from the helpdesk which require software fixes, the Contractor shall provide an analysis of the problem and proposed fix, to include estimated number of hours required and schedule, within 48 hours of the determination that a Priority 1 or 2 deficiency in the fielded software problem exists. The Government will review the analysis and determine the appropriate course of action.
Software Fielding Kit
The Contractor shall deliver 22 fielding kits for each software release IAW CDRL A003. Shipping location will be provided IAW government direction.
CDRL A003, Software Fielding Kits
Software Configuration Control
The Contractor shall implement and maintain the Software Configuration Management (SCM) process for the TBMCS software providing baseline control of all software and software-related products. The Contractor shall document the baseline control in the SSP, consistent with the TBMCS Addendum to the PM, AC2SN Configuration Management Plan (CMP); and shall include implementation of a change control management process that can track the “as-installed” software configuration for each USMC TBMCS.
Data Rights
The Government shall have Unlimited Rights in all software and software documentation developed under this contract, IAW the DFARS clauses 252.227-7013 (Rights in Technical Data-Non-Commercial Items) and 252.227-7014 (Rights in Noncommercial Computer Software and Noncommercial Computer Documentation). For any pre-existing component of software, and related documentation, whose development has been exclusively funded by the contractor and which is to be included in new software to be incorporated into the TBMCS program, the contractor will provide a proper and timely post award assertion of restrictions listing, per subsection (e) of DFARS 252.227-7014 and 252.227-7013.
Contractor Acceptance Test
The Contractor shall perform Contractor Acceptance Test that verifies the software load process and includes functionality testing, to include backwards/forwards compatibility testing with joint service TBMCS configurations of each software release. The Contractor shall support Government observers during Contractor Acceptance Test.
Government participation in Contractor Acceptance Test will be conducted in accordance with CDRL B005 IMS.
The Contractor shall complete final Contractor Acceptance Test with no unresolved Priority 1 or 2 software defects (trouble Reports (bugs), TPR, or PCR). Prioritization of deficiencies shall be IAW the following table 3-1.
Table 31 Software Priority Definitions
| USMC Priority |
| Priority |
| Impact |
| 1b |
| Emergency |
| If uncorrected, may cause death, severe injury, or severe occupational illness and no workaround is known |
1b
If uncorrected, may cause major loss or damage to equipment or a system and no workaround is known
1a
Prevents the accomplishment of an essential capability or critically restricts occupational safety, suitability and effectiveness, to include required interaction with other mission critical platforms or systems; and no workaround is known
| 2a |
| Urgent (I) |
| Adversely affects an essential capability or negatively impacts operational safety, suitability or effectiveness and no acceptable workaround is known. |
2b
Adversely affects technical, cost, or schedule risks to the project or to life cycle support of the system, or results in a production line stoppage and no acceptable workaround is known.
| 3a |
| Urgent (II) |
| Adversely affects an essential capability or negatively impacts operational safety, suitability, or effectiveness and adequate performance is achieved through significant compensations or acceptable workaround. |
3b
Adversely affects technical, cost, or schedule risks to the project or to life cycle support of the system, but an acceptable workaround is known.
4a
Does not affect an essential capability but may result in user/operator inconvenience or annoyance. Adequate performance is achieved through minimal compensation.
4b
Results in inconvenience or annoyance for development or maintenance personnel but does not prevent the accomplishment of the task. Adequate performance is achieved through minimal compensation.
Any other effect, i.e., enhancements having little or no impact to occupational safety, suitability or effectiveness under current conditions.
Upon the conclusion of final contractor testing, the Contractor shall provide a test report and software readiness brief detailing the results of contractor testing IAW CDRL A006, to include all identified issues in the form of bugs categorized using the Severity definitions in this document in Table 3-1. The results of the Contractor’s Acceptance Test will be used as one of the data points for entering Government testing.
At the conclusion of successful Contractor acceptance Test the Contractor shall provide Software Kit IAW CDRL A003 and VDD IAW CDRL A004. The Software Kits (A003) shall be provided to the Government Acceptance Test sites identified in paragraph 3.3.1.6.
CDRL A003, Software Fielding Kits CDRL A004, Version Description Document CDRL A006, Contractor Test Report
Government Acceptance Test Support
The results of the Contractor tests shall inform the Government Acceptance Test Readiness Review (TRR). The Contractor shall support a GAT on each release with on-site personnel for on-site analysis of discovered software issues for each software release. Government acceptance testing will include the joint services to ensure continued interoperability and backwards/forwards compatibility and will be conducted on each software release. The Contractor shall provide support to the GAT consisting of one week each for each release. GAT will be conducted at Langley AFB, VA and Marine Corps Tactical System Support Activity, (MCTSSA), Camp Pendleton, CA.
Government Acceptance Test Outcomes
GAT events shall result in no Priority 1 or 2 PCRs. The Contractor shall not make any software modifications without presentation of the change at the SCRB and receipt of Government approval. Any functionality changes made to software may require regression testing IAW PWS section 3.3.1.2.
The final release media kit will be delivered in support of the GAT event. No further software, documentation or media kit production is required unless a critical redline to the load guide or priority 1 or 2 software defect (PCR) is identified during the GAT event. Non-critical redlines will be accomplished in the next release. Critical redlines must be incorporated and validated during the Government Acceptance Test event.
Other Government Support
The Government shall assist the Contractor in obtaining Public Key Infrastructure (PKI) products (Axway, Tumbleweed, 90Meter), Cisco IOS, Firmware, and Assured Compliance Assessment Solution (ACAS)). The Government will provide the Contractor with required hardware and software as required to maintain the system baseline and evaluate interfaces. The Government will provide the Contractor with JITC SIPR test tokens to support evaluation of the PKI implementation. The Government will provide approval to procure the commercial code signing certificates. The Contractor shall incorporate the need dates for each item into their IMS.
CDRL B005, Integrated Master Schedule (IMS)
Cybersecurity Program and Requirements
The Contractor shall comply with DoD cybersecurity references listed in Section 2.0. The Contractor shall ensure personnel supporting cybersecurity functions obtain the appropriate DoD-approved baseline certification/educational level for INTERMEDIATE software development along with Computing Environment (CE) certifications for the operating system(s) and/or security related tools/devices they support IAW DoDM 8140.03. The Contractor shall provide the Government copies of the cybersecurity workforce certifications for personnel assigned to this task. The Contractor shall ensure COTS IA and IA-Enabled Information Technology Products are procured as described in:
· DoD Instruction 8500.01 - Cybersecurity
· CNSSP 11 - National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology Products
The Contractor shall ensure COTS IA and IA-Enabled Information Technology Products are evaluated and validated IAW:
· ISO/IEC 15408-1 – Information Technology – Security Techniques – Evaluation Criteria for IT Security
· CCMB-2017-04-001 - Common Criteria for Information Technology Security Evaluation
· FIPS PUB 140-2 – Security Requirements for Cryptographic Modules
The Contractor shall maintain the SHA-256 compliance to the extent practical given legacy system backward and forward compatibility requirements IAW:
· NIST SP 800-78-4, Cryptographic Algorithms and Key Sizes for Personal Identity Verification)
· Homeland Security Presidential Directive 12 (HSPD-12) Policies for a Common Identification Standard for Federal Employees and Contractors
· FIPS Pub 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors
· OMB M-11-11, Continued Implementation of HSPD-12 for a Common Identification Standard for Federal Employees and Contractors
· DoD-CIO Memo, DoD's Migration to Use of Stronger Cryptographic Algorithms
The Contractor’s software release shall be compliant to the extent practical given legacy system backward and forward compatibility requirements with:
· DoDI 8520.2, Public Key Infrastructure (PKI) and Public Key Enabling
· MARADMIN 051/16, DoD Cybersecurity Scorecard: Updated Policy for Public Key Enablement (PKE) of All Marine Corps Enterprise Network (MCEN) Authorized Users, System Administrators, Privileged Users, and Non-Person Entities
· MARADMIN 185/16, Updated Policy for Public Key Enablement (PKE) of all Marine Corps Enterprise Network (MCEN) Authorized Users and Privileged Accounts
Deviations from compliance with specified documents will be documented in the Living POA&M and with the COR.
The Contractor's software release, delivered IAW CDRL A003, shall implement recommended Basic Input/Output System (BIOS) protections guidelines IAW NIST SP 800-147 and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .