Attachment 0003 - Statement of Work (SOW) dated 23 April 2024.pdf
PDF 164 KB Posted
- Attached to
- M8 Smoke Pot Metal Components IDIQ Federal contract opportunity
- Solicitation number
- W519TC-23-R-0107
About this file
This document is a Statement of Work (SOW) for the manufacture and delivery of metal components for the M8 smoke grenade. The key details are:
The contractor shall fabricate, assemble, test, and pack each metal component per the applicable drawings, specifications, and contract requirements. The SOW specifies the applicable documents, including technical data package listings, specifications, and military standards. It outlines requirements for configuration management, design changes, supplier control, quality assurance, first article testing, lot acceptance testing, packaging and marking, and security requirements. The SOW also contains details on meetings, inspection and acceptance, measurement system evaluation, critical characteristics, and ammunition data cards.
The related federal contract opportunity is a 5-year Firm-Fixed Price Indefinite Delivery, Indefinite Quantity (IDIQ) contract solicitation for the metal parts and components for the M8 smoke pot, issued by the Army Contracting Command Rock Island as a 100% Small Business Set-Aside under NAICS code 332999. The solicitation closes on June 14, 2024.
View the file
Other files for this federal contract opportunity
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
For
M8 Metal Components
C.1.0 Scope. The Contractor shall manufacture and pack each metal part component specified in the contract and deliver as per the directions in the contract. The quantity of each metal parts component and its delivery schedule are specified in the contract.
C.1.1 Background. The metal parts components are manufactured to meet the requirements in the applicable specifications listed in section C.2.0 below. The material is manufactured to create the top, body and additional metal parts components needed to produce smoke grenades. The metal parts for the smoke grenades are needed to house the smoke mix and dyes and serve as the structure of the grenade.
C.2.0 Applicable Documents.
The following Drawings, Specifications and Documents will be applicable to this procurement.
• M8 Technical Data Package Listing (TDPL) 20190008: 81361 TDPL to include but not limited to the following:
o 36-2-226 Rev P - Container only -30 configuration o 36-2-225 Rev F– Gasket o 36-2-127 Rev R – Clamp o 36-2-313 Rev A with NOR Y76-0093-004 – Clamp o 36-2-227 Rev H - Cover, Inner Assembly o 36-2-228 Rev H - Cover, Inner o 36-2-128 Rev M - Cover, Outer o 36-2-312 Rev D - Fuze Adapter o 36-2-133 Rev M – Handle o 36-2-193 Rev K - Lug, Handle o 36-1-316 Rev E - Plug, Closure o EA-S-1805 Rev C AM 1 – Detail Specification Smoke Pot, Practice, M8 o AN316-12 – Nut, Jam, Hexagon
• Engineering Change Proposal (ECP) Y76-0081/NOR Y76-0081-001
• MIL-DTL-1353 Rev G Amendment 3 with NOR 934-0001-009 – Grenades, Hand, Inert Component
• MIL-HDBK-61B, Configuration Management dated 07 April 2020
• MIL-STD-1168C with Notice 1, Ammunition Lot Numbering & Ammunition Data Cards dated 21
February 2019
• MIL-STD-129R with Change 3, Marking for Shipment and Storage dated 25 February 2023
• MIL-STD-147E with Change 2, Standard Practice: Palletized Unit Loads dated 27 June 2019
• MIL-HDBK-781A, Reliability Test Methods, Plans, and Environments for Engineering Development, Qualification and Production with Notice 1 dated 30 January 2015
• MIL-PRF-61002C, Labels, Pressure-Sensitive Adhesive, for Bar Coding with 10 January 2023
• ISO 9001:2015
C.3.0 Requirements.
C.3.1 General. The Contractor shall fabricate, assemble, test, and pack each component IAW applicable drawings, specifications, and contract, inclusive of all approved Engineering Change Proposals (ECPs) and schedule, as detailed in the contract. The Contractor shall acquire and maintain facilities and equipment to provide Production, Engineering, and Quality Assurance/Reliability personnel necessary to meet the requirements of the contract.
C.3.2 Certification of Producibility. The Contractor shall review the Detailed Specifications for each metal parts component to identify any problem areas that would be detrimental to production and propose corrective actions through the Integrated Product Team (IPT) process. The Contractor’s analysis shall focus on eliminating inconsistencies in the Detailed Specifications related to omissions, errors, and specific elements of producibility, both stated and implied, to include materials, processes, packaging, testing, and single point failures. The analysis shall address any design feature that can be revised/broadened to simplify/improve assembly or performance. The
Contractor’s review of the Detailed Specifications shall include all drawings, hazardous component safety data sheets, item specifications, and associated quality provisions and acceptance requirements. The Contractor shall certify to the Government Procurement Contracting Officer (PCO) as per DI-MISC-82386 A001 that the Detailed
Specifications, including all components, assemblies, and parts thereof, can be fabricated, assembled, tested, and packed in complete compliance with this contract. The Contractor shall not be required to certify the Detailed
Specifications to the performance requirements, shelf life or safety. The Contractor is responsible to certify the producibility of each deliverable in the contract, even if the Contractor does not submit Producibility Improvement
Study (PIS) ECPs on each of the deliverables. If the Government disapproves an ECP that the Contractor states is essential for certification of producibility, then certification can be made conditional on a suitable solution of the issue deemed critical by the Contractor.
C.3.3 Rights in Technical Data. All data submitted by the Contractor under the Certification of Producibility shall be provided to the Government with unlimited rights as defined in DFARS clause 252.227-7013, Rights in
Technical Data -- Noncommercial Items.
C.3.4 Technology Insertion. At any time during this contract, the Government may require, at its option, the insertion of state-of-the-art, advanced or alternate technology into the items called for under the contract.
Technology insertion may be initiated through Engineering Change Proposals and incorporated into the contract via contract modification. If any Engineering Change Proposal would result in the contract price being changed, it may be negotiated as any in scope change under change order modification, and any equitable adjustment shall be incorporated into the contract in the form of a contract modification.
C.3.5 Meetings.
C.3.5.1 Post Award Meeting. The Contractor shall host a post award meeting at the Contractor’s facility to include contracts, management, and technical personnel no later than 30 calendar days after contract award. Minutes to be submitted within 5 calendar days post meeting per DI-ADMN-81250C A002. If an in-person meeting at the contractor's facility is not feasible, the post award conference may be held via teleconference, to be organized by the
Contracting office. Agenda shall be submitted 10 calendar days prior to meeting per DI-ADMN-81249C A003.
C.3.5.2 Other Meetings. The Contractor shall accommodate Government visits at least once during each production run. It is anticipated that IPT meetings shall occur telephonically or at Contractor’s facility during regular production.
C.3.6 Configuration Management Plan. The Contractor shall submit and maintain a Configuration Management
Plan throughout the life of the contract per DI-SESS-80858D A004. The Contractor shall submit Engineering
Change Proposals (ECPs) per DI-SESS-80639E A005, Request for Variances (RFVs) per DI-SESS-80640E A006 and Notices of Revision (NORs) per DI-SESS-80642E A007 as necessary. MIL-HDBK-61B may be used as guidance when preparing these reports. All configuration changes shall be reviewed and approved by the
Government. ECPs/RFVs shall be submitted on-line via the Chemical Biological Center (CBC), Edgewood, product data management system (ePDM) weblink application: https://plm.epdm.army.mil/Windchill/.
C.3.6.1 The Configuration Change Management section of SAE EIA-649-1 “Configuration Management
Requirement for Defense Contracts”, Paragraph 3.3, shall be used for configuration control of material with the following exclusions: paragraph 3.3(3); the second sentence of paragraph 3.3.1.8.1(1), and the General Note in paragraph 3.3.2.4(1) which reads as "Generally, Minor RFVs address product changes that are temporary and do not impact the baseline."
C.3.6.2 Furnished item(s) shall conform to the approved configuration requirements/revision unless a Request for
Variance (RFV) is processed and approved. The term "Request for Variance" includes Requests for Deviations and
Waivers.
C.3.6.3 Value Engineering Change Proposals (VECPs) for cost saving improvements to the Technical Data Package
(TDP) should not be processed per SAE EIA-649-1 and should be referred to FAR Part 48 Value Engineering.
https://plm.epdm.army.mil/Windchill/
C.3.6.4 All Engineering Change Proposals (ECPs) submitted will be deemed routine. If an ECP is considered as an emergency or urgent, that justification for the rationale shall be included in the ECP submittal with all applicable supporting documentation.
C.3.6.5 For ECPs, RFVs, Notices of Revision (NORs) or Specification Change Notices (SCNs), the Contractor must submit the applicable documentation listed in sub-paragraphs 5(a) through 5(d) to the Administrative Contracting
Officer (ACO), with an information copy to the Procuring Contracting Officer (PCO). Failure to submit a complete legible package may result in return of the ECP/RFV/SCN/NOR without processing.
(a) Documentation and/or use of DD Form 1692 (current revision) and delivery of data per DI-SESS-80639 is detailed in paragraph 3.3.1 of EIA-649-1 for ECPs.
(b) Documentation and/or use of DD Form 1694 (current revision) and delivery of data per DI-SESS-80640 is detailed in paragraph 3.3.2 of EIA-649-1 for RFVs.
(c) Documentation and/or use of DD Form 1695 (current revision) and delivery of date per DI-SESS-80642 is detailed in paragraph 3.3.4 of EIA-649-1 for NORs.
(d) Documentation and delivery of data per DI-SESS-80643 is detailed in para. 3.3.3 of EIA- 649-1 for SCNs.
C.3.6.6 Questions regarding the status of previously submitted ECP or RFV should be directed to the PCO.
Incorporation of an approved RFV and/or ECP will require a contract modification execution.
C.3.6.7 The submission of an ECP/RFV/SCN/NOR does not affect the required delivery date of the contract. If a delivery date change is needed, a contract modification is required.
C.3.7 Design Changes.
C.3.7.1 Contractor Proposed Design Changes. If the contractor proposes a change to the configuration baseline of C.2.0, then the contractor shall submit to the Government evidence demonstrating that the contract requirements continue to be met. Changes to the design or process may, at the Government's discretion, require First Article
Testing (FAT) at the Contractor’s expense.
C.3.8 Control of Suppliers. The contractor shall establish a supplier network that will ensure timely delivery of material and parts throughout production to meet the requirements of the metal parts. The contractor shall maintain control of the quality of all suppliers throughout production. The control techniques shall be defined but not limited to, incoming inspection, source inspection, and monitoring vendor selection, evaluation, and rating techniques. The contractor shall flow down all applicable requirements to their suppliers. The Government reserves the right to inspect contractor facilities, their potential suppliers, and all processes at the Government’s discretion at any time.
The contractor shall inform potential suppliers that the Government reserves this right.
C.3.9 Accident/Incident Report. The contractor shall report immediately any major accident/incident (including fire) resulting in any one or more of the following: causing one or more fatalities, or one or more disabling injuries;
damage of Government property exceeding $10,000; affecting program planning or production schedules; degrading the safety of equipment under contract, such that personal injury or property damage may be involved; and identifying a potential hazard requiring corrective action. The contractor shall prepare the report IAW DI-SAFT-
81563 with Notice 2 A008 for each incident IAW the CDRL.
C.3.10 Ozone Depleting Chemicals
The contractor shall not use Class I or Class II Ozone Depleting Chemicals in the execution of the Program.
C.4.0 Quality Assurance.
C.4.1 Quality Assurance Program. The contractor shall maintain a quality management system, compliant with
ISO 9001:2015 or equivalent submitted as part of the proposal.
C.4.2 Quality Management Plan and Detailed Inspection Plan. The contractor shall submit a product-specific quality assurance plan applicable for all metal parts in this contract IAW DI-QCIC-81722 A009.
C.4.3 Quality Audits. The contractor shall accommodate the Government Quality Audits prior to the start of each production run. Information to be provided by the Contractor includes, but not limited to, CDRL, any external or internal audit reports, findings, and corrective actions, customer concern/complaint reports, management review reports, and preventative action requests.
C.4.4 Inspection and Acceptance Requirements. Inspection and acceptance for all material developed and manufactured under this contract shall be completed by the Government at destination. Prior to Contractor shipment, all material shall be inspected by the Contractor IAW the specification requirements.
At the time of each delivery of supplies or services required under this contracting effort, the Contractor shall furnish to the Government a material inspection and receiving report (DD Form 250). Acceptance of material shall include approval of all invoices, shipping, and related documents. Preparation of these documents shall be accomplished electronically using the Wide Area Work Flow (WAWF) System. Prior to utilizing this system, a password and access must be requested from the system administrator. Access information and usage instructions are located at https://wawf.eb.mil.
C.4.5 Measurement System Evaluation (MSE). The contractor shall submit designs, capabilities, operating procedures, calibration procedures, manuals, and specification sheets of all inspection and test equipment
(Acceptance Inspection Equipment (AIE) and Automated Acceptance Inspection Equipment (AAIE) used to perform examinations and tests per required specifications DI-QCIC-81960 with Notice 1 A010. Measurement
System Evaluation (MSE) shall meet all contract requirements.
C.4.6 First Article Testing (FAT). The contractor shall submit FAT test plan for Government review and approval
30 calendar days prior to FAT. FAT test plan, which includes definitions of pass/fail criteria, shall be IAW DI-
NDTI-81307A A011 The contractor is responsible for submitting a FAT sample to the Government for test and acceptance prior to the start of every production run of all metal parts as defined in the applicable Detailed
Specifications (C.2.0) and other applicable requirements of the contract. Additional FAT samples may be required under the contract if more than 90 calendar days has passed between subsequent production runs under the contract.
Prior to submission of the FAT sample, the lot shall have been inspected to and shall meet all requirements of the contract. The Government shall be notified within 24 hours in the event of a failure. The contractor shall submit a
FAT test report, including resulting test data and any anomalies encountered during the contractor’s inspection, shall be provided to the Government IAW DI-NDTI-80809B* with Notice 2 A012. See Section E of the contract for
Inspection and Acceptance requirements.
C.4.7 Lot Acceptance Testing (LAT). The contractor shall submit a LAT sample to the Government for test and acceptance for each lot of metal parts produced as defined in the applicable Detailed Specifications (C.2.0) and other applicable requirements of the contract. Prior to submission of the LAT sample, the lot shall have been inspected to and shall meet all requirements of the contract. The Government shall be notified within 24 hours in the event of a failure. Resulting test data, including any anomalies encountered during the contractor’s inspection, shall be provided to the Government IAW DI- NDTI-80809B* with Notice 2 A022. See Section E of the contract for
Inspection and Acceptance requirements.
C.4.8 Failure Analysis and Corrective Actions Report. The contractor shall submit a Failure Summary and
Analysis Report per DI-SESS-80255B A013 post FAT or LAT failures or post issuance of a Quality Deficiency
Report for Government approval. See MIL-HDBK-781A, Para 4.6, for additional guidance.
C.4.9 Non-Conforming Material. All non-conforming material as defined in FAR Clause 52.246-2 shall be segregated from acceptable material and assembled in areas such that no non-conforming material may be mixed into production. Non-conforming material shall remain segregated until a decision is made by the Material Review
Board. The Government reserves the right to require destruction of non-conforming material.
C.4.10 Material Certification. Material certifications are to be provided for any component, part, or process which has a material requirement on its associated drawing or specification. The contractor shall certify the product delivered complies with the design configuration that successfully completed FAT as per DI-MISC-82386 A001.
https://wawf.eb.mil/
C.4.11 Process Capability, Control, and Improvement (PCCI). The contractor shall evaluate all process operations (e.g. fabricate, assemble, test, and pack) for implementation of monitoring and control procedures. The
Contractor shall maintain a Process Control System and submit a Process Control Plan (PCP) in accordance with the
PCCI requirements and characteristics defined in Section E of the contract as per DI-MGMT-80004A (Tailored)
A014.
C.4.12 Critical Characteristics. This contract contains critical characteristics requirements. The Contractor’s processes shall be designed with the objective of preventing the creation or occurrence of non-conforming critical characteristics (see Critical Characteristics Control (CCC) Clause (52.246-4011)). The Contractor shall establish, document, and maintain a product specific, Critical Characteristic Control Plan (CCCP) that shall be submitted 60 calendar days after award to and approved by the Contracting Officer (CO) per DI-MGMT-81986 with Notice 1
A015. The QA Addendum Critical Characteristics Clause contains requirements regarding critical characteristics with guidance for developing the CCCP and classifying additional critical characteristics for the Critical Items
Characteristics List (CICL) DI-MGMT-81988 with Notice 1, A016, which shall be submitted with the CCCP. The
Contractor’s CCCP shall include or reference all procedures, work and handling instructions and process controls relating to any critical characteristics. The Contractor shall submit Critical Safety Item, Characteristic and Critical
Defect Report, DI-SAFT-80970A with Notice 2, A017, with the CCCP. The contractor may develop alternative plans and provisions, collectively referred to as a Critical Plan of Action (CPOA) DI-MGMT-81996 with Notice 1, A018 relative to government or contractor identified critical characteristics. Mistake Proofing techniques of the material handling and inspection systems shall be a part of the CCCP. See Section J addendum of the contract for additional information/requirements.
C.4.13 Ammunition Data Card (ADC). Ammunition Lot Numbers and Ammunition Data Cards shall be prepared and submitted in accordance with MIL-STD-1168. ADCs are required for each lot IAW DI-MISC-80043B with
Notice 2 A019. ADCs shall follow the format required by the world wide web application identified as WARP or
Worldwide Ammunition-data Repository Program. Information provided in paragraphs 6.7 through 6.16 of MIL-
STD-1168 shall be considered mandatory requirements where all instances of the term “should” are considered to be replaced with the word “shall.” This shall also include, if required on the DD Form 1423, a Report of Contractor
Lot Acceptance/Ballistic Testing and Acceptance and Description Sheets (for Propellants and Explosives). WARP will reside within the Munitions History Program (MHP). For access go to https://mhpwarp.redstone.army.mil/ or contact usarmy.redstone.usamc.mbx.immc-mhp-helpdesk@mail.mil
C.4.14 Phosphate Coating Pre-Production Test Procedure. The contractor shall follow requirements regarding light, medium, and heavy phosphate coating as applicable to this statement of work and any resultant contract in addition to those requirements set forth in specification MIL-DTL-16232H with Amendment 1. The contractor shall submit Phosphate Coating Procedure and Phosphate Coating Test Procedures IAW DI-NDTI-80603A A020. Panels shall be submitted at Government Discretion.
C.5.0 Packing and Marking Requirements.
C.5.1 Preservation and Packaging Requirements:
(1) General Packaging Requirements: Preservation, packaging, packing, unitization and marking furnished by the supplier shall provide protection for a minimum of one year.
(2) Cleanliness: Items shall be free of dirt and other contaminants which would contribute to the deterioration of the item, or which would require cleaning by the customer prior to use. Coatings and preservatives applied to the item for protection are not considered contaminants.
C.5.2 Packing Requirements.
(1) Unit package:
https://mhpwarp.redstone.army.mil/ mailto:usarmy.redstone.usamc.mbx.immc-mhp-helpdesk@mail.mil
i. The item unit package shall be so designed and constructed that it will contain the contents with no damage to the item(s), and with minimal damage to the unit pack during shipment and storage and will allow subsequent handling.
ii. The outmost component of a unit package shall be a container such as a carton, box, metal, or fiber drum. All components of the container which come into contact with the contents must be compatible with the contents, or protected by means of a liner. Net weight of contents in unit container shall preferably be 320 lbs. A smaller increment of 160 lbs. may be proposed. If fiber drums are utilized, only 30-gallon or 55-gallon drums shall be used.
iii. Unit packages not meeting the requirements for a shipping container shall be packed in shipping containers.
All shipping containers shall be the most cost effective and shall be of minimum cube to contain and protect the items.
(2) Shipping Containers: The shipping container (including any necessary blocking, bracing, cushioning, or waterproofing) shall comply with the regulations of the carrier used and shall provide safe delivery to the destination at the lowest tariff cost. The shipping container shall be capable of multiple handling, stacking at least ten feet high, and storage under favorable conditions (such as enclosed facilities) for a minimum of one year.
C.5.3 Marking Requirements.
(1) Marking: All unit packages and, as applicable, exterior shipping containers and unitized loads shall be marked in accordance with MIL-STD-129R.
(2) Bar coding: Bar codes shall be applied to the unit packs, and as applicable, exterior shipping containers and unitized loads in accordance with MIL-STD 129R. 2-D bar code marking is required on the outer shipping container and the unitized load.
C.5.4 Unitization Requirements.
(1) Unitization: Shipments of identical items going to the same destination shall be palletized if they have a total cubic displacement of 50 cubic feet or more unless skids or other forklift handling features are included on the containers. Pallet loads must be stable, and to the greatest extent possible, provide a level top for ease of stacking. A palletized load shall not exceed 4,000 pounds and should not exceed 52 inches in length or width, or 54 inches in height. The load shall be contained in a manner that will permit safe handling during shipment and storage.
(2) MIL-STD-147E with Change 2 provides useful information about unitizing and palleting loads for shipments to military facilities. Material is advisory only, cannot be cited as a contract requirement.
C.5.5 Special Notes to Packaging Requirements.
(1) Wood Packaging Materials
i. All non-manufactured wood used in packaging or unitization shall be heat treated to a core temperature of 56 degrees Celsius for a minimum of 30 minutes. The box, wood packaging and pallet manufacturers shall be affiliated with an inspection agency accredited by the Board of Review of the American Lumber Standard Committee. An international source of wood must be accredited by an international certification authority recognized by the U.S.
Department of Agriculture.
ii. The box, wood packaging, and pallet manufacturer shall ensure traceability to the original source of heat treatment. Each box shall be marked to show the conformance to the International Plant Protection Convention
Standard.
iii. Boxes and any wood used as inner packaging made of non-manufactured wood shall be heat treated. The quality mark shall be placed on both ends of the outer packaging (between the end cleats or battens if applicable).
Quality marks for pallets shall be placed on two opposite end posts. Quality mark for wood unitization components shall be placed on two opposite sides.
C.6.0 Security. THE HIGHEST CLASSIFICATION FOR THIS EFFORT IS UNCLASSIED. Controlled
Unclassified Information (CUI): Contractor employees that will require access to CUI will follow all DoD (DoDI
5200.48) and Army policies regarding access to CUI, and the handling, storage, transmission, and destruction of
CUI. Contractor employees are required to complete initial CUI training (available at https://securityawareness.usalearning.gov/cui/index.html) within 30 days of start of performance on the contract, and then annually thereafter. CUI may be transmitted electronically (e.g., data, website, or e-mail), via approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure or transport layer security (e.g., https). Secure file transfer tools, such as the DoD Safe Access File Exchange (SAFE) website (https://safe.apps.mil/), should be utilized. Electronic files/data stored on removable media may be transferred via US postal service or other approved delivery service.
C.6.0.1 Information Protection. The Contractor shall not release any information or data to third parties without the express written approval of the Contracting Officer. All requests for publication in technical journals, magazines, newspapers, or other public releases shall be cleared by the Picatinny Arsenal Public Affairs Office in accordance with the Clearance of Technical Information for Public Release, JPEO Form 3002f, 09 Nov 2018. A copy of the approved release shall be provided to the COR and PCO.
C.6.0.2 Information Subject to Export Control Laws/International Traffic in Arms Regulation (ITAR): Public
Law 90-629, "Arms Export Control Act," as amended (22 U.S.C. 2751 et. seq.) requires that all unclassified technical data with military application may not be exported lawfully without an approval, authorization, or license under EO 12470 or the Arms Export Control Act and that such data require an approval, authorization, or license for export under EO 12470 or the Arms Export Control Act. For purposes of making this determination, the Militarily
Critical Technologies List (MCTL) shall be used as general guidance. All documents determined to contain export controlled technical data will be marked with the following notice:
W_A_R_N_I_N_G_ This document contains technical data whose export is restricted by the Arms Export Control
Act (Title 22, U.S.C., and Sec 2751, et seq) or the Export Administration Act of 1979, as amended, Title 50, U.S.C., App. 2401 et seq. Violations of these export laws are subject to severe criminal penalties. Disseminate in accordance with provisions of DoD Directive 5230.25.
C.6.1 OPSEC Standard Operating Procedure/Plan. The contractor shall develop an OPSEC Standard Operating
Procedure (SOP)/Plan, DI-MGMT 80934C with Notice 2 A021, within 90 calendar days of contract issuance, to be reviewed and approved by the responsible Government OPSEC officer, per AR 530-1, Operations Security. This
SOP/Plan will include the government's critical information, why it needs to be protected, where it is located, who is responsible for it, and how to protect it. In addition, the contractor shall identify an individual who will be an
OPSEC Coordinator. The contractor will ensure this individual becomes OPSEC Level II certified per AR 530-1.
C.6.2 OPSEC Training. Per AR 530-1, Operations Security, new contractor employees must complete Level I
OPSEC training within 30 calendar days of their reporting for duty. All contractor employees must complete annual
OPSEC awareness training.
C.6.3 Controlled Unclassified Information (CUI):
Contractor employees that will require access to CUI will follow all DoD (DoDI 5200.48) and Army policies regarding access to CUI, and the handling, storage, transmission, and destruction of CUI.
Contractor employees are required to complete initial CUI training (available at https://securityawareness.usalearning.gov/cui/index.html) within 30 days of start of performance on the contract, and then annually thereafter. CUI information may be transmitted electronically (e.g., data, website, or e-mail), via approved secure communications systems or systems utilizing other protective measures such as Public Key
Infrastructure or transport layer security (e.g., https). Secure file transfer tools, such as the DoD Safe Access File
Exchange (SAFE) website (https://safe.apps.mil/), should be utilized.
C.6.4 Safeguarding Covered Defense Information
The Contractor shall use the following to supplement Defense Federal Acquisition Regulation Supplement (DFARS)
Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.
1. System Security Plan and Plans of Action and Milestones (SSP/POAM) Reviews
(a) Within thirty (30) days of contract award, unless otherwise notified by the Government, the Contractor shall make its System Security Plan(s) (SSP(s)) for its covered contractor information system(s) available for review by the Government at the Contractor's facility. The SSP(s) shall describe how the National Institute of Standards and
Technology (NIST) Special Publication (SP) 800-171 security requirements are implemented as required by Defense
Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which is included in this contract, and identify all applicable Commercial and Government Entity Code codes affected. The Contractor shall fully cooperate in the Government's review of the SSPs at the Contractor's facility.
(b) If the Government determines that the SSP(s) does not adequately describe how the NIST SP 800-171 security requirements are implemented, then the Government shall notify the Contractor of each identified deficiency. The
Contractor shall correct any identified deficiencies within thirty (30) days of notification by the Government. The contracting officer may provide for a correction period longer than thirty (30) days and, in such a case, may require the Contractor to submit a Plan of Action and Milestones (POAM) for the correction of the identified deficiencies.
The Contractor shall immediately notify the contracting officer of any failure or anticipated failure to meet a milestone in such a POAM.
(c) Upon conclusion of the correction period, the Government may conduct a follow-on review of the SSP(s) at the
Contractor's facilities. The Government may continue to conduct follow-on reviews until the Government determines that the Contractor has corrected all identified deficiencies in the SSP(s).
(d) The Government may, in its sole discretion or in response to a cyber incident, conduct subsequent reviews at the
Contractor's site to verify the information in the SSP(s). The Government may conduct reviews at any time upon thirty (30) days' notice to the Contractor.
2. Compliance to NIST SP 800-171
(a) The Contractor shall fully implement the Controlled Unclassified Information (CUI) Security Requirements
(Requirements) in NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the
Contracting Officer, or establish a SSP(s) and POAMs) that varies from NIST SP 800-171 only in accordance with
DFARS clause 252.204-7012(b)(2), for all covered contractor information systems affecting this contract.
(b) Notwithstanding the allowance for such variation, the Contractor shall identify in any SSP and POAM their plans to implement the following, at a minimum:
(1) Implement Requirement 3.5.3 (Multi-factor authentication). This means that multi-factor authentication is required for all users, privileged and unprivileged accounts that log into a network. In other words, any system that is not standalone should be required to utilize acceptable multi-factor authentication. For legacy systems and systems that cannot support this requirement, a combination of physical and logical protections acceptable to the
Government may be substituted;
(2) Implement Requirement 3.1.5 (least privilege) and associated Requirements, and identify practices that the
Contractor implements to restrict the unnecessary sharing with, or flow of, covered defense information to its subcontractors, suppliers, or vendors based on need-to-know principles;
(3) Implement Requirement 3.1.12 (monitoring and control remote access sessions)-Require monitoring and controlling of remote access sessions and include mechanisms to audit the sessions and methods;
(4) Audit user privileges on at least an annual basis;
(5) Implement Requirement 3.13.11 (Federal Information Processing Standards (FIPS) 140-2 validated cryptology or implementation of National Security Agency- or NIST-approved algorithms (i.e., FIPS 140-2 Annex
A: Advanced Encryption Standard (AES) Or Triple Data Encryption Standard (DES) or compensating controls as documented in a SSP and POAM));
(6) Implement Requirement 3.13.16 (Protect the confidentiality of CUI at rest) or provide a POAM for implementation which can be evaluated by the Government Program Manager for risk to the program;
(7) Implement Requirement 3.1.19 (encrypt CUI on mobile devices) or provide a plan of action for implementation which can be evaluated by the Government Program Manager for risk to the program.
3. Cyber Incident Response:
(a) The Contractor shall, within fifteen (15) days of discovering the cyber incident (inclusive of the 72-hour reporting period in DFARS clause 252.204-7012), deliver all data used in performance of the contract that the
Contractor determines is impacted by the incident and begin assessment of potential warfighter/program impact.
Incident data shall be delivered in accordance with the Department of Defense Cyber Crimes Center (DC3)
Instructions for Submitting Media available at http://www.acq.osd.mil/dpap/dars/pgi/docs/lnstructions_for_Submitting_Media.docx. In delivery of the incident data, the Contractor shall, to the extent practical, remove contractor-owned information from Government covered defense information.
(b) If the Contractor subsequently identifies any such data not previously delivered to DC3, then the Contractor shall immediately notify the contracting officer in writing and shall deliver the incident data within ten (10) days of identification. In such a case, the Contractor may request a delivery date later than ten (10) days after identification.
The contracting officer will approve or disapprove the request after coordination with DC3.
4. Army Counterintelligence (Cl) Outreach
The Contractor shall engage, whenever practicable, with Army Cl industry outreach efforts and consider recommendations for hardening of covered contractor information systems affecting Army programs and technologies; and make Contractor personnel available for threat briefings specific to foreign intelligence threats to
Army programs and technologies.
5. Army Cl/Industry Monitoring
(a) In the event of a cyber incident or at any time the Government has indication of a vulnerability or potential vulnerability, the Contractor shall cooperate with the Army Cl, which may include cooperation related to: threat indicators; pre-determined incident information derived from the Contractor's infrastructure systems; and the continuous provision of all Contractor, subcontractor, or vendor logs that show network activity, including any additional logs the Contractor, subcontractor or vendor agrees to initiate as a result of the cyber incident or notice of actual or potential vulnerability.
(b) If the Government determines that the collection of all logs does not adequately protect its interests, the
Contractor will coordinate with Army Cl to implement additional measures, which may include allowing the installation of an appropriate network device that is owned and maintained by the Army Cl, on the Contractor's information systems or information technology assets. The specific details (e.g., type of device, type of data gathered, monitoring period) regarding the installation of an Army Cl network device shall be the subject of a separate agreement negotiated between Army Cl and the Contractor. In the alternative, the Contractor may install network sensor capabilities or a network monitoring service, either of which must be reviewed for acceptability by
Army Cl. Use of this alternative approach shall also be the subject of a separate agreement negotiated between Army
Cl and the Contractor.
(c) In all cases, the collection or provision of data and any activities associated with this statement of work shall be in accordance with federal, state, and non-US law.
File details come from the government source that posted it. Updated .