A01 - Attachment 0002 - Statement of Work Appendix A_DCGS-A CD 2_25JUN20....pdf
PDF 356 KB Posted
- Attached to
- FORMAL SOLICITATION - Distributed Common Ground System - Army Capability Drop 2 Data Fabric and Analytics Federal contract opportunity
- Solicitation number
- W56KGY-19-R-0007
About this file
This document is a solicitation for a multiple award indefinite delivery, indefinite quantity contract to provide a Distributed Common Ground System - Army Capability Drop 2 Data Fabric and Analytics solution. The Army seeks to upgrade components in the DCGS-A "Brain" through a commercial solution that incorporates current industry approaches to enable centralized data receipt, processing, refinement, management, storage, and access. The solution will also enable Intelligence Reach to tactical forces and distribution of Geospatial Information and Services for Mission Command at any echelon with a data refinement mission. The base period of performance is four years with a three-year option period and a minimum guarantee of $3,500 for the first order. The total contract ceiling is $823,263,105.82. The Government intends to award this contract on a firm-fixed-price basis by issuing orders competitively in accordance with FAR Parts 12 and 15. All questions must be submitted by 12:00PM Eastern on August 2, 2019 to the identified email addresses.
Solicitation Section J Attachments/Exhibits
View the file
Other files for this federal contract opportunity
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED // FOR OFFICIAL USE ONLY
STATEMENT OF WORK (SOW)
Appendix A - Other Contract Requirements and
Guidelines
FOR
Distributed Common Ground System – Army (DCGS-A) Capability Drop (CD) 2 – Data Fabric and Analytics
Solicitation Number: W56KGY-19-R-0007
Base Contract Version 1.0
25 June 2019
Project Manager (PM) DCGS-A 6580 Surveillance Loop, Building 6006 Aberdeen Proving Ground, MD 21005
Solicitation # W56KGY-19-R-0007 SOW Appendix A 25 June 2019
Table of Contents
1.0 Security Requirements
1.1 Industrial Security
1.2 Antiterrorism
1.2.1 Antiterrorism (AT) Level I Training
1.2.2 AT Awareness Training for Contractor Personnel Traveling Overseas
1.2.3 iWATCH Training
1.3 Information Security
1.3.1 Access and General Protection/Security Policy and Procedures
1.3.2 Handling/Access to Classified Information
1.4 Operations Security
1.4.1 Operations Security Plan
1.4.2 OPSEC Training
1.4.3 OPSEC Countermeasures
1.5 Cybersecurity Requirements
1.5.1 Access to Government Information Systems
1.5.2 Cybersecurity/information technology (IT) training
1.5.3 Cybersecurity/ IT certification
1.5.4 Cybersecurity Compliance
1.6 Security Incidents Clause
1.7 Access and General Protection Policy and Procedures
1.7.1 Common Access Card (CAC):
1.8 Threat Awareness and Reporting Program
1.9 Delivery Order Security Requirements
1.9.1 Performance or Delivery in a Foreign Country:
1.10 Key Control
1.11 Lock Combinations
1.12 Protection of Unclassified Information
1.13 Government-Issued Personal Identification Credentials
1.14 Security Classification Guides
2.0 Government Furnished Information
2.1 Computer Software and Interfaces
2.2 Contractor Furnished Property
2.3 Government/Military Facilities
3.0 Additional GFI
4.0 Travel
5.0 Acronym List
1.0 Security Requirements
The Contractor shall be cognizant, comply, and implement the following detailed security requirements listed below.
1.1 Industrial Security
The Contractor will be required to have a Top Secret Facility Clearance with Top Secret safeguarding capability limited to at a minimum of two (2) cubic feet at the contractor facility. The contractor must provide adequate storage for all the classified hardware as well to the level of Top Secret. The Contractor will require access to COMSEC information, North Atlantic Treaty Organization (NATO) and For Official Use Only (FOUO) information. Contractor will require access to the Top Secret Joint Worldwide Intelligence Communications System Network, Secure Internet Protocol Router Network (SIPRNet) at Government and industry facilities. All Contractor personnel performing work on this contract shall possess and maintain a minimum of a Top Secret United Stated of America (US) Government security clearance.
The Contractor will have access to classified information at Government and industry facilities while performing this contract. In performing this contract, the Contractor may require access to classified information at facilities in the following CONUS and OCONUS locations: (Industry Facility address); PEO IEW&S/PM DCGS-A (BLDG 6002/6006) and I2WD (BLDG 6003), Aberdeen Proving Ground (APG), Maryland; Fort Gordon, GA, Fort Bragg, NC and OCONUS locations: Germany, Korea, and Hawaii.
The Contractor will be authorized to receive and generate classified material at the contractor facility (documents and/or hardware). Contractors shall be required to complete derivative classification training, located at the following link:
https://www.cdse.edu/catalog/elearning/IF103.html, and submit certificates of completion to the Contracting Officer’s Representative (COR) NLT 30 days of delivery order request. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents.
A COMSEC account shall be required and there will be a TEMPEST requirement. The contractor is authorized a COMSEC account and use of the Defense Courier Service is authorized.
All Contractors granted SIPRNet access must be aware that NATO classified material resides on the SIPRNet and the Contractor is not authorized to access, download, or to disseminate any NATO or other special access data (i.e. intelligence, COMSEC, etc.) outside the execution of the defined contract requirements and without guidance and written permission. All Contractors will read the NATO Central Registry awareness briefing prior to being issued a SIPRNet account located at https://www.cdse.edu/documents/toolkits-fsos/NATO_Brief.pdf.
This briefing does not authorize NATO access, and is solely for the purpose of awareness. The Contractor is authorized the use of the Defense Technical Information Center or other secondary distribution center.
https://www.cdse.edu/catalog/elearning/IF103.html https://www.cdse.edu/documents/toolkits-fsos/NATO_Brief.pdf
DD Form 254, Contract Security Specification, will be included in the resulting contract and individual task orders as required. All security requirements will be specified in PWS for applicable task orders. The contractor will also require access to Security Classification Guide(s) (SCG) as required. Administrative duties may not require a clearance but may require investigation for information technology (IT) duties.
1.2 Antiterrorism
1.2.1 Antiterrorism (AT) Level I Training
All Contractor employees, to include subcontractor employees shall complete Antiterrorism (AT) Level I awareness training within 30 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR or to the Contracting Officer, if a COR is not assigned, within 30 calendar days after completion of training by all employees and subcontractor personnel AT level I awareness training is available at https://jkodirect.jten.mil for Contractors with Common Access Cards (CAC). Use http://jko.jten.mil/courses/atl1/launch.html if Contractor does not have a CAC.
1.2.2 AT Awareness Training for Contractor Personnel Traveling Overseas
US based Contractor employees and associated subcontractor employees may require Government provided area of responsibility (AOR) specific AT awareness training as directed by AR 525-13. Specific AOR training content is directed by the combatant commander with the unit Antiterrorism Officer being the local Point of Contact (POC). US based Contractor employees and associated subcontractor employees will submit an Isolated Personnel Report prior to deployment, IAW AR 525-28, Personnel Recovery.
The Contractor is required to fill out the survey on NIPRNET at https://prmsglobal.prms.af.mil/prmsconv/Profile/Survey/start.aspx prior to OCONUS travel. The Contractor is then required to advise the PRMS manager of the submission and request validation of the updated survey.
1.2.3 iWATCH Training
The Contractor and all associated subcontractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity Antiterrorism Officer). This local developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 calendar days of contract award and within 30 calendar days of new employees commencing performance with the results reported to the COR NLT 60 calendar days after contract award. iWATCH training and program information is available at the following website:
http://www.myarmyonesource.com/familyprogramsandservices/iwatchprogram/default.aspx https://jkodirect.jten.mil/ http://jko.jten.mil/courses/atl1/launch.html https://prmsglobal/ http://www.myarmyonesource.com/familyprogramsandservices/iwatchprogram/default.aspx
1.3 Information Security
1.3.1 Access and General Protection/Security Policy and Procedures
This standard language text is for Contractor employees with an area of performance within an Army controlled installation, facility or area. Contractor and all associated subcontractors employees shall comply with applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by Government representative). The Contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements as directed by DOD, HQDA and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in Contractor security matters or processes.
1.3.2 Handling/Access to Classified Information
Contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires Contractors to comply with— (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M); any revisions to DOD 5220.22-M, notice of which has been furnished to the Contractor.
1.4 Operations Security
1.4.1 Operations Security Plan
The Contractor shall develop a standard operating procedure (SOP) within its Operations Security (OPSEC) Plan, IAW CDRL B001, to be reviewed and approved by the responsible Government OPSEC officer, per AR 530-1, Operations Security. This SOP/Plan will include the Government’s critical information, why it needs to be protected, where it is located, who is responsible for it, and how to protect it. In addition, the Contractor shall identify an individual who will be an OPSEC Coordinator. The Contractor will ensure this individual becomes OPSEC Level II certified per AR 530-1.
1.4.2 OPSEC Training
Per AR 530-1 Operations Security, the Contractor employees must complete Level I OPSEC Awareness training. New employees must be trained within 90 calendar days of their reporting for duty and annually thereafter. Level I OPSEC training is available at the following website:
http://cdse.edu/catalog/elearning/GS130.html (Duration: approximately 45 minutes). Employees will follow the Government OPSEC Plan.
http://cdse.edu/catalog/elearning/GS130.html
1.4.3 OPSEC Countermeasures
The Contractor shall cooperate with OPSEC countermeasures to ensure their publicly assessable websites are free of classified or FOUO material, and/or indicators that could tip off adversaries about impending activity. The Contractor shall minimize any attentions that focus on additional intelligence collection assets and reduce any possibilities to impede mission requirements or harm personnel. The Contractor shall also include measure taken to eliminate from websites certain technological/technical data, when combined with other unclassified information that may reveal an additional association or relationship that meets the standards for classification.
1.5 Cybersecurity Requirements
1.5.1 Access to Government Information Systems
All Contractor employees who require access to a Government Information System (IS) must be registered in the ATCTS (Army Training Certification Tracking System) at commencement of services and must successfully complete the DOD Cybersecurity (CS) Awareness training prior to being granted access to the IS and then annually thereafter.
1.5.2 Cybersecurity/information technology (IT) training
All Contactor employees and associated subcontractor employees must complete the DoD Cybersecurity Awareness training before issuance of network access and annually thereafter. All Contractor employees and subcontractor employees working Cybersecurity/IT functions must comply with DoD and Army training requirements in DoDD 8570.01, DoD 8570.01-M and AR 25- 2 within six (6) months of appointment to Cybersecurity/IT functions.
1.5.3 Cybersecurity/ IT certification
All Contractor employees working Cybersecurity or other Information Technology (IT) functions must comply with DoD and Army training requirements in DoDD 8140.01, DFARS 252.239.7001, and AR 25-2 and per DoD 8570.01-M (Ch 4) shall meet the appropriate training and certification requirements upon contract award. The baseline certification as stipulated in DoD 8570.01-M (Ch
4) must be completed upon contract award. New employees shall meet the baseline IA/CS training and certification requirements within six (6) months of appointment to CS/IT functions.
Contractor personnel performing IT sensitive duties are subject to investigative and assignment requirements IAW AR 25-2, AR 380-67 and affiliated regulations.
1.5.4 Cybersecurity Compliance
The DCGS-A CD 2 solution shall meet all applicable security control requirements so that an ATO can be obtained. Once an authorization decision has been obtained, the Contractor shall continue to sustain the security posture of the system baseline to maintain the compliance of the ATO requirement. The Contractor shall maintain IAVM patching process at least on a monthly basis to support CCRI compliance.
Effective 26 August 2015, 48 Code of Federal Regulations (CFR) Parts 202, 204, 212, 239, and 252, Defense Federal Acquisition Regulation Supplement (DFARS) Case 2013-D018 (Network Penetration Reporting and Contracting for Cloud Services) 26 August 2015, requires all Contractors to provide adequate security and rapidly report cyber incidents to DoD for covered Defense information for the performance of work under new solicitations and resulting contracts.
Contractors are required to follow guidance in DFARS provision at 252.204-7008 (Compliance with Safeguarding Covered Defense Information controls) and DFARS clause at 252.204-7009 (Limitations on the Use or Disclosure of Third- Party Contractor Information) for all solicitations and DFARS clause at 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) for all contracts. As defined in DFARS clause at DFARS 252.227-7013 covered Defense information includes controlled technical information, export controlled information, critical information, and other information requiring protection by law, regulation, or Government-wide policy.
Per DFARS 252.204-7012, Disclosure of Information, http://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012, contractors are required to:
1. When the Contractor discovers a cyber-incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support, the Contractor shall—
i. Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other information systems on the Contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the Contractor’s ability to provide operationally critical support; and
ii. Rapidly report cyber incidents to DoD at http://dibnet.dod.mil.
2. Cyber incident report. The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements at http://dibnet.dod.mil.
3. Medium assurance certificate requirement. In order to report cyber incidents IAW this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on http://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012 http://dibnet.dod.mil/ http://dibnet.dod.mil/ obtaining a DoD-approved medium assurance certificate, see https://cyber.mil/eca/.
1.6 Security Incidents Clause
Security infractions and violations are costly to the Government and adversely affect the program.
A security incident will be defined as any security infraction or security violation. The definitions for these items are:
• Security Infraction – a security incident involving a deviation from current governing security regulations that does not result in an unauthorized disclosure or compromise of national intelligence information nor otherwise constitutes a security violation.
• Security Violation – a security incident involving: (1) any action that results in or could reasonably be expected to result in an unauthorized disclosure or compromise of classified information (including national intelligence): (2) any knowing, willful, or negligent action to classify or continue the classification of information contrary to the requirements of Executive Order 12958, as amended, or its implementing directives;
or (3) any knowing, willful, or negligent action to create or continue a Special Access Program contrary to the requirements of Executive Order 12958, as amended.
1.7 Access and General Protection Policy and Procedures
Access and general protection/security policy and procedures for Contractor employees with an area of performance within Army controlled installation, facility, or area: Contractor and all associated subcontractor employees shall provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, HQDA and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the FPCON at any individual facility or installation change, the Government may require changes in Contractor security matters or processes.
1.7.1 Common Access Card (CAC):
Before CAC issuance, the Contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation IAW Army Directive 2014-05. The Contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review https://cyber.mil/eca/ of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.
Contractor and all associated subcontractors employees not eligible/not require CAC, but require access to a DoD facility or installation shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by Government representative), or, at OCONUS locations, IAW status of forces agreements and other theater regulations.
1.8 Threat Awareness and Reporting Program
For all Contractors with security clearances, per AR 381-12 Threat Awareness and Reporting Program (TARP), Contractor employees must receive annual TARP training by a CI agent or other trainer as specified in 2-4b. This provision/contract text is for Contractor employees with an area of performance within an Army controlled installation, facility or area. All Contractor employees, to include subcontractor employees, requiring access to Government installations, facilities, and controlled access areas shall complete TARP training within 30 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR, within 30 calendar days after completion of training by all employees and subcontractor personnel. TARP Training is available at the following website:
https://www.lms.army.mil/StaticContent/ALMS_NewUserTraining/start.html for those Contractors not working on a military installation; Contractors working on a military installation shall attend a live TARP presentation. Contractors will report threat-related incidents, behavioral indicators, and other matters of CI interest specified in chapter 3, to the facility security officer, the nearest military CI office, the Federal Bureau of Investigation, or the Defense Security Service.
1.9 Delivery Order Security Requirements
Contractor personnel performing IT sensitive duties are subject to investigative and assignment requirements IAW AR 25-2, AR 380-67 and affiliated regulations. All Contractors granted access to SIPRNet will be required to complete the NATO Central Registry awareness briefing.
Contractor requires access to Planning Programming and Budgeting Business Operating System (PPBBOS) documents and supporting databases IAW DoD Directive Number 7045.14, Change 1 dated 28 July 1990, paragraph 4.7, and DoDD 7045.14, paragraph 4.8. Individuals must have appropriate clearance before requesting access a system.
1.9.1 Performance or Delivery in a Foreign Country:
DFARS Clause 252.225-7043, Antiterrorism/Force Protection applies for all Defense Contractors that require performance or delivery in a foreign country outside the US. This clause applies to both contingencies and non-contingency support. The key AT requirement is for non-local national contractor personnel to comply with theater clearance requirements and allows the combatant commander to exercise oversight to ensure the contractor’s compliance with combatant commander and subordinate task force commander policies and directives.
1.10 Key Control
The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer. In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the Contracting Officer, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying.
When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.
The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.
1.11 Lock Combinations
The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed annually and when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Contractor’s Quality Control Plan.
1.12 Protection of Unclassified Information
The Contractor shall safeguard unclassified DoD information stored on non-DoD information systems to prevent the loss, misuse, and unauthorized access to or modification of this information. The Contractor shall:
A. Not process DoD information on public computers (e.g., those available for use by the general public in kiosks or hotel business centers) or computers that do not have access control.
B. Protect information by no less than one (1) physical or electronic barrier (e.g., locked container or room, login, and/or password) when not under direct individual control.
C. Sanitize media (e.g., overwrite) before external release or disposal.
D. Encrypt the information that has been identified as Controlled Unclassified Information (CUI) when it is stored on mobile computing devices such as laptops and personal digital assistants, or removable storage media such as thumb drives and compact disks, using the best available encryption technology.
E. Limit information transferred to subcontractors or teaming partners with a need to know and a commitment to at least the same level of protection.
F. Transmit e-mail, text messages, and similar communications using technology and processes that provide the best level of privacy available, given facilities, conditions, and environment. Examples of recommended technologies or processes include:
closed networks, virtual private networks, public key-enabled encryption, and Transport Layer Security (TLS).
G. Encrypt organizational wireless connections and use encrypted wireless connection, where available, when traveling. When encrypted wireless is not available, encrypt application files (e.g., spreadsheet and word processing files), using no less than application-provided password protection level encryption.
H. Transmit voice and fax transmissions only when there is a reasonable assurance that access is limited to authorized recipients.
I. Not post DoD information to Web site pages that are publicly available or have access limited only by domain or Internet protocol restriction. Such information may be posted to Web site pages that control access by user identification or password, user certificates, or other technical means and provide protection via use of TLS or other equivalent technologies. Access control may be provided by the intranet (vice the Web site itself or the application it hosts).
J. Provide protection against computer network intrusions and data ex-filtration, including no less than the following:
i. Current and regularly updated malware protection services, e.g., anti-virus, anti-spyware.
ii. Monitoring and control of inbound and outbound network traffic as appropriate
(e.g. at the external boundary, sub-networks, individual hosts) including blocking unauthorized ingress, egress, and ex-filtration through technologies such as firewalls and router policies, intrusion prevention or detection services, and host-based security services.
iii. Prompt application of security-relevant software patches, service packs, and hot fixes.
K. Comply with other current Federal and DoD information protection and reporting requirements for specified categories of information (e.g., critical program information, Personally Identifiable Information (PII), export controlled information) IAW the requirements of the contract.
1.13 Government-Issued Personal Identification Credentials
The Contractor shall account for all forms of U.S Government-provided identification credentials (CAC or U.S. Government-issued identification badges) issued to the Contractor (or their employees in connection with performance) under the contract. The Contractor shall return such identification credentials to the Trusted Agent at the earliest of any of the following, unless otherwise determined by the U.S. Government:
A. When no longer needed for contract performance.
B. Upon completion of the Contractor employee’s employment.
C. Upon contract completion or termination.
1.14 Security Classification Guides
The Contractor(s) will require access to the DCGS-A SCG.
2.0 Government Furnished Information
2.1 Computer Software and Interfaces
The Contractor shall be required to interface with several third-party systems as stated in the PRD. The Government will provide those systems, if required and determined by the Government, to authorized Contractors after initial contract award. All use and care shall be in conformance with FAR 52.245-1.
2.2 Contractor Furnished Property
The Contractor shall ensure that Contractor-owned property brought to Government work sites is clearly marked as such to preclude misidentification as Government property.
2.3 Government/Military Facilities
During Performance Tests the Government may provide facilities for the Contractor to support performance activity.
For any Contractor working in a Government facility, the following shall be provided:
Telephone Service. The Government will provide telephone communication service exclusively for the conduct of official business. The Contractor shall be responsible for charges for long distance telephone calls made or accepted by Contractor personnel, which are not for the purpose of conducting official Government business. The Contractor shall be responsible for long distance telephone calls and charges made by or accepted by Contractor personnel that are not required for the performance of the mission.
Telephone service will be subject to the standard monitoring requirements of the Government telephone network. The Government-furnished telephones are subject to security monitoring at all times. Use of these telephones constitutes consent to security monitoring.
Network Access. The Government will provide network access for all vendor products under consideration of CD 2 capability assessment during Performance Tests.
System and Functional Administration. The Government will provide systems and functional administration of the Local Access Network (LAN) in support of Performance Tests on both classified & unclassified networks.
Custodial and Refuse Services. The Government will provide custodial and refuse services for the Government facilities used in performance of this contract. The Government’s provision of custodial and refuse services do not relieve the Contractor of the responsibility for keeping work areas in a clean and sanitary condition. In some areas, the Contractor shall be required to empty trash from office/shop trashcans to dumpsters.
Copying, Printing, and Reproduction. The Government will provide shared-use copy machines for limited copying of official reports, documents, and correspondence to accomplish the requirements of specific tasks.
3.0 Additional GFI
The Government may provide additional information such as manuals, drawings, test data including information on third party devices, software, etc. in support of the requirements of this contract. For GFI which is wholly owned by the Government, use and care shall be in conformance with classification, handling and/or distribution markings and statements contained within the GFI.
4.0 Travel
The Contractor shall be required to travel to designated destinations in order to perform activities, as required to support fielding, training, maintenance, cybersecurity, and testing.
5.0 Acronym List
ACAS Assured Compliance Assessment Solution ACC-APG Army Contracting Command- Aberdeen Proving Ground APG Aberdeen Proving Ground APL Approved Products List AT Antiterrorism ATCTS Army Training Certification Tracking System ATEC Army Test and Evaluation Center ATO Authority to Operate CAC Common Access Card CCRI Command Cyber Readiness Inspection CD Capability Drop CDRL Contract Data Requirements List CFR Code of Federal Regulations CIA Confidentiality, Integrity, and Availability CM Configuration Management CONUS Contiguous United States COR Contracting Officer’s Representative CS Cybersecurity CTSF Central Technical Support Facility CUI Controlled Unclassified Information DCGS-A Distributed Common Ground System‐Army DDS Data Dissemination Service DFARS Defense Federal Acquisition Regulation Supplement DISA Defense Information Systems Agency DoD Department of Defense DO Delivery Order FCA Functional Configuration Audit FOUO For Official Use Only
FPCON Force Protection Condition FTP File Transfer Protocol GEOINT Geospatial Intelligence GERB Government Engineering Review Board GFE Government Furnished Equipment GFI Government Furnished Information GFP Government Furnished Property GOTS Government Off‐the‐Shelf HE Human Engineering HTTP Hypertext Transfer Protocol IA Information Assurance IAVA Information Assurance Vulnerability Alert IAVB Information Assurance Vulnerability Bulletins IAVT Information Assurance Vulnerability Tech Tips
IAW IAW
IDS/IPS Intrusion Detection System/Intrusion Prevention System ILS Integrated Logistics Support IS Information System IT Information Technology JVMF Joint Variable Message Format KO Contracting Officer (Army) KS Knowledge Service LAN Local Area Network MASIT Measurement and Signal Intelligence MC Mission Command NACI National Agency Check with Inquiries NATO North Atlantic Treaty Organization NCIC-III National Crime Information Center Interstate Identification
Index NET New Equipment Training NIAP National Information Assurance Partnership NLT No Later Than NVA Network Vulnerability Assessment OCONUS Outside Contiguous United States OEM Original Equipment Manufacturer OPSEC Operations Security OTRR Operational Test Readiness Review PM Program Manager
POA&M Plan of Action and Milestones PPBBOS Planning Programming and Budgeting Business Operating
System PRD Performance Requirement Document QASP Quality Assurance Surveillance Plan RMF Risk Management Framework SA Situational Awareness SCA Security Control Assessor SCG Security Classification Guide SME Subject Matter Expert SOP Standard Operating Procedure SOW Statement of Work SPOT Synchronized Pre‐Deployment Operational Tracker STIG Security Technical Implementation Guides STR Software Trouble Report SVD Software Version Description TARP Threat Awareness and Reporting Program TIR Test Incident Report TLS Transport Layer Security TRADOC U.S. Army Training and Doctrine Command TRR Test Readiness Review TSDB Terrorist Screening Database UC Unified Capabilities USMTF United States Message Text Format VMF Variable Message Format VPN Virtual Private Network
| 1.0 Security Requirements |
| 1.1 Industrial Security |
| 1.2 Antiterrorism |
| 1.2.1 Antiterrorism (AT) Level I Training |
| 1.2.2 AT Awareness Training for Contractor Personnel Traveling Overseas |
| 1.2.3 iWATCH Training |
| 1.3 Information Security |
| 1.3.1 Access and General Protection/Security Policy and Procedures |
| 1.3.2 Handling/Access to Classified Information |
| 1.4 Operations Security |
| 1.4.1 Operations Security Plan |
| 1.4.2 OPSEC Training |
| 1.4.3 OPSEC Countermeasures |
| 1.5 Cybersecurity Requirements |
| 1.5.1 Access to Government Information Systems |
| 1.5.2 Cybersecurity/information technology (IT) training |
| 1.5.3 Cybersecurity/ IT certification |
| 1.5.4 Cybersecurity Compliance |
| 1.6 Security Incidents Clause |
| 1.7 Access and General Protection Policy and Procedures |
| 1.7.1 Common Access Card (CAC): |
| 1.8 Threat Awareness and Reporting Program |
| 1.9 Delivery Order Security Requirements |
| 1.9.1 Performance or Delivery in a Foreign Country: |
| 1.10 Key Control |
| 1.11 Lock Combinations |
| 1.12 Protection of Unclassified Information |
| 1.13 Government-Issued Personal Identification Credentials |
| 1.14 Security Classification Guides |
| 2.0 Government Furnished Information |
| 2.1 Computer Software and Interfaces |
| 2.2 Contractor Furnished Property |
| 2.3 Government/Military Facilities |
| 3.0 Additional GFI |
| 4.0 Travel |
| 5.0 Acronym List |
File details come from the government source that posted it. Updated .