AGATCS SDP Draft Order SOW Version 1.docx
DOCX document 110 KB Posted
- Attached to
- Army Ground Aerial Target Control System (AGATCS) Support, Development, and Production (SDP) Federal contract opportunity
- Solicitation number
- W900KK20R0020
About this file
This statement of work outlines requirements for an indefinite delivery/indefinite quantity contract to provide target and threat operation, production, and development services in support of multiple Army programs and training events. Key details include providing production and development capabilities for aerial and ground-based targets and target controlling systems. Operational services, subject matter experts for mission support, and research and development of target and threat products are also required. Delivery locations may be both within and outside the continental United States. The anticipated multiple award IDIQ contract will have a one-year base period and four one-year options and is intended for the U.S. Army Program Executive Officer for Simulation, Training, and Instrumentation through the Project Manager for Cyber, Test and Training.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A13 Presolicitation RFP - RESPONSE - Industry Questions.pdf | ||
| AGATCS SDP Draft Sample Orders Version 1.docx | DOCX document | |
| Draft IDIQ Section B Version 1.docx | DOCX document | |
| AGATCS SDP IDIQ DRAFT SOW Version 1.docx | DOCX document | |
| W900KK-20-R-0020_Amend 01-ATFS_.docx | DOCX document | |
| W900KK-20-R-0020_RFI_AGATCS_2021.docx | DOCX document | |
| W900KK-20-R-0020_SOW-FD_RevC111419.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK (SOW)
ARMY GROUND AERIAL TARGET CONTROL SYSTEM SUPPORT, DEVELOPMENT & PRODUCTION
Delivery Order 0001
Transition and Cyber
Prepared By
Threat Systems Management Office (TSMO) Project Manager for Cyber, Test & Training (CT2) Program Executive Office for Simulation Training and Instrumentation Bldg. 3203 Hercules Road, Redstone Arsenal, AL 35898 -7458
Table of Contents
| 1.0 | OBJECTIVE | 1 |
| 1.1 | Background | 1 |
| 1.2 | Scope | 1 |
| 2.0 | APPLICABLE DOCUMENTS AND DEFINITIONS | 2 |
| 2.1 | Delivery Orders | 2 |
| 2.2 | Applicable Documents | 2 |
| 2.3 | Definitions | 2 |
| 3.0 | REQUIREMENTS | 3 |
| 3.1 | General | 3 |
| 3.2 | Meeting and Reviews | 5 |
| 3.3 | System Upgrades | 5 |
| 3.4 | Other Direct Costs | 6 |
| 3.5 | Travel | 6 |
| 3.6 | Environmental | 7 |
| 4.0 | SAFETY | 7 |
| 4.1 | Safety Program Plan | 7 |
| 4.2 | Safety Assessment Report (SAR) | 7 |
| 4.3 | Accidents/Incidents | 8 |
| 4.4 | Operations Safety | 8 |
| 5.0 | SECURITY MANAGEMENT | 8 |
| 6.0 | CYBERSECURITY | 10 |
| 6.1 | Cybersecurity Training | 11 |
| 6.2 | Cyber Documentation | 11 |
| 6.3 | Cyber Tools and Reports | 11 |
| 7.0 | PRODUCT/QUALITY ASSURANCE | 14 |
| 7.1 | Quality System Plan (QSP) | 14 |
| 7.2 | Parts, Materials, and Processes Control Program | 15 |
| 7.3 | Electronics Fabrication Procedures | 16 |
| 7.4 | Test Plans/Reports | 16 |
| 7.5 | Validation of Special Inspection/Test Equipment | 16 |
| 7.6 | Quality Accreditation Programs | 16 |
| 7.7 | Latent Defects | 17 |
| 8.0 | CONFIGURATION MANAGEMENT/TECHNICAL DATA | 17 |
| 8.1 | Configuration Planning and Management | 17 |
| 8.2 | Technical Reviews | 17 |
| 8.3 | Configuration Identification (CI) | 17 |
| 8.4 | Technical Data | 17 |
| 8.5 | Serialization | 18 |
| 8.6 | Item Unique Identification (IUID) | 18 |
| 8.7 | Engineering Change Proposals (ECP) | 18 |
| 8.8 | Configuration Control | 19 |
| 8.9 | Configuration Status Accounting (CSA) | 19 |
| 8.10 | Configuration Audits | 19 |
| 9.0 | GOVERNMENT FURNISHED PROPERTY | 19 |
| 10.0 | INVENTORY | 20 |
| 11.0 | PROPERTY MANAGEMENT SYSTEM | 20 |
| 12.0 | ENTERPRISE-WIDE CONTRACTOR MANPOWER REPORTING APPLICATION (eCMRA) | 20 |
| 13.0 | IMPORT/EXPORT, END-USER CERTIFICATE AND ITAR COMPLIANCE | 21 |
| 14.0 | CONTRACTOR TRANSITION PHASE-OUT & PHASE-IN | 21 |
| 14.1 | Contractor Phase-In | 21 |
| ACRONYM LIST | 22 | |
| APPENDIX A | 26 | |
| APPENDIX B | 29 |
UNCLASSIFIED/FOUO
STATEMENT OF WORK
ARMY GROUND AERIAL TARGET CONTROL SYSTEM
SUPPORT, DEVELOPMENT & PRODUCTION
i iii
STATEMENT OF WORK (SOW)
ARMY GROUND AERIAL TARGET CONTROL SYSTEM
SUPPORT, DEVELOPMENT & PRODUCTION
Delivery Order 0001 Transition and Cyber
1.0 OBJECTIVE
This Statement of Work (SOW) establishes the Delivery Order (DO) #0001 contractor tasks to complete the contract transition phase-in process and to conduct annual cyber security updates to the Army Target Control System.
Unless otherwise noted in this SOW, requirements for DO #0001 are defined in the base AGATCS support, development and production (SDP) SOW, W900KK-20-R-0020. In case of a conflict between the requirements and documents cited herein and the Base AGATCS SDP SOW, this SOW will take precedence.
Background The Army Target Control System (TCS), currently known as the Army Ground Aerial Target Control System (AGATCS), is the Army’s primary aerial (full scale, subscale, rotary wing, small unmanned aerial system (SUAS)), and surface (ground/maritime) target control system. AGATCS enables remote control of Army targets with a single control system in support of weapon system live fire testing necessary for lethality evaluation and sensor package testing for evaluation of suitability and effectiveness. AGATCS systems are fielded to Army Test and Evaluation Command (ATEC) Test Centers: (White Sands Missile Range (WSMR), NM; Yuma Proving Grounds (YPG), AZ; Aberdeen Proving Grounds (APG), MD; Redstone Arsenal, AL, Dugway Proving Ground (DPG), UT) and TSMO Aerial Target Flight Services (Ft. Bliss, TX). Additional development to integrate new targets and new target control capabilities continues per the Test Capabilities Requirements Document (TCRD) prepared by ATEC.
AGATCS includes other areas of target control such as target test sets, avionics, and target instrumentation.
Scope This Statement of Work (SOW) defines the general requirements for DO #0001 to conduct annual cybersecurity software updates to the Army TCS and to conduct the phase-in transition required to execute this contract for the support, development and production of new targets and new target control capabilities into the AGATCS and associated ancillary equipment and to provide upgrades for other miscellaneous target control systems. The Army Target Control Systems (TCS) will be located at various Army, Navy, Air Force or other locations.
2.0 APPLICABLE DOCUMENTS AND DEFINITIONS
Delivery Orders Delivery Orders (DOs) will be issued to accomplish specific requirements. Each DO will have a SOW which references requirements identified at the base Indefinite Delivery/Indefinite Quantity (IDIQ) level but with order level specific requirements which provide more detail. DOs may be issued at any time during the ordering period of the base IDIQ. Additionally, each DO may contain DO specific Contract Data Requirements Lists (CDRLs).
Applicable Documents The applicable top-level documents are contained in the Contract Document Summary List (DSL), by number, title, date, contract reference and category. The document versions specified on the DSL take precedence over the generic references (those without the revision letters) cited in the SOW.
Performance specifications, engineering specifications, drawings, software documentation, operations manuals, and other available documentation generated by previous original equipment manufacturers and engineering service contractors for the Army TCS that technically defines existing hardware and software.
All data associated with this requirement will be in accordance with (IAW) Distribution Statement D.
Definitions
2.3.1 “Army TCS” hereafter refers to all AGATCS and AGATCS ancillary equipment as well as any next generation AGATCS and Target Interface Control Units (TICU) equipment with a different naming convention. General statements referring to the AGATCS shall be interpreted to include AGATCS and associated hardware including any prototype equipment.
2.3.2 “Ancillary equipment” is defined as surface (ground/maritime) target instrumentation (STI), aerial target instrumentation (ATI) and control and monitoring equipment for aerial, ground, and maritime targets. Included are the components of a target group set such as the transponder, datalink, encoder/decoder device, TICU and associated test equipment, avionics package, ground target interface equipment, maritime target interface equipment, vehicle control module, power conditioning modules, engine interface modules, system disconnect switches, emergency stop systems, radios, Global Positioning System (GPS) receiver, antennas and antenna switch, range interface processor; simulation/visualization processor, test sets, launch control equipment; and other airborne/ground/maritime target equipment. Also included are components for control and monitoring such as laptops, computers, antennas, monitors, video systems, and cables.
2.3.3 “Other airborne/ground/maritime target equipment” is defined as auxiliary and/or add-on devices which require control from the AGATCS to include autopilots, gyros, Inertial Measurement Units (IMU), bus nodes, processors, power supplies, actuators, payloads, altimeters, sensors, brackets, and wiring/cabling connecting those devices.
2.3.4 Any references to “the Government,” unless otherwise specified, shall mean the Procuring Contracting Officer (PCO), the Contracting Officer Representative (COR), or to the extent authorized by the PCO, the Government Project Director.
3.0 REQUIREMENTS
General The requirements defined herein form the basis for all supplies and services to be delivered to the Government. This SOW defines the scope of work for this DO. The requirements to be performed as part of engineering development were defined in general terms by the Base SOW. Specific tasks are further defined in this DO SOW and include the following:
a) The contractor shall incorporate completed and tested software code updates (modifications, additions and system change requests (SCRs)) into the next software baseline release. The contractor shall update cybersecurity for the system per the latest cybersecurity requirements and include this into the next software baseline release. This process shall be completed once annually and the image of the software baseline shall be delivered to the Government. Details for cybersecurity requirements are outlined in Section 6 of this SOW.
b) The contractor shall prepare a transition phase-in plan outlining the transition phase-in period. During the transition phasein period the contractor shall prepare to and assume responsibility for AGATCS. Details for phase-in requirements are outlined in Section 14 of this SOW.
The contractor shall ensure compliance with the contract requirements and delivery of the required products and incidental services. The Government shall retain unlimited rights to all work, created, generated, or produced and required to be delivered under all DOs as defined at DFARS clause 252.227-7020 (Rights in Special Works).
In accomplishing the work outlined in the SOW, the contractor shall not duplicate any work required by any other government contract. The contractor shall make known to the Government if duplicate work is requested by any Government agency.
Program Management The contractor shall perform all management functions required to fulfill the requirements as stated in this SOW. The contractor shall designate a single point of contact (POC) to serve as the Government’s POC. The Government does not require the establishment of field offices for performance under this contract.
Kickoff Meetings/Post Award Conferences The contractor shall participate in a Post Award Conference after DO award as directed by the Government. This meeting will be either via telecom or at the contractor’s facility. Key personnel and points of contact for both parties will be identified. The contractor shall be prepared to discuss the phase-in plan and the respective responsibilities of all parties. The purpose of the conference is to ensure that the contractor is prepared to execute the work required in the SOW. The contractor shall place emphasis on management plan implementation, agreement on metrics and measures, operating procedures, transition plan and other contract matters. The contractor shall prepare and submit Record of Meeting/Minutes in accordance with IAW CDRL A024.
Management Plan The contractor shall submit a Management Plan. The management plan shall describe the contractor’s organization, assignment of functions, duties, and responsibilities, management procedures and policies, and reporting requirements for the conduct of contractually-imposed tasks, projects, or programs. The contractor shall prepare and submit Management Plan IAW CDRL A025.
Integrated Master Plan (IMP) The contractor shall prepare and submit an IMP and an Integrated Master Schedule (IMS) IAW CDRL A026. The contractor shall maintain and manage to the IMP and IMS developed for each specific DO, including appropriate program milestones with corresponding entrance and exit criteria. The IMP shall include a detailed account of all tasks necessary to accomplish the goals and objectives of each specific DO.
Progress Reports The contractor shall prepare and submit Monthly Progress Reports IAW CDRL A027. The report shall include schedules (proposed and actual), description of significant events (problems encountered, resolution, tests conducted, major findings), and disposition of the task(s) (cancelled, completed, carried forward to another DO).
Technical Reports The contractor shall prepare Technical Study/Services Reports IAW CDRL A002 to document the work accomplished and results obtained from engineering studies and analyses or specific technical services performed as defined in appropriate DOs. The contractor shall prepare and submit Scientific and Technical Reports IAW CDRL A002.
Final Report The contractor shall submit a Final Report at the conclusion of each DO IAW CDRL A027. This report shall document all work performed under each effort, and shall include all designs, analyses, test results, study findings, and recommendations.
Financial Reports The contractor shall prepare the following:
· Performance and Cost Report IAW CDRLA007
· Contract Funds Status Report IAW CDRL A038
· Contract Invoicing and Payment Report IAW CDRL A012
· Contract Work Breakdown Structure IAW CDRL A037 Work Control All data interchange shall be conducted in a digital environment compatible with the latest version of Microsoft Office family of products. The Contract shall query Government to ask for a designated standard naming convention for all electronic submissions as required.
Meeting and Reviews The contractor shall conduct, attend, and participate in meetings and reviews. The specific locations, dates, and duration of the meetings will vary based on requirements. Meetings and reviews will be chaired by a government representative. The contractor shall prepare drawings and other data to aid in the presentations. The contractor shall have key personnel and support available to carry out the meeting. The contractor shall explain assumptions and methodologies in arriving at particular conclusions, recommendations, or alternatives in the accomplishment of the DOs. Subcontractors shall attend meetings and reviews when required to address key elements. The contractor shall prepare the meeting agenda, meeting minutes and presentation material appropriate for the meetings and reviews. The contractor shall prepare and submit Record of Meeting/Minutes IAW CDRL A024.
Except where noted herein, meetings and reviews shall be considered fulfilled when the following items are completed:
| a. | A meeting has been conducted and reviews are presented to the Government. |
| b. | Topics required for discussion and presentation have been covered. |
| c. | Action items requiring contractor response have been resolved. |
| d. | The Government has accepted the meeting minutes. |
Technical Interchange Meeting (TIM) The contractor shall participate in Technical Interchange Meetings (TIMs). During these meetings, the contractor shall present necessary data to enable a joint review of its various assigned efforts, along with attendant schedules, and resource expenditures. The contractor shall participate in technical discussions and inform the COR, in a timely fashion, of any problems with contract execution. The contractor shall present proposed solutions. The contractor shall conduct, attend, and participate in Verification, Validation and Accreditation (VV&A) meetings, and other meetings as scheduled by the PCO or written designee. The contractor shall submit Report, Record of Meeting/Minutes IAW CDRL A024 and submit Presentation Material IAW CDRL A022.
System Upgrades The contractor shall integrate software and cybersecurity updates to the Army TCS to achieve a target system capable of meeting the requirements of state-of-the-art weapons systems undergoing research, development, test and evaluation (RDT&E). Software and cyber updates shall be integrated into the defined end item and tested as a complete operational unit. Testing can be conducted using factory qualification testing (FQT) or field testing, when required due to the nature of the change. Prior to using any commercial software, the Contractor shall provide copies of the software license agreements for the Government’s review. All software license agreements shall adhere to federal procurement law.
Other Direct Costs The Government may require the Contractor to purchase hardware, software, firmware, maintenance, insurance, related supplies and other direct costs (ODCs) that are integral and necessary in support work as outlined in the SOW and subsequent orders. Such requirements will be identified at the time an order is issued or may be identified during the course of an order, by the Government or the Contractor.
ODCs, for material necessary for performance of this contract, shall be specified in individual orders and shall be reimbursed in accordance with the billing and payment clauses of this contract. The Contracting Officer will establish the maximum allowable amount of and determine the fair and reasonableness of the proposed price/prices. Proposed supplies and/or materials must be itemized and priced in the cost proposal. Prior to any purchases, the contractor shall coordinate requirements with the COR, for further approval by the PCO.
Travel Travel may be required to fulfill the requirements of the SOW. It is anticipated that contractor support may require travel both CONUS and OCONUS. Contractors shall be required to have a valid passport and current immunizations for OCONUS travel. The contractor shall be responsible for obtaining passports, immunizations, and/or visas for traveling contractor personnel. The contractor shall be responsible for funding and processing these requirements. Since the anticipated travel costs cannot be accurately forecasted, it shall be awarded on a reimbursable basis for actual allowable costs (supporting documentation required). All travel shall be in accordance with the Federal Travel Regulations (FTR) and the Joint Travel Regulations (JTR) and adhere to Federal Acquisition Regulation (FAR) 31.205-46. The contractor shall ensure that the requested travel costs will not exceed the amount authorized in this task order. Travel must be submitted for COR approval.
All travel must be authorized by the COR or other authorized approving official and be in compliance with the task order and all other applicable requirements. The contractor shall use only the minimum number of travelers and rental cars needed to accomplish the trip purpose. Travel shall be scheduled during normal duty hours whenever possible. Airfare will be reimbursed for actual common carrier fares which are obtained by the most reasonable and economical means. The contractor shall provide a Trip Report for each trip associated with a travel approval. The contractor shall maintain a summary of all approved travel, to include at a minimum, the name of the traveler, location of travel, duration of trip, total cost of trip.
Environmental All contractor and subcontractor activities shall be in compliance with applicable federal, state, and local environmental laws and regulations. The Contractor shall ensure that design, maintenance, operation, manufacturing, programmatic decisions, and trade-off studies strive to eliminate or reduce hazardous materials and wastes. For systems, subsystems, ancillary devices, or other items developed or modified under this contract, the contractor shall prepare a Hazardous Materials Management Program (HMMP) Plan IAW CDRL A010 and National Aerospace Standard (NAS) 411. The contractor shall not use any Class I Ozone Depleting Chemical/Ozone Depleting Substance (ODC/ODS) (identified at http://www.epa.gov/ozone/ods.html) or any ODC/ODS solvents (identified at http://www.epa.gov/ozone/snap/lists/index.html in the manufacture or support of items required by this SOW unless a waiver is obtained from the Army Acquisition Executive. Any ODC/ODS refrigerant alternatives used must appear in the Environmental Protection Agency’s (EPA)’s Significant New Alternatives Policy (SNAP) list (identified at http://www.epa.gov/ozone/snap/lists/index.html and have received a toxicity clearance from the U.S. Army Public Health Command (USAPHC). The contractor shall prepare annual HMMP Reports IAW CDRL A009. The HMMP Reports shall provide the following information: (1) Any of the following materials that are contained within a user end item: EPA 17 List materials (identified at http://www.epa.gov/opptintr/3350/33finb1.htm), beryllium, coatings (identified by MIL SPEC), functional fluids (e.g. coolant, hydraulic fluid, petroleum products), energetics/solid rocket motor components (including Explosives Class Number), advanced composite materials (e.g. fabricated from silica, graphite, carbon, boron, fiberglass), batteries, Class I/Class II ODS/ODC materials, and asbestos; (2) A general description (to include a graphic or drawing) of where these materials are located within the end item; (3) Required maintenance/repair/support materials to include: EPA 17 List materials, sealants, adhesives, coatings (identified by MIL SPEC), and Class I/Class II ODS/ODC materials; and (4) any Emergency Planning and Community Right-to-Know Act (EPCRA) 302/313 materials utilized in the manufacturing process (identified in EPA 550-B-19-003 / June 2019 and found at https://www.epa.gov/sites/production/files/2015-03/documents/list_of_lists.pdf). The contractor shall provide immediate notification of any proposed hazardous material mitigation/elimination efforts that may adversely impact schedules, cost and/or performance.
4.0 SAFETY
Safety Program Plan The contractor shall prepare and submit a Safety Program Plan IAW CDRL A023 covering operations and activities to be performed. The Safety Program Plan shall incorporate the controls for the safety of personnel and property and shall assure compliance with applicable Federal, State, Department of the Army and local safety and environmental requirements.
Safety Assessment Report (SAR) The contractor shall submit a Safety Assessment Report IAW CDRL A001.
Accidents/Incidents The contractor shall maintain an accident prevention program to ensure the Government assets are protected from damage and theft. The contractor shall prepare and report any accidents/incidents in the Accident/Incident Report IAW CDRL A011.
Operations Safety The contractor shall comply with all safety procedures and practices set out during mission support activities at host installation/ranges. The contractor shall be responsible for the safety of their personnel and provide contractor personnel with any required personal protective items such as safety shoes, protective eyewear, hearing protection and other personal protective items.
5.0 SECURITY MANAGEMENT
The general scope of the work defined by the SOW is unclassified. However, the contractor may be required to be at a location where other classified work is being conducted or classified material may be disclosed to the contractor in the normal conduct of work. Therefore, in accordance with the Defense Department (DD) Form 254, Contract Security Classification Specification, the contractor shall provide personnel with the necessary security clearances and shall provide the appropriate protection for classified or sensitive information normally acquired in the performance of the SOW. This DO SOW will not require classification above the level of the base IDIQ DD254, therefore a separate DD254 will not be issued for this DO.
5.1 Classified information provided by the Government in support of the Army TCS, or developed or acquired by the contractor in accomplishing this contract, shall be handled in accordance with the procedures established in DoD 5220.22-M, National Industrial Security Program Operating Manual, and in accordance with the DoD Form 254, DoD Contract Security Classification Specification.
5.1.1 For Official Use Only (FOUO) information provided by the Government in support of the Army TCS, or developed or acquired by the Contractor in accomplishing this contract, shall be handled in accordance with the procedures established in DoD 5200.1-R, DoD Information Security Program.
5.1.2 The Contractor shall provide any request for release of information on the Army TCS from persons or organizations outside of the Government. All request will be referred to the Contracting Officer for consideration in accordance with DoD 5400.7-R, DoD Freedom of Information Act (FOIA) Program.
5.1.3 The contractor may provide release of general business reports or product information to the general public, including media representatives, pertaining to the contractor’s organization, finances, or publicly available products if not restricted in any way by the SOW.
5.1.4 Contractor employees, to include subcontractor employees, requiring access to Army installations, facilities and controlled access areas shall complete Anti-Terrorism (AT) Level I awareness training within 30 calendar days after DO award date. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the PCO or COR, if assigned. AT level I awareness training is available at the following website: https://atlevel1.dtic.mil/at.
5.1.5 Access and General Protection/Security Policy and Procedures. Contractor and all associated subcontractors employees shall comply with applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by Government representative). The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements as directed by DOD, Headquarters, United States Department of the Army (HQDA) and local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.
5.1.6 AT Awareness Training for Contractor Personnel Traveling Overseas. This standard language text requires US-based contractor employees and associated subcontractor employees to receive Government provided Area of Responsibility (AOR) specific AT awareness training as directed by Army Regulation (AR) 525-13. Specific AOR training content is directed by the combatant commander with the unit Antiterrorism Officer (ATO) being the local point of contact.
5.1.7 IWATCH Training. The contractor and all associated subcontractors shall brief all employees on the local watch program (training standards provided by the requiring activity ATO). This local developed training shall be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 60 calendar days of award and within 30 calendar days of new employees commencing performance with the results reported to the PCO or COR no later than 60 calendar days after award.
5.1.8 The contractor shall complete the DOD Information Assurance Awareness training prior to accessing the Information System (IS) and then annually thereafter.
5.1.9 The contractor shall develop an Operations Security (OPSEC) Standing Operating Procedure (SOP)/Plan IAW CDRL A019 to be reviewed and approved by the responsible Government OPSEC officer, per AR 530-1, Operations Security. This is required for contracts that require an OPSEC standing Operating Procedure/Plan This SOP/Plan shall include the Government's critical information, why it needs to be protected, where it is located, who is responsible for it, and how to protect it. In addition, the contractor shall identify an individual who shall be an OPSEC Coordinator. The contractor shall ensure this individual becomes OPSEC Level II certified per AR 530-1.
5.1.10 For Contracts that Require OPSEC Training. Per AR 530-1, Operations Security, new contractor employees must complete Level I OPSEC training within 30 calendar days of reporting for duty. All contractor employees must complete annual OPSEC awareness training.
5.1.11 For Information Assurance (IA)/information technology (IT) training all contractor employees and associated subcontractor employees shall complete the DoD IA awareness training before issuance of network access and annually thereafter. All contractor employees working IA/IT functions shall comply with DoD and Army training requirements in DoD 8570.01-M and AR 25-2 within six months of employment.
5.1.12 For Contract Requiring Performance or Delivery in a Foreign Country, DFARS 252.225-7043, Antiterrorism/Force Protection for Defense Contractors Outside the US. This clause applies to both contingencies and non-contingency support. The key AT requirement is for non-local national contractor personnel to comply with theater clearance requirements and allows the combatant commander to exercise oversight to ensure the contractor’s compliance with combatant commander and subordinate task force commander policies and directives.
5.1.13 For contracts that require handling or access to Classified Information. Contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires contractors to comply with The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M) and any revisions to DOD 5220.22-M, notice of which has been furnished to the contractor.
6.0 CYBERSECURITY
The contractor shall provide Information Assurance (IA) system-level support functions IAW provisions in the following documentation and references in Special Provisions (Appendix A of the SOW):
The contractor shall implement and/or be compliant with the following:
· Army Best Business Practices Federal Information System Management Act (FISMA) security requirements, Appendix II of OMB A-130
· Security Technical Implementation Guides (STIGs) compliance, patch management, Information Assurance Vulnerability Management (IAVM), AR 380-5
· National Security Telecommunications and Information Systems Security Policy (NSTISSP), No. 11 with revisions
· Department of Defense Instruction 8500.1: Cybersecurity, DoDI 8500.01
· Network Enterprise Technology Command (NETCOM) Tactics Techniques Plans (TTPs)
· Department of Defense Instruction 8510.01: Risk Management Framework (RMF) for DOD Information Technology (IT), DODI 8510.01
· The Federal Information Processing Standard (FIPS) Publication 140-2, (FIPS PUB 140-2)
· National Institute of Standards and Technology (NIST), Special Publications (SP) 800-53 and 800-53A Security and Privacy Controls for Federal Information Systems and Organizations
· NIST SP 800-39
· FIPS 200-Minimum Security Requirements for Federal Information and Information Systems
Cybersecurity Training The contractor shall require that lead and support personnel performing IA-enabled job functions possess the Information Assurance Management (IAM) or Information Assurance Technical (IAT) certification relevant to their role within the execution of this contract and IAW DoDD 8140.01, DoD 8570.01-M and AR 25-2 (4-3 Information Assurance Training) engineers, analysts, and technicians shall complete the required DoD Cybersecurity Training on an Annual basis. Method of training for "DoD CyberAwareness Training" is https://cs.signal.army.mil/courses.asp, titled "DoD Cyber Awareness Training.” The contractor’s CybersecurityTeam shall complete the required "Cyber Security Fundamentals (CSF) formerly known as the IAF" every two years.
Cyber Documentation The contractor shall establish a program cybersecurity liaison with the Government or designee to provide and maintain up-to-date status of cybersecurity accreditation/remediation efforts IAW CDRL A003. The contractor shall assist in the upkeep of the System Security Plan (SSP), System Contingency Plan (SCP), System Configuration Management Plan (SCMP), systems Plan of Action and Milestones (POA&M), STIG Deviation Reports, Accreditation Boundaries, Software and Hardware Lists for each system configuration.
Cyber Tools and Reports The contractor shall configure the system to maintain an Authority to Operate (ATO) certification to the Risk Management Framework (RMF) Confidentiality Integrity and Availability (CIA) and Certification Level (CL). The contractor shall coordinate with the Government to maintain the system accreditation by incorporating STIG compliance updates and mitigating the results of penetration testing into all software baseline release activities. The contractor shall perform automated and manual IAVM scans per the latest STIG requirements and incorporate the updates into each subsystem/system software revision. In the event that Defense Information Systems Agency (DISA) ceases support for the current, Information Assurance toolset (For example: Assured Compliance Assessment Solution (ACAS)/Nessus and Security Configuration Automation Protocol (SCAP) is required for Vulnerability Testing, and for Security Coding Tool an example is Fortify), the contractor shall migrate to an alternative toolset, an action that will be directed by the Government. This data shall be incorporated into the appropriate System POA&M in order to maintain the ATO. The contractor shall fix or mitigate items from the POA&M per Government direction and shall update. The contractor shall incorporate IAVM updates for each system configuration into the system software development process, to include sub-systems, IAW the POA&M; IAVM updates shall be integrated into the fielded system software release IAW approved SSP and NETCOM TTP or in each software revision, whichever comes first.
The contractor shall prepare and submit a schedule for Information Assurance activities including system cybersecurity updates for insertion into system software releases, the update cycle for STIG review, implementation, and compliance, mitigations, technical reports, and any other pertinent IA activities IAW CDRL A003.
The contractor shall support the annual review of each accredited system/sub-system's IA controls according to Federal Information Security Management Act (FISMA) guidance in conjunction with the TSMO Information System Security Manager (ISSM) and or PEO STRI IA designee. The contractor shall conduct cybersecurity scans on Government Furnished Equipment (GFE).
The contractor shall follow production specification and evaluation requirements of the National Institute of Standards and Technology (NIST), Special Publications (SP) 800.53 Security and Privacy Controls for Federal Information Systems and Organizations, Committee on National Security Systems Instruction (CNSSI) 4009, CNSS Glossary, Common Criteria, and National Information Assurance Partnership (NIAP) Approved Product List (APL). All incorporated IT products, and IA-enabled IT products that require use of the product's cybersecurity capabilities, acquired under the contract, shall comply with the National Security Telecommunications and Information Systems Security Policy (NSTISSP) No. 11 "National Policy Governing the Acquisition of Information Assurance (IA) and IA-enabled Information Technology Product." All contractor developed products shall be secured IAW STIG’s and tested with a Software Code Security Tool in order to make sure contract develop software is secure prior to be applied to baseline of system.
Cyber Reports and Tasks Schedules The contractor shall provide technical support on developing the following reporting requirements IAW CDRL A003.
· Assistant Secretary of the Army for Acquisition, Logistics & Technology ASA (ALT), Department Chief Information Officer (CIO)-G6 Headquarters, and PEO STRI Tasks
· Quarterly IAVA Reports
· IAVA Reports could be more than quarterly if a tasker requires PEO STRI, ASA (ALT) or Department CIO-G6 Headquarters requests an update.
· FISMA Annual Review Reports
· ACAS/Nessus Scan Reports
· SCAP Scan Reports on all COTS software
· Database Scan Reports
· Software Security Reports
· Updated NETCOM Software and Hardware Lists
· STIG Deviation Reports
· STIG Checklists
· IAVA Reports
· Ports, Protocols and Services (PPS) Lists
· STIG Lists (by type, version and release)
· Updated Configuration Drawings
· POA&M
· RMF Re-accreditation Reports
· ACAS/Nessus Scan Reports
· SCAP Scan Reports on all COTS software
· Database Scan Reports
· Software Security Reports
· Updated Software and Hardware Lists
· STIG Deviation Reports
· STIG Checklists
· IAVA Reports
· Ports, Protocols and Services (PPS) Lists
· STIG Lists (by type, version and release
· Updated Configuration Drawings
· POA&M
· Vulnerability Scan Reports Bi-Annually
· ACAS/Nessus Scans
· SCAP Scan Reports on all COTS software
· Database Scan Reports
· Software Security Reports
· STIG Deviation Reports
· Updated Configuration Drawings
· POA&M
· Cybersecurity Posture Analysis Checklist (CPAC)
· ACAS/Nessus Scan Reports
· SCAP Scan Reports on all COTS software
· Database Scan Reports
· Software Security Reports
· Updated Software and Hardware Lists
· STIG Deviation Reports
· STIG Checklists
· IAVA Reports
· Ports, Protocols and Services (PPS) Lists
· STIG Lists (by type, version and release
· Updated Configuration Drawings
· POA&M
· Training Reports Monthly
· Acceptable Use Policy (AUP)
· Privileged Access Agreements (PAA)
· RMF Monthly Report
· Annual Cyber DOD Certificates
· Cyber Security Fundamentals
· MISC Cyber Training/Certification (Security +, Other Cyber Training)
Computer Hardware Enterprise Software Solutions Program (CHESS)
The Contractor shall comply with the Army's Computer Hardware, Enterprise Software Solutions (CHESS) program, under PEO Enterprise Information System. CHESS is the mandatory source for commercial Information Technology (IT) purchases. CHESS contracts provide IT products and services that comply with Network Enterprise Technology Command (NETCOM), Army and DOD policy and standards. The Contractor shall procure commercial hardware and software IT requirements by utilizing CHESS contracts and DOD Enterprise Software Initiative agreements first, regardless of dollar value. Any purchase made outside of CHESS contracts requires a waiver. A complete list of CHESS contracts and the on-line waiver process can be found at https://chess.army.mil. Reference Army Policy Notice 09-44A, Use of CHESS as the Primary Source for Procuring Commercial Information Technology (IT) Hardware and Software.
7.0 PRODUCT/QUALITY ASSURANCE
The contractor shall provide Product Assurance (PA) technical expertise to include the utilization of PA management and technical principals, inspection techniques and other analytical and empirical tools during the development and production of systems/subsystems/components developed.
The contractor shall implement and maintain a quality system that meets the requirements of ANSI/ASQC/Q9001/ISO/Q9001/Q10012-1 or propose an equivalent system. The contractor's quality procedures, planning and all other documentation and data that comprise the quality system (for both hardware and software) shall be made available upon Government.
Quality System Plan (QSP) The contractor’s QSP shall describe in detail the approach to implement and maintain a basic quality system that meets the requirements of ISO 9001/ASQ9001/ISO 10012, AS9100 or equivalent. The QSP shall provide for controls of process and product characteristics and include criteria and methodology that are used to validate conformance to performance specifications and to achieve functional areas in the design, test, production, and management processes. If the contractor proposes to use a quality system that has not been approved under the Department of Defense Common Process (or Standard Process) Initiatives for DOD contracts, the description shall address at least the following twenty elements: management responsibility; quality system; contract review; design control; document and data control; purchasing; control of customer supplied product; product identification and traceability; process control; inspection and testing; control of inspection, measuring and test equipment; inspection and test status; control of nonconforming product; corrective and preventive action; handling, storage, packaging, preservation, and delivery; control of quality records; internal quality audits; training; servicing; and statistical techniques. The contractor shall submit Quality System Plan (QSP) IAW CDRL A028, if not submitted previously in the base SOW.
The QSP shall include a description of the contractor’s:
- Electrostatic Discharge Protection.
- Quality Assurance Provisions.
- Product Acceptance System and validation methodology.
- Environmental Stress Screening.
- Special Test/Inspection Equipment and validation methodology.
Parts, Materials, and Processes Control Program The contractor shall submit a Parts, Materials and Processes Control Program Plan as part of the QSP. The Parts, Materials and Processes Control Program Plan shall include a description of the methods of process controls, documentation, and verification of continued process improvement, and the controls and policies for the following subjects as applicable:
| - Parts Selection and Qualification |
| - Parts Survivability |
| - Parts Approval |
| - Approved Parts List |
| - Parts Control |
| - Supplier Selection |
| - Supplier Management |
| - Parts Screening |
| - Parts Documentation |
| - Parts Quality |
| - Parts Validation |
| - Plastic Encapsulated Devices |
- COTS Selection and Qualification
| - Obsolete Parts/Diminishing Manufacturing Sources and Material Shortages | - Test/analysis requirements to assure piece parts/materials |
| specification compliance for parts procured non-compliant to |
Government or DOD-adopted industry standards, including custom parts.
- Printed Wiring assembly (PWA) design and component mounting processes
- Electrostatic Discharge (ESD) control
- Maintenance and equipment used for electronic manufacturing processes
- Process controls, workmanship methodologies and procedures
- Training/proficiency of the workforce
- Rework and repair of PWAs and cable assemblies
Electronics Fabrication Procedures The contractor shall ensure that processes utilized for the manufacture and repair of electronic hardware produce assemblies and equipment that meet the system performance requirements. The contractor’s electronic fabrication plan shall describe the materials, methods, and verification criteria for producing quality electrical interconnections and assemblies and shall utilize process control methodologies for the planning, implementation, and evaluation of the fabrication process. The contractor shall use Institute for Interconnecting and Packaging Electronic Circuits (IPC)/ Electronic Industries Association (EIA) J-STD-001, Class 3 as guidance in developing this plan. The contractor shall submit the Electronic Fabrication Procedures as part of the QSP.
Test Plans/Reports The contractor shall prepare and submit acceptance test plans IAW CDRL A005. The contractor shall prepare and submit acceptance test reports IAW CDRL A006. For any product or service provided under this contract, the contractor shall make all draft test plans and/or draft reports available for Government review and verification prior to final CDRL submission.
Validation of Special Inspection/Test Equipment Inspection and test equipment used to verify acceptance criteria specified in the controlling document shall require validation. The contractor shall verify that the Special Inspection Equipment will perform the function for which it has been designed and shall perform an equipment validation/proofing. The validation/proofing shall be in accordance with contractor developed instructions and shall assure acceptance of known good hardware and the rejection of hardware with known faults. Any change that invalidates the original criteria shall require revalidation. The Government reserves the right to witness the validation/proofing activities. The Government shall have final approval for use of Special Inspection/Test Equipment.
Quality Accreditation Programs A contractor with an American National Standards Institute (ANSI)/ American Society for Quality (ASQ) Q9000 or ISO Q9001 third party registration (through a registrar accredited by the Registrar's Accreditation Board (RAB)) may submit the scope of the registration as evidence of the contractor’s compliance to the basic quality system requirements or a contractor may submit evidence of DOD approval of a Common Process or Standard Process Initiative for its basic quality system. If the contractor furnishes either of the cited documents as evidence of meeting the basic quality requirements, the overall QSP shall address the requirements of the Parts, Materials and Processes Control Program and the Electronic Fabrication Procedures sections of this document.
Latent Defects The contractor shall extend any commercial warranty provided by the original product manufacturer. Additionally, the contractor shall be responsible for any latent defects discovered during the life of the product. A latent defect is defined as a flaw, weakness, imperfection or defect which adversely affects critical performance requirements of the delivered product that is not apparent and cannot be discovered by observation or a reasonably careful inspection at the time of acceptance by the Government. The contractor shall extend a one year warranty on any end item deliverable at no cost to the Government.
8.0 CONFIGURATION MANAGEMENT/TECHNICAL DATA
Configuration Planning and Management The contractor shall designate a single point of contact as the technical authority with program responsibility for all Configuration Management (CM) functions. The Government will designate a Government CM person to interface with the designated contractor CM person to assure proper development and coordination of the CM process. The contractor shall prepare and submit a Configuration Management Plan IAW CDRL A029, if not submitted previously in the base SOW.
Technical Reviews The contractor shall participate in technical reviews. Reviews may include Systems Requirements Reviews (SRR) and Test Readiness Review (TRR). At each of these reviews, the contractor shall present applicable technical data for Government review. The contractor shall prepare Technical Data IAW CDRL A002.
Configuration Identification (CI) The contractor shall establish and maintain a Configuration Identification system of all hardware developed. All parts must be identified by part number.
Technical Data
The contractor shall maintain a Technical Data Package (TDP) in sufficient detail using best commercial practices IAW CDRL A030 to allow for full and open competitions for the Army TCS systems or subsystems. The contractor shall certify that all TDP documentation prepared as a result of this SOW contains sufficient information with which the Government can procure from other sources identical items, components, and software products without additional design effort or recourse to the original design activity.
The contractor shall also prepare and submit a variety of technical data sets. Those data sets shall include the following:
· Computer Software Product IAW CDRL A016
· Software Version Description IAW CDRL A018
· Software Design Description IAW CDRL A036
· Software Product Package IAW CDRL A035
The contractor shall submit all technical data created or updated to the Government. The contractor shall provide reproductions of existing technical data applicable to work performed IAW CDRL A008.
The contractor shall prepare and provide all documentation, drawings, and software to the Government in native format. This shall include all necessary support files and software/firmware in executable form. Method of delivery and media types shall be approved by the government.
Serialization The contractor shall establish and maintain an automated records system approved by the contracting officer (KO)/COR/ or Property Administrator for each serialized item or component. Property assigned serial numbers, such as tail numbers/hull numbers and equipment registration numbers, shall be in human-readable format on major end items when required by law, regulation, or military operational necessity. A tangible item used by DOD, which is designated by the KO/COR/ or Property Administrator to be uniquely tracked, controlled, or managed in maintenance, repair, and/or supply shall be required to have a serial number. The latest version of Military Standard (MIL-STD)-130, Marking of U.S. Military Property, shall be used for the marking of human-readable information. All production items with an acquisition cost of $5,000 or greater require a serial number. Unique tooling designated for preservation and storage in a Major Defense Acquisition Program will be considered a serially-managed item. Items that are classified as sensitive and are highly pilferable will require a serial number regardless of the acquisition cost.
Item Unique Identification (IUID) The contractor shall produce, assign and install an IUID label IAW DFARS 252.211-7003, MIL-STD-129 “Military Marking For Shipment and Storage” and MIL-STD-130 “Identification Marking of U.S. Military Property”. All production items with an acquisition cost of $5,000.00 or greater shall be marked with an IUID. The contractor shall apply the IUID labels to the end items or components identified and enter the IUID information into the centralized DOD IUID database prior to delivery of the item to the Government. The contractor shall assign and record an IUID number to all serialized items regardless of acquisition cost.
Engineering Change Proposals (ECP) The contractor shall document all proposed changes and submit to the government for review. The contractor shall document the proposed changes IAW CDRL A039.
Configuration Control The contractor shall maintain configuration control of hardware and software baselines during development. Once technical baselines are released via engineering change proposal (ECP)/ engineering revision request (ERR), no changes to baseline documentation shall be made without Government approval.
Configuration Status Accounting (CSA) The contractor shall maintain configuration control of all items being developed by means of a CSA system that provides the complete and accurate configuration history and status. The contractor shall prepare CSA information IAW CDRL A031.
Configuration Audits The contractor shall conduct Functional Configuration Audits (FCA) or Physical Configuration Audits (PCA) with Government participation when requested by the Government. The contractor shall prepare FCA and PCA plans IAW CDRL A032.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .