Attachment_4_PWS_Task_Order_0002.docx
DOCX document 55 KB Posted
- Attached to
- Command, Control, Communications, Computers, Combat Systems, Intelligence, Surveillance, and Reconnaissance (C5ISR) - Integrated Operations for High Performance Computing Scientific, Engineering, Analysis, and Outreach Support Services Federal contract opportunity
- Solicitation number
- W911QX-17-R-0008
About this file
Attachment 4 PWS Task Order 0002
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
C5ISR - INTEGRATED OPERATIONS FOR HIGH PERFORMANCE COMPUTING
TASK ORDER #2 PERFORMANCE WORK STATEMENT (PWS)
Scientific, Engineering, Cyber Security, Cybersecurity Defense Service Provider (CDSP), and Analysis Support Services
CONTENTS
C.1 MISSION, BACKGROUND & OBJECTIVES
C.1.1 Mission C.1.2 Background C.1.3 Objective
C.2 REQUIREMENTS
C.2.1 Overview C.2.2 General Professional, Scientific, Engineering, and Analysis Support C.2.3 Task Order Support Requirements C.2.4 Program & Project Management Support C.2.5 U.S. ARL Cybersecurity Defense Service Provider (CDSP), Assessment, and Research and Development (R & D) Support Services C.2.6 Corporate Information Management – Collaboration Environment Technical Support C.2.7 Research, Development, and Engineering Network (RDENET) Scientific System Administration Support C.2.8 Network Security and Assessments
C.3 DELIVERABLES
C.3.1 CONTRACT DATA REQUIREMENTS LISTS (CDRL DD FORM 1423)
C.3.2 PROGRAM MANAGEMENT PLAN
C.3.3 FINANCIAL REPORTS
C.3.4 TASK ORDER DELIVERABLES
C.3.5 MONTHLY STATUS REPORTS
C.3.6 OTHER DELIVERABLES
C.4 ANTI TERRORISM OPERATIONS SECURITY AT-OPSEC
C.1 MISSION, BACKGROUND & OBJECTIVES
C.1.1 MISSION The mission of the Army Research Laboratory (ARL) is to provide America's soldiers the technological edge by conducting a broadly based, multidisciplinary program of basic and applied research, exploratory development, and analysis, operating with the critical mass, synergy and flexibility to satisfy the Army's future technological needs. Research and technology development is the primary business of ARL. This task order will provide the ARL Computational and Information Sciences Directorate (CISD) with the research, development, and technology services necessary to support scientific and technological innovation in a variety of technical disciplines encompassed within Command, Control, Communications, Computers, Combat Systems, Intelligence, Surveillance, and Reconaissance (C5ISR).
C.1.2 BACKGROUND This Task Order Performance Work Statement (TO PWS) details the levels and types of contractor services required to sustain the mission and functions of the ARL CISD, primarily located at t he ARL facilities in Aberdeen Proving Ground, MD, Adelphi, MD, and White Sands Missile Range, NM. CISD provides scientific research and technology focused on information processing, network and communication sciences, information assurance, and battlespace environments, and advanced computing that create, exploit and harvest innovative technologies to enable knowledge superiority for the Warfighter. CISD's technologies provide the strategic, operational, and tactical information dominance across the spectrum of the US Army Research Laboratory’s (ARL) operations.
C.1.3 OBJECTIVE The TO 2 support shall include research and development (R & D) and technical services supporting the areas of Cybersecurity research, development, and assessment; Enterprise/ARL Open Campus solutions for collaboration, RDENET support, and Network Security. It shall also include directly related program and project management analysis and support. The contractor shall provide support to each of the subtasks listed within this Task Order PWS. Support should be called out in the cost breakout as a portion of each subtask.
C.2 REQUIREMENTS
C.2.1 OVERVIEW:
C.2.1.1 This Task Order supports Corporate Information support for software development and hardware implementation activities in the ARL/CISD Office of the Director, Research and Development efforts for Ad-hoc Mobile Networks as well as Network Security and Intrusion Detection Monitoring in the Network Sciences Division, and network and system support in the Information Sciences Division. The Any in-scope changes to the Government requirement for Contractor support will be linked to a particular Section C.2.2 through C.2.7.
C.2.2 TASK ORDER OVERSIGHT AND SUPPORT
The government requires one (0.5) FTE (960 hrs) Program Manager – Management Consultant (Senior) (KEY PERSONNEL) to address the tasks requested in section C.2.2.
The Contractor Program Manager(s) shall provide oversight and management over contract employees and tasks as well as oversight of sub-contractors IAW - BASE PWS C.2.2.1 and BASE PWS C.2.2.2.
C.2.3 PROGRAM & PROJECT MANAGEMENT SUPPORT
C.2.3.1 Program & Project Management and Analysis.
The Government requires: one (1) Management Analyst 3 – 1.920 hrs. and one (1) Management Analyst 1 - 1,920 hrs. for the following tasks:
C.2.3.1.1 The Contractor shall apply an understanding of the overarching and specific plans, programs and funding in support of ARL/CISD to provide program support and analysis of the technical mission and customer programs and projects, to include the Cybersecurity Defense Service Provider (CDSP) project.
C.2.3.1.2 The Contractor shall provide Government technical managers with support related to the overall planning, execution, reporting and monitoring of Mission and Customer programs and projects. The Contractor shall research, consolidate, prepare, and present status reports, charts and other media of current and projected status of technical deliverables, including the management of cost, schedule and performance. The Contractor shall provide recommendations for each milestone and identify issues that may delay or impact the program or its direction.
C.2.3.1.3 The Contractor shall monitor and report the utilization and execution of resources with consideration being given to Government mandated goals for obligations and disbursements and the impact project status will have on meeting these goals. The Contractor shall identify, research, and report anticipated shortages in resources, both labor and financial, that may impact programs and projects for Government review.
C.2.3.1.4 The Contractor shall assess programs and processes, review reporting documents, and provide decision-support analysis to provide recommendations for overall program direction.
C. 2.3.1.5 Specific requirements for one (1) Management Analyst 3 shall include:
· Prepares complete clear, concise, timely and accurate exectution status and analysis reports to be utilized by Directorate level managers and below.
· Provides recommendations for the preparation of future year budget requests while ensuring strategic alignment with CISD’s mission, strategic requirements, and performance goals.
· Closely monitors program budget execution and recommends courses of action to address areas of concern.
· Closely monitors program budget execution for correct use of funds within authorized parameters.
· Administers Financial Management for each Customer Connection within the Customer Service Management (CSM) database.
· Prepares and delivers CDSP CSM reports; to include invoices with balances, payments assigned to an invoice, payments by Command Communications Service Designator (CCSD), and payments without MIPR received.
· Provides support to the CDSP Sustainment team in the generation and distribution of CDSP invoices for services.
· Analyzes delinquent CDSP accounts and escalates for government evaluation and action.
· Generates, reviews, and submits the AMC DD1144 Support Agreement for all CDSP sponsors.
Specilaized Experience shall include:
· Minimum of (3) years of GFEBS experience to include Budgetary ERP and BI access roles
· Minimum of (2) years of experience with MS Office Products
· Demonstrable understanding of standard bookkeeping and account procedures for Government Accounting
· B.S. or B.A. degree in Business, Accounting, Information Systems, or other related fields preferred.
Specific requirements for one (1) Management Analyst 1 shall include:
· Works directly in GFEBS, the Government Financial Accounting System, to complete, collect, and distribute financial data for review by CISD Governmet personnel.
· Utilizes SAP application software, Enterprise Resource Planning (ERP) systems, and performs the functions of the Army Business Process areas of GFEBS.
· Prepares and processes funding documents for mission, customer, and OSD funding.
· Assists with updates for monthly financial status reports.
· Creates Work Breakdown Structures (WBS) and Sales Orders for incoming funding documents.
· Creates funding transfer documents of various types, as required.
· Provides support for senior financial personnel, as required.
· Generates and submits and distributes the AMC DD1144 Support Agremment for all CDSP sponsors.
Prepares and delivers CDSP CSM reports; to include invoices with balances, payments assigned to an invoice, and payments without MIPR received.
Specialized Experience shall include:
· Minimum of (1) year of GFEBS experience to include Budgetary ERP and BI access roles
· Minimum of (2) years of experience with MS Office Products
· Demonstrable understanding of standard bookkeeping and account procedures for Government Accounting
· B.S. or B.A. degree in Business, Accounting, Information Systems, or other related fields preferred.
C.2.4 U.S. ARL CYBERSECURITY DEFENSE SERVICE PROVIDER, ASSESSMENT, AND RESEARCH AND DEVELOPMENT (R&D) SUPPORT SERVICES
Contractors working within Task C.2.4 require a TS-SCI clearance.
For project and planning oversight in section C.2.4 the Government requires: one (1) Subject Matter Expert 1 (1920 hrs) , one (1) Subject Matter Expert 3 (1920 hrs), one (1) Subject Matter Expert 5 (1920 hrs)(KEY PERSONNEL), and one (1) Management Consultant (1920 hrs.) (KEY PERSONNEL) for full oversight and reporting.
C.2.4.1 The Contractor shall provide project management and technical support to ARL Cybersecurity Defense Service Provider (CDSP) and associated customers, including sites on the Non-Classified Internet Protocol Router Network (NIPRNET), Defense Research and Engineering Network (DREN) and other DoD Networks. The Contractor shall demonstrate past performance and a technical understanding of operating a Cybersecurity Defense Service Provider and executing services, including but not limited to vulnerability assessment support, anti-virus and anti-spyware support, Information Operations Condition (INFOCON) implementation, Information Assurance Vulnerability Management (IAVM) support, network security monitoring and intrusion detection, attack sensing and warning, situational awareness, host based security, incident reporting, response, and analysis, and computer network defense (CND) training at the highest accreditation level. The Contractor shall possess an understanding of applying security to research and engineering wide area networks, namely Defense Research and Engineering Network (DREN) and Secret DREN (SDREN), in an effort to support the test and evaluation (T&E) communities residing on the networks, as well as support for operational enterprise networks, specifically Non-classified Internet Protocol (NIPRNet) and Secret Internet Protocol Router Network (SIPRNet).
2.4.2 The Government requires: one (1) Engineer/Scientist 1 (1920 hrs), one (1) Subject Matter Expert 1 (1920 hrs), one (1) Subject Matter Expert 4 (1920 hrs), one (1) Technical Analyst 1 (1920 hrs), three (3) Technical Analyst 2 (5760 hrs) , two (2) Technical Analyst 3 (3840 hrs), two (2) Security Specialist 2 (3840 hrs), and two (2) Security Specialist 3 (3840 hrs) to perform the tasks in Section C.2.4.1 and include the following specific requirements and skills:
The Contractor shall:
· Perform and analyze monthly vulnerability scans of subscriber networks and provide monthly trending reports along with weekly status updates.
· Deploy Assured Compliance Assessment Solution (ACAS) for new subscribers and/or subscribers migrating from legacy Retina solutions to ACAS to include deployment and configuration. Ensure subscribers have information needed to leverage ACAS to its full capabilities as it applies to their requirements.
· Perform and provide external assessments for ARL CDSP subscribers to include obtaining a red or blue team assessment and creating and distributing lessons learned reports to the ARL CDSP subscriber base and tier 1.
· Provide recommendations to ARL CDSP subscribers concerning host-based anti-malware protection in compliance with DoD regulations and ensure subscribers have malware mitigation and response procedures in place. Ensure ARL CDSP subscribers create and maintain an anti-malware policy that is in compliance with DoD policy and regulations.
· Maintain accurate, current information regarding all ARL CDSP subscriber networks, provide recommendations for hardening the networks, and provide information and resources to develop subscriber cyber defense training materials.
· Monitor compliance levels after changes in INFOCON or Cyber Protection Condition (CPCON).
· Track changes or updates to the INFOCON and/or CPCON level and report compliance to tier 1 for all CDSP subscribers.
· Issue, track, and report IAVM status of all ARL CDSP subscribers.
· Provide recommendations regarding the development and progress of subscriber IAVM Plan Of Action and Milestones (POA&M).
· Perform proactive defensive actions using available CMRS capabilities.
2.4.3 The Government also requires: one (1) Technical Analyst 4 (1920 hrs), two (2) Security Specialist 2 (3840 hrs), one (1) Security Specialist 3 (1920 hrs), and one (1) Security Specialist 4 (1920 hrs), to perform the tasks in Section C.2.4.1 with the follow specific tasks and skills:
The Contractor shall:
· Maintain documented plans and procedures to augment existing personnel to surge operations in response to a major incident. The Contractor shall be able to maintain surge tempo for not less than 14 days.
· Execute yearly surge table top exercises to test Contingency Of Operations Planning (COOP).
· Ensure Interrogator Intrusion Detection systems (IDSs) are deployed on all subscriber networks in accordance with DoD policy. Perform regular active maintenance and tuning of the sensors to ensure effectiveness of the IDS devices.
· Perform collection, normalization, analysis, and correlation of network data to identify unauthorized and malicious activity. Sense changes in subscriber computer networks based on the analysis of current and archived security information. Use attack sensing and warning information to enhance cyber monitoring and detection services in response to emerging threats and provide this information to other CDSPs and tier 1 organizations.
· Continually perform real-time and retrospective intrusion detection analysis on Linux and Unix-based Intrusion Detection systems.
· Develop and maintain software scripts to automate analyst processes.
· Use ARL-developed Continuous Monitoring Risk Scoring (CMRS) capabilities to monitor all subscriber networks for network-based attacks and threats.
· Perform daily open-source intel checks of security blogs and websites for any new threats, new types of malware, new malware variants, zero day exploits, or any other information that can be used to create new IDS rules, or to perform retrospective data searches in order to protect subscribers’ sites immediately and in the future.
· Produce indications, warnings, and situational awareness reports for sharing and distribution to ARL CDSP subscribers, peer CND organizations, and tier 1.
· Perform incident and event reporting to tier 1, and law enforcement counter intelligence in accordance with Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510 reporting guidance.
· Safeguard all incident reports and supporting raw data so that valuable information is available for analysis by authorized network security analysts but protected against unauthorized disclosure.
· Provide 24x7 incident and event response to ARL CDSP subscribers and ensure response actions occur in compliance with DoD-mandated timelines.
· Provide ad hoc reports as required by the COR or Technical Monitor.
· Perform threat analysis in addition to tool development to enhance and evolve the analytical capability.
· Develop tools and methods to detect and identify any unauthorized activity to determine its origin and its malicious or hostile intent. Develop and advance tools that to decrypt decode hostile network traffic.
· Prepare and deliver cyber threat briefs on recent attacks and intrusions into DoD information systems to ARL CDSP subscribers and peer DoD organizations.
· Interact with peer threat analysis groups inside DoD and USG to maintain and share up-to-date knowledge of network threats facing similar organizations.
· Mentor and provide training for CND analysts in order to enhance their skill sets with new analytic t echniques and knowledge.
· Work with subscriber sites and their network operations centers to implement network blocks on perimeter routers, firewalls, and/or switches to prevent and mitigate network-based attacks and prevent further spread of malware infections.
C.2.4.4 The Contractor shall support the U.S. ARL Assessment team, as well as the ARL Cybersecurity Defense Service Provider (CDSP). The Contractor shall provide project management and technical support to ARL CDSP and assessment team client and associated customers, including sites on the NIPRNET, DREN, and other DoD Networks.
C.2.4.4.1 The Contractor shall demonstrate experience and technical proficiency in External Assessments (EA), to include Army Risk Management Framework (RMF) assessments, DISA Command Cyber Readiness Inspection (CCRI), and HPCMP Comprehensive Security Assessment (CSA). A demonstration of past performance in DIACAP, AR 25-2, DoD Evalutator Scoring Metrics (ESM) and DoD 8500 series is required. The Contractor shall have experience in planning, coordinating, executing and providing deliverables associated with a large-scale EA program.
C.2.4.4.1.1 The Government requires: one (1) Technical Analyst 3 (1920 hrs), one (1) Technical Analyst 4 (1920 hrs), to perform the tasks in Section C.2.4.4.1 and include the following specific requirements and skills:
· Provide a Cyber Operations and Services Manual to update, test, implement, and validate the most efficient and effective methods for conducting cyber vulnerability assessments in accordance with DoD and Army policy and guidelines.
· Perform approximately 25 onsite and 25 offsite DIACAP assessments annually across CONUS and OCONUS sites. Both remote and onsite assessments include validations under the DIACAP and site assistance visits to prepare CDSP customers for triennial Command Cyber Readiness Inspections (CCRI) from the Defense Information Systems Agency (DISA).
· Provide feedback to developers for incorporation into the Consolidated Virtual Inspection Process Pilot (CVIPP), a new DoD program to consolidate information assurance checklists and reduce a duplication of efforts and improve inspection efficiency through electronic communication.
· Identify and execute effective remote inspection procedures to ensure remote DIACAP inspections achieve the same effectiveness as onsite inspections.
· Implement a quality control process to ensure all ARL ACA scorecards and documentation meet high-quality standards.
· Recommend and maintain clear and reasonable quality control and quality assurance procedures to ensure delivery of high-quality reports.
C.2.4.5 The Contactor shall support the applied research, development, and engineering of cybersecurity capabilities to support the protection and defense of Army and DoD systems. The Contractor shall have experience in using a wide variety of programming and software development languages, as well as big data analytics and cloud technologies. The Contractor shall have experience in supporting Army and DoD research environments, consisting of Army and DREN enterprise data, in order to support Commander situational awareness at an executive level. The Contractor must have experience with implementation of the DoD Big Data Platform as a framework to support big data analytics. This scope also includes recommendations on utilization of new system functionality as well as outlining the risks, impact, and potential benefits of the different implementation approaches possible.
C.2.4.5.1 The Government requires: two (2) Engineer/Scientist 3 (1920 hrs), and one (1) Engineer/Scientist 4 (1920 hrs), to perform the tasks in Section C.2.4.5 and include the following specific requirements and skills:
The Contractor shall:
· Create and maintain a Cyber Operations and Services Manual to update, test, implement, and validate efficient and effective methods for conducting CMRS.
· Provide architecture, engineering, and development efforts to bring several different systems into a server-oriented architecture based on cloud technologies.
· Use basic and applied research to create, update, maintain, and expand real-time risk scores to evaluate the risk of DoD networks and systems being monitored by the ARL CDSP.
· Collect and store data from the following enterprise tools on Linux-based hardware using primarily open-source software (Interrogator, C&A TdB, CSM, HBSS ePO, LLAMA, Nessus, and others) as requested by the COR or Technical Monitor. The data shall be easily retrievable and organized in a way to enable rapid retrieval and correlation between data types in a federated approach.
· Coordinate with multiple Army Federally Funded Research and Development Centers to adapt and inject developed CMRS analytics into the ARL CMRS solution.
· Provide demonstrations of the ARL CMRS solution as requested by the COR or Technical Monitor.
· Develop and maintain a user interface for analyst to easily interact and run various types of queries against the stored data.
· Perform daily server maintenance and engineering to ensure the continuous operational functionality of the ARL CMRS hardware.
· Create and maintain project management plans and work breakdown structures for the development of the CMRS solution. Track progress of CMRS project tasks and provide updates to the COR on the status.
· Coordinate to ensure requests for information to ARL from Army and DoD constellation partners participating in CMRS development are appropriately answered and addressed in a timely manner.
· Import data collected by the Host Based Security System (HBSS) and Assured Compliance Assessment Solution (ACAS) established programs into the CMRS to compute the risk score.
· Consolidate and use the following existing systems in the ARL CMRS solution:
· Interrogator, C&A TdB, CMDSP Service Management tool (CSM) tool, JIGSAW, McAfee ePolicy Orchestrator (ePO) Host Agent, LLAMA, Incident reports from analysts, Detects from 20+ network traffic analysis tools, Enterprise Nessus (ACAS), Various port lists, HBSS, and CAS.
C.2.4.6 The Contractor shall have past performance in developing and applying scoring methodologies most effective in managing and mitigating risk. The Contractor shall also demonstrate an ability to correlate enterprise Information Assurance (IA) and CND capabilities to enable the on-going observation of DoD Networks and Information Systems (IS). The Contractor’s R&D efforts must include collaboration and information sharing with DoD agencies, industry and academia partners.
C.2.5 CORPORATE INFORMATION MANAGEMENT – COLLABORATION ENVIRONMENT TECHNICAL SUPPORT The Government requires: one (1) Engineer/Scientist 4 (1920 hrs), one (1) Engineer/Scientist 2 (1920 hrs), to perform the following tasks.
C.2.5.1 The Contractor shall support the Corporate Information Management Branch in its mission to provide the Army’s premier laboratory with the necessary resources (people, technology, and processes) to facilitate novel and innovating research and development (R&D) for the Soldier. Through collaboration and coordination within the Army, other services and their laboratories, industry, and academia, the ARL Corporate Information Management Branch requires support in the identification, design, development,, and implementation of strategies and technologies most effective in promoting and enabling collaboration with partners. The Contractor shall work with internal and external stakeholders to understand and formally document requirements and build business cases, specifically with a focus on the ARL’s Open Campus endeavor and its eight (8) science and technology (S&T) campaigns – Extramural Basic Research, Computational Sciences, Materials Research, Sciences-for-Maneuver, Information Sciences, Sciences-for-Lethality and Protection, Human Sciences, and Assessment and Analysis.
C.2.5.2 The Contractor shall provide formal recommendations on strategies, technologies and platforms to assist ARL scientists and engineers (S&Es) in sharing information and data with its partners, in order to establish and maintain synergistic relationships with international, academic, and entrepreneur communities.
C.2.5.3. The Contractor shall identify, design, develop, and implement accessible, online collaboration software/tools to accomplish the following:
1. Provide applicable program management tools
1. Provide applicable relational database management tools and techniques that facilitate collaboration
1. Share data and allow real-time desktop to desktop collaboration
1. Provide access and a real time Developer Environment for the development of High Performance Computing capability.
C.2.5.3.1 The Contractor shall ensure the management tools include the ability to access and share program documents, briefings and reports in a secure manner. The capability shall also require Defense Connect Online (DCO)-like conference capability, as well as a search engine to find and retrieve data in a wiki-like format.
C.2.5.3.2 The Contractor shall lead the architecture and employment of a highly-customized, flexible, and diverse collaboration environment to foster partnerships between internal and external parties. The environment shall serve as an incubator for transitions of technologies and capabilities and increase opportunities for technology advancement and transfer of research knowledge. Additionally, the environment shall include authentication mechanisms to apply access controls and establish need-to-know principles.
C.2.5.3.3 Required Specialized Experience The Contractor shall have a minimum of two years of development experience with Ruby On Rails and Redmine, be proficient in installing, configuring, deploying, and modifying Redmine, have proven experience in developing Redmine plug-ins in support of the ARL Open Campus Collaboration initiative, thorough working knowledge of Common Access Card and Yubi Key authentication. The contractor shall have excellent communication skills as end user training for Redmine, new plug-ins, and other applications shall be required. A working knowledge of the Java programming language is preferred.
C.2.6 RESEARCH DEVELOPMENT AND ENGINEERING NETWORK (RDENET) SCIENTIFIC SYSTEM ADMINISTRATION SUPPORT
The Government requires one (1) Subject Matter Expert 3 (1920 hrs) to perform the following tasks:
C.2.6.1 The Contractor shall perform Scientific System Administration (SA) and IA activities to assist Scientists and Engineers (S&Es) of the ARL within the Research Development and Engineering Network (RDENET). The Contractor shall possess a comprehensive understanding of the ARL’s Research, Development, Test, and Engineering (RDT&E) network and its ability to support Research and Development (R&D) activities that cannot be performed on production and/or enterprise networks.
C.2.6.1.1 The Contractor shall be required to perform the following IT and IA configuration and maintenance tasks to include, but not be limited to:
· Initial setup and configuration of RDT&E systems, adhering to all applicable IA requirements, controls, guidelines, and accreditation specifications as specified by the ARL-IAM office, RDENET Change Configuration Board (CBB), and Chief High Performance Computing Networking Branch (HPCNB).
· Managing RDENET systems and maintaining continued compliance with all applicable requirements.
· Developing centralized management and IT support systems, servers, and services to enhance efficiencies in maintaining RDENET systems’ conformance to applicable requirements.
· Creating, updating, maintaining, and submission of required IA documentation.
· Collaborating and sharing of information with the ARL S&Es to engineer the integration of R&D with IT systems and solutions.
C.2.6.2 The Contractor shall coordinate with ARL Information Assurance Management (IAM) personnel, HPCNB Networking personnel, ARL CDSP, and/or IA teams and personnel to maximize the security posture of the RDENET while ensuring the integrity, continuity, and capabilities required by the S&Es in order to perform their RDT&E mission.
Specialized Experience required for C.2.6 shall include:
· Strong background in the Windows Operating System, Linix Operating Sytem (SUSE, RHEL, Debian, Ubuntu, etc.), Linksus
· Working knowledge of Network Firewalls to include Astaro Security Linux, Cisco PIX, and Juniper SRX
· Familiarity with Monitoring and Provisioning software such as Puppet, Nagios, Ganglia, and Hobbit.
· A minimum of 5 years of system administration experience.
C.2.7 NETWORK SECURITY & ASSESSMENTS
C.2.7.1 Network Security
The Government requires one (1) Security Specialist 3 (1920 hrs), and one (1) Subject Matter Expert 3 (1920 hrs) to perform the following tasks:
Contractors working within Tasks C.2.7.1 and C.2.7.2 shall require a TS-SCI clearance.
The Contractor shall provide scientific subject matter expertise (SME) in cyber security to support an external customer for program product lines. The Contractor support shall include, Cybersecurity Science support regarding system requirements/capabilities, system functional analysis, system design, and development reviews; system integration, test and evaluation, training, material fielding, production, evaluation of technical capabilities, and technology readiness support. The Contractor support shall include influencing projects, proposals, and support of work from a Cybersecurity Science standpoint. The Contractor shall assist in defining, establishing, and influencing the Cyber Science aspects of executing technical cost, schedule, and performance objectives of acquisition programs. The Contractor shall provide Cyber Science subject matter expertise in the establishment of milestones for the progress of assigned systems through the total acquisition lifecycle. The Contractor shall provide assistance in planning, programming, coordinating and controlling the execution of Cybersecurity functions to meet program requirements with stakeholders. The Contractor shall assist in the development of complex Cybersecurity documentation within System Engineering Plans, Test and Evaluation Master Plans, System Specifications, and Integrated Master Schedules. The Contractor shall make formal/informal Cybersecurity presentations and prepare technical reports/papers of behalf of the Government. The Contractor shall provide advice and subject matter expertise to customer Tech Directors and APMs on Cybersecurity technical issues. The Contractor personnel shall not perform any inherently Governmental duties.
C.2.7.2 Security Assessments
In accordance with U.S. Cyber Command (USCC) Task Order (TASKORD) 13-0613, the ARL Web Assessment Team (WAT) evaluates the security posture of public-facing websites connected to the Department of Defense Information Networks (DoDIN) to enumerate exploitable vulnerabilities on DoDIN-connected web servers by conducting assessments from a non-DoD network.
The contractor shall be required to:
· Conduct formal security assessments on web-based applications, using both automated tools and manual techniques, including penetration testing tools and other hacking methods, in order to enumerate vulnerabilities in web technologies.
· Prepare a formal reports that highlight mission impact and ranking of each finding by severity.
· Work with web site administrators after the assessments to recommend strategies to mitigate the vulnerabilities, and harden the DoDIN sites.
· Work closely with the SBNAB CNSP Watch Officers and Net Defenders.
· Work closely with Threat Cell when new vulnerabilities are found and/or released.
· Support researchers with tool development, data acquisition/verification, and consultation on various tools and techniques.
Required specific experience:
· In-depth knowledge of both Linux and Windows operating systems, networking, network protocols, databases, scripting languages, and some programming.
· Extensive knowledge of web technologies: PHP, CSS, CMS, Apache, Burp, Metasploit, and other relevant technologies.
· Up-to-date knowledge of the latest vulnerabilities and versions of all these technologies, and keeping up with new technologies, products, and hacking techniques.
· Design new tests and techniques to probe for vulnerabilities
C.3 DELIVERABLES
C.3.1 CONTRACT DATA REQUIREMENTS LISTS (CDRL DD FORM 1423)
CDRLS shall be provided as exhibits in each individual Task Order. The Contractor shall use commercial standards and practices, when available, in lieu of these documents with the exception of the Department of the Army (DA) or DoD Technical Architecture documents, which are mandatory.
Electronic versions of Government documents can be found at the following web sites:
· Army Publishing Directorate: http://www.apd.army.mil
· DoD Forms Management Program: http://www.dtic.mil/whs/directives/infomgt/forms/formsprogram.htm;
· DoD ASSIST website: http://www.assistdocs.com.
C.3.2 PROGRAM MANAGEMENT PLAN
C.3.2.1 The Contractor shall prepare a Program Management Plan. The Contractor shall submit the Program Management Plan to the COR both electronically and hard copy thirty (30) calendar days after basic contract award for review. The COR will provide approval or comments within two (2) weeks of receipt. The Contractor shall submit a final Program Management Plan to the COR both electronically and in hard copy within one (1) week of receipt of approval.
C.3.2.2 The Program Management Plan shall address at a minimum:
· Personnel Management Plan (see Base PWS Section C.8.2)
· Recruitment Plan (see Base PWS Section C.8.3.1)
· Retention Plan (see Base PWS Section C.8.3.2)
· Telework Plan (see Base PWS Section C.4.2)
· Additional Contractor procedures for ensuring efficient operation of this task order.
C.3.2.3 The Program Management Plan shall be maintained and implemented. The Contractor shall update and submit to the COR electronically and in hard copy a revised Program Management Plan on a bi-annual basis at a minimum.
C.3.2.4 Notification of Program Manager (PM) Within three (3) calendar days following basic contract award, the Contractor shall provide the Government, in writing, the name and contact information of the PM and other management or supervisory personnel employed to perform work under this contract.
C.3.3 FINANCIAL REPORTS
The Contractor shall provide the monthly financial report to the COR electronically and in hard copy NLT the tenth day of every month. The financial reports shall include the breakdown of labor hours per contract employee by day, labor expenditures, travel expenditures, remaining funds and estimated date of funds running out at current rate. The Contractor shall ensure the financial report includes a written summary report of all costs to include incurred labor hours per contract employee, materials, travel expenditures, subcontracts, overhead expenses, and fees, remaining funds and estimated date of funds running out at current rate broken out by area of focus. The Contractor shall include detailed copies of all invoices submitted to date for payment from both the Prime Contractor as well as all SubContractors. The Contractor shall ensure each invoice details the labor categories, labor rates, labor hours, and all Other Direct Costs (ODCs). The contractor shall provide all financial reports in PDF and Excel formats.
C.3.4 TASK ORDER DELIVERABLES
The following standard reports are applicable to this TO. The Contractor shall submit all reports and TO deliverables to the TO COR for inspection and acceptance. The Contractor shall provide all reports and deliverables in accordance with the DD Form 1423, Contract Data Requirements List (Exhibit A, Section J of the contract). The Contractor shall adhere to the distribution statement as specified in specific TO. Required reports are:
| DI-MGMT-80004A | Management Plan |
| DI-MGMT-81911 | Work Management Plan |
| DI-MGMT-81797 | Program Management Plan |
| DI-MGMT-80368A | Status Report (delete paragraph 3.2.3) |
| DI-FNCL-80331A | Funds and Man-Hours Expenditure Report |
| DI-FNCL-81565C | Cost Data Summary Report |
| DI-FNCL-81765B | Contractor Business Data Report |
| DI-MGMT-81834A | Contractor’s Personnel Roster (include pending vacancies) |
· Safety Report: The Contractor shall provide a Safety Report that lists the safety certifications and training records for all Contractors working under this contract to the TO COR on a quarterly basis.
· Final Reports: The Contractor shall provide a final report summarizing the Contractor personnel activities and endorsed by the TO COR indicating that the work has been satisfactorily accomplished to the Contracting Officer within sixty (60) days following the end of the TO period of performance.
· Employee Roster: A roster of employees who will be performing under the contract TO will be submitted to the TO COR ten (10) days following TO contract award and updated within twenty-four (24) hours of any change.
· Government Furnished Equipment: The Contractor shall maintain and provide a spreadsheet or database of all Government furnished equipment that uniquely identifies each piece of equipment, it’s location, primary user, model number, serial number, and Government Hand Receipt holder id and name.
C.3.5 MONTHLY STATUS REPORTS
The Contractor shall provide monthly reports summarizing current program accomplishments for this TO. The Contractor shall deliver the monthly report to the COR on the tenth day of each month. The Contractor shall ensure that the monthly reports include a progress update for the covered time period, identification of any unresolved technical problems, meetings attended, planned activities, issues and recommendations for a path forward in each subtask area (C.2.1.-C.2.7).
The Contractor shall ensure the monthly report includes a written summary report of all costs to include labor, materials, subcontracts, overhead expenses, and fees, broken out by subtask. The Contractor shall provide current status and estimated financial requirements for the remaining period of performance The Contractor shall include detailed copies of all invoices submitted to date for payment from both the Prime Contractor as well as all SubContractors. The Contractor shall ensure each invoice details the labor categories, labor rates, labor hours, and all Other Direct Costs (ODCs). The Contractor shall include the following within the monthly reports:
· total number of contract employees currently on contract
· a listing of hired and/or separated employees during the reporting period
· status of any open positions and a description of efforts to fill those positions
· was Contractor Manpower Reporting (CMR) performed during the monthly reporting period? If so, what information was entered?
· A complete listing of employees and vacancies by subtask to include but not limited to name, position/title, clearance level, date of hire, date of separation, work site.
C.4 ANTI TERRORISM OPERATIONS SECURITY AT-OPSEC
AT Level I training. This standard language is for Contractor employees with an area of performance within an Army controlled installation, facility or area. All Contractor employees, to include subContractor employees, requiring access Army installations, facilities and controlled access areas shall complete AT Level I awareness training within 45 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and subContractor employee, to the COR or to the contracting officer, if a COR is not assigned, within 45calendar days after completion of training by all employees and subContractor personnel. AT level I awareness training is available at the following website: http://jko.jten.mil
Access and general protection/security policy and procedures. This standard language is for Contractor employees with an area of performance within Army controlled installation, facility, or area. Contractor and all associated sub-Contractors employees shall provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, HQDA and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in Contractor security matters or processes.
For Contractors requiring Common Access Card (CAC). Before CAC issuance, the Contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation in accordance with Army Directive 2014-05. The Contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.
For contractors that do not require CAC, but require access to a DoD facility or installation. Contractor and all associated sub-contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.
AT Awareness Training for Contractor Personnel Traveling Overseas. This standard language required US based contractor employees and associated sub-contractor employees to make available and to receive government provided area of responsibility (AOR) specific AT awareness training as directed by AR 525-13. Specific AOR training content is directed by the combatant commander with the unit ATO being the local point of contact.
iWATCH Training. This standard language is for Contractor employees with an area of performance within an Army controlled installation, facility or area. The Contractor and all associated sub-Contractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity ATO). This local developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 45 calendar days of contract award and within 45 calendar days of new employees commencing performance with the results reported to the COR NLT 45 calendar days after contract award.
Army Training Certification Tracking System (ATCTS) registration for Contractor employees who require access to Government information systems. All Contractor employees with access to a Government info system must be registered in the ATCTS (Army Training Certification Tracking System) at commencement of services, and must successfully complete the DOD Information Assurance Awareness prior to access to the IS and then annually thereafter.
For contracts that require a formal OPSEC program. The Contractor shall develop an OPSEC Standing Operating Procedure (SOP)/Plan within 90 calendar days of contract award, to be reviewed and approved by the responsible Government OPSEC officer. This plan will include a process to identify critical information, where it is located, who is responsible for it, how to protect it and why it needs to be protected. The Contractor shall implement OPSEC measures as ordered by the commander. In addition, the Contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1.
For contracts that require OPSEC Training. Per AR 530-1 Operations Security, the Contractor employees must complete Level I OPSEC Awareness training. New employees must be trained within 30 calendar days of their reporting for duty and annually thereafter.
For information assurance (IA)/information technology (IT) training. All Contractor employees and associated sub-Contractor employees must complete the DoD IA awareness training before issuance of network access and annually thereafter. All Contractor employees working IA/IT functions must comply with DoD and Army training requirements in DoDD 8570.01, DoD 8570.01-M and AR 25-2 within six (6) months of appointment to IA/IT functions.
For information assurance (IA)/information technology (IT) certification. Per DoD 8570.01-M , DFARS
252.239.7001 and AR 25-2, the Contractor employees supporting IA/IT functions shall be appropriately certified upon contract award. The baseline certification as stipulated in DoD 8570.01-M must be completed upon contract award.
For contracts that require handling or access to classified information. Contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires Contractors to comply with— (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M); (2) any revisions to DOD 5220.22-M, notice of which has been furnished to the Contractor.
Threat Awareness Reporting Program. For all Contractors with security clearances. Per AR 381-12 Threat Awareness and Reporting Program (TARP), Contractor employees must receive annual TARP training by a CI agent or other trainer as specified in 2-4b.
4/11/2017 12:34 PM Page 14 of 14
File details come from the government source that posted it. Updated .