20170428_Attach-1_PWS-TRAC_Security_v6.pdf

PDF 78 KB Posted

Attached to
TRAC Physical Security Support Federal contract opportunity
Solicitation number
W91QF4-17-R-0012
Issued by
Department of the Army Materiel Command Mission and Installation Contracting Command Fort Leavenworth

About this file

Attach 1-Performance Work Statement

View the file

Other files for this federal contract opportunity

Other files attached to TRAC Physical Security Support, newest first.
File Type Posted
20170523_SF30_Amend-0002_W91QF417R0012.pdf PDF
20170511_SF30-Amend-0001_W91QF417R0012.pdf PDF
20170508_Attach-4_Exh-2_Rvsd_Relevant_Contract_Form_Template.doc DOC document
20170511_Solicitation_Q-A_W91QF417R0012.pdf PDF
20170428_SF33_Solicitation_W91QF417R0012.pdf PDF
20170428_Attach-2_PRS_TRAC_Security.pdf PDF
20170428_Attach-3_DD254_TRAC_Security_signed.pdf PDF
Ex-1_Consent_Form_Template.docx DOCX document
Ex-2_Relevant_Contract_Form_Template.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

W91QF4-17-R-0012

Attachment 1

Version date: 28 April 2017

PERFORMANCE WORK STATEMENT

Information, Personnel, and Physical Security Support TRADOC Analysis Center, Fort Leavenworth KS

1. General: This is a non-personal services contract to provide Information, Personnel, and Physical Security Support.

1.1. Description of Services/Introduction: The Contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to conduct information, personnel, and physical security support services as defined in this performance work statement (PWS) except for those items specified as Government furnished property and services.

The Contractor shall perform to the standards in this contract.

1.2. Background: TRADOC Analysis Center (TRAC) is one of the lead analysis agencies of the United States Army. TRAC conducts research and analysis on military operations worldwide to inform senior Army decision makers about current and future issues facing the Army and the Department of Defense (DoD). TRAC conducts operations research (OR) on a wide range of military topics, some contemporary, but most often set 5 to 15-years in the future. The TRAC mission is to develop future concepts and requirements in direct support to the Army's major command, Training and Doctrine Command (TRADOC), while also serving the decision needs of senior military leaders throughout the Army and Joint community. The TRAC program of operations research and analysis addresses a wide range of military topics. TRAC conducts analysis within a joint framework of combined arms operations across a full spectrum of missions and environments. TRAC leads TRADOC's major studies of new warfighting operations and organization (O&O) concepts and requirements. The analysis topics span doctrine, training, leader development, organization, materiel, and soldier support.

1.3. Objectives: Most of the mission-related work conducted at TRAC is classified;

therefore, information, automation, physical, and personnel security are critical to successful mission accomplishment. The primary work areas within the TRAC@FLVN facilities have been designated as “open storage areas” (OSAs) and consequently, warrant special security procedures, controlled systems, and physical access by all personnel per Army Regulation (AR) 25-2 (Cyber Security/Information Assurance (CS/IA)), AR 380-5 (Department of the Army Information Security Program), and AR 190-13 (The Army Physical Security Program). In addition, TRAC personnel frequently visit other classified locations in support of mission requirements necessitating a system capable of generating visit requests, maintaining records, and forwarding security clearance evidence to those other locations. TRAC heavily relies on automation to accomplish its missions.

1.4. Scope: The Contractor shall provide administrative assistance of security and other security-related support functions for the Training and Doctrine Command TRAC facilities and operations located at Fort Leavenworth, Kansas. For the purposes of this contract, all security functions addressed will apply only to the two elements of TRAC geographically located at Fort Leavenworth, hereafter referred to as TRAC@FLVN (TRAC-HQ and TRAC-FLVN).

1.5. Period of Performance: The period of performance for this contract is one (1) 12-month base period plus four (4) 12-month optional periods.

1.6. General Information:

1.6.1. Quality Control: Quality Control is the responsibility of the Contractor. The Contractor is responsible for the delivery of quality services/supplies to the Government (see FAR 52.246-4, Inspection of Services – Fixed-Price). The Contractor shall develop, implement and maintain an effective Quality Control System which includes a written Quality Control Plan (QCP). The QCP shall implement standardized procedure/methodology for monitoring and documenting contract performance to meet all contract requirements. The Contractors’ QCP must contain a systematic approach to monitor operations to ensure acceptable services/products are provided to the Government. The QCP, as a minimum, shall address continuous process improvement;

procedures for scheduling, conducting and documentation of inspection; discrepancy identification and correction; corrective action procedures to include procedures for addressing Government discovered non-conformances; procedures for root cause analysis to identify the root cause and root cause corrective action to prevent re-occurrence of discrepancies; procedures for trend analysis; procedures for collecting and addressing customer feedback/complaints. The Contractor shall upon request provide to the Government their quality control documentation. The QCP shall be provided to the administrative Contracting Officer (KO) and contract specialist via e-mail within 10 business days of the performance start date (PSD). The Government will accept, or return the QCP for revision within 10 business days. Any change to the QCP after initial acceptance requires the review and acceptance of the KO.

1.6.2. Quality Assurance: The Government will evaluate the Contractor’s performance under this contract in accordance with (IAW) the Quality Assurance Surveillance Plan (QASP). This plan is a Government only document primarily focused on what the Government must do to assure that the Contractor has performed IAW the requirements of the contract.

1.6.3. Federal Government Holidays:

New Years Day 1st day of January Martin Luther King Jr.'s Birthday 3rd Monday of January Washington’s Birthday 3rd Monday of February Memorial Day Last Monday of May Independence Day 4th day of July

Labor Day 1st Monday of September Columbus Day 2nd Monday of October Veterans Day 11th day of November Thanksgiving Day 4th Thursday of November Christmas Day 25th day of December

1.6.4. Hours of Operation: The Contractor is responsible for conducting business, between the hours of 7:00 a.m. to 5:45 p.m., Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings.

1.6.5. Place of Performance: All work shall be provided and performed in and around the three TRAC, Fort Leavenworth facilities: McNair Hall (Bldg 286), Funston Hall (Bldg 314), and the TRAC Warehouse (Bldg 107).

1.6.6. Security Requirements: Contractor personnel performing work under this contract must have a SECRET security clearance upon the performance start date, and must maintain the level of security required for the life of the contract. The Contractor shall possess and maintain a SECRET facility clearance from the Defense Security Service at the time of proposal submission and must maintain the level of security required for the life of the contract. The security requirements are in accordance with the attached DD Form 254, Department of Defense Contract Security Classification Specification. In addition, access to the Fort Leavenworth Non-Secure Internet Protocol Router Network (NIPRNET) and Secure Internet Protocol Routing Network (SIPRNET) is limited to United States citizens. This contract may include the requirement for the Contractor to access North Atlantic Treaty Organization (NATO) information. Special briefings are required for access to NATO information. Access to classified NATO information requires a final U.S. Government clearance at the SECRET level.

1.6.7.1. Physical Security: The Contractor shall be responsible for safeguarding all Government equipment, information and property provided for Contractor use.

Contractor shall secure Government facilities, equipment and materials at the close of each work day.

1.6.7.2. Key Control: The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer’s Representative (COR).

1.6.7.2.1. In the event keys are lost or duplicated, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the

Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.

1.6.7.2.2. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.

1.6.7.3. Lock Combinations: The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. These procedures shall be included in the Contractor’s QCP.

1.6.8. Special Qualifications: Not Applicable.

1.6.9. Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post-award conference convened by the contracting activity or contract administration office IAW FAR Subpart 42.5. The KO, COR, and other Government personnel, as appropriate, may meet periodically with the Contractor to review the Contractor's performance. At these meetings the Government will apprise the Contractor of how the Government views the Contractor's performance and the Contractor will apprise the Government of problems, if any, being experienced.

Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the Government.

1.6.9.1. Monthly Progress Report: The Contractor shall provide a Monthly Progress Report to the COR. The report shall be prepared in Microsoft Word and forwarded via electronic mail. Reporting period is the first through the last day of the month with report due no later than the 5th working day of the following month. The report shall provide a brief description of the work performed under the contract during the previous month and shall include at a minimum, the following information: Title and contract number;

period covered by the report; date and name of preparer; status of deliverables;

significant events during the reporting period to include potential or outstanding problem areas; and deliverables for following month.

1.6.9.2. In-Process Reviews (IPRs): The Contractor shall attend and participate in weekly staff meetings and informal IPRs with Government personnel. Contractor shall verbally discuss ongoing actions and issues associated with tasks identified in the PWS.

1.6.10. Contracting Officer Representative (COR): The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions:

assure that the Contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the Contractor concerning technical aspects of the contract;

issue written interpretations of technical requirements, including Government drawings, designs, and specifications; monitor Contractor's performance and notify both the KO and Contractor of any deficiencies; coordinate availability of Government furnished property; and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.

1.6.11. Key Personnel: Not Applicable.

1.6.12. Identification of Contractor Employees: The Contractor shall provide each employee an Identification (ID) Badge, which includes at a minimum, the Company Name, Employee Name and a color photo of the employee. ID Badges for Key Personnel shall also indicate their job title. ID Badges shall be worn at all times during which the employee is performing work under this contract. Each Contractor (to include subcontractors) employees shall wear the ID Badge in a conspicuous place on the front of exterior clothing and above the waist except when safety or health reasons prohibit.

The Contractor (to include subcontractors) shall be responsible for collection of ID Badges upon completion of the contract or termination of employee. All contract personnel attending meetings, answering Government telephones, and working in other situations where their Contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials.

1.6.13. Supervision of Contractor Employees: The Government will not exercise any supervision or control over Contractor employees while performing work under the contract. Such employees shall be accountable solely to the Contractor, not the Government. The Contractor, in turn, shall be accountable to the Government for Contractor employees.

1.6.14. Contractor Travel: No travel planned at this time.

1.6.15. Other Direct Costs: Not applicable.

1.6.16. Organizational Conflict of Interest (OCI): The contracting officer has not identified any OCIs inherent to this requirement. It is the offeror’s responsibility to notify the contracting officer, prior to submission of proposals, if a potential OCI is identified.

1.6.17. PHASE IN /PHASE OUT PERIOD: The first seven days following contract award will allow for a phase in / phase out period with start of full job performance on PSD+8. Duties during the phase in period include, but are not limited to, Contractor in-processing, receipt of JPAS and LCAM orientations, and completion of a key control inventory in order to commence full performance of services. The total time of phase-in / phase out plus full performance would equal the 12-month period of performance.

1.6.16. Anti-Terrorism (AT) Level I Training: All Contractor employees requiring access Army installations, facilities and controlled access areas shall complete AT Level I awareness training within 30 calendar days of the PSD or effective date of incorporation of this requirement into the contract, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee to the COR or to the contracting officer, if a COR is not assigned, within 30 calendar days after completion of training by all employees. AT level I awareness training is available at the following website: http://jko.jten.mil.

1.6.17. Access and General Protection/Security Policy and Procedures: Contractor and employees shall provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, HQDA and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in Contractor security matters or processes.

1.6.17.1. Contractors Requiring a Common Access Card (CAC): Before CAC issuance, the Contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation in accordance with Army Directive 2014-05. The Contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.

1.6.17.2. Contractors Not Requiring a CAC but Require Access to a DoD Facility or Installation: N/A

1.6.18. AT Awareness Training for Contractor Personnel Traveling Overseas: N/A

1.6.19. iWATCH Training: The Contractor shall brief all employees on the local iWATCH program (training standards provided by the requiring activity’s ATO). This locally developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 calendar days of the PSD and within 30 calendar days of new employees commencing performance with the results reported to the COR no later than (NLT) 15 calendar days after completion of training.

1.6.20. Access to Government Information Systems: All Contractor employees with access to a Government info system shall be registered in the Army Training Certification Tracking System (ATCTS), and shall successfully complete the DoD Cyber Awareness Challenge (formerly Information Assurance (IA) Awareness) prior to gaining access to the IS and annually thereafter. DoD IA training is available at https://ia.signal.army.mil/DoDIAA/default.asp.

1.6.21. Operations Security (OPSEC) Standing Operating Procedure (SOP)/Plan: N/A

1.6.22. OPSEC Training: Per AR 530-1, Operations Security, all Contractor employees shall complete Level I OPSEC training within 30 calendar days of their reporting for duty. All Contractor employees shall complete annual OPSEC awareness training. This training is available at http://www.cdse.edu/catalog/elearning/GS130.html.

1.6.23. Information Assurance (IA)/Information Technology (IT) Certification: N/A

1.6.24. Threat Awareness Reporting Program (TARP): Per AR 381-12 Threat Awareness and Reporting Program (TARP), Contractor employees who possess a security clearance must receive annual TARP training by a CI agent or other trainer as specified in paragraph 2-4b. The COR will coordinate for the next available TARP class for each period of performance.

2. DEFINITIONS AND ACRONYMS:

2.1. Definitions:

2.1.1. Contractor: A supplier or vendor awarded a contract to provide specific supplies or services to the Government. The term used in this contract refers to the prime.

2.1.2. Contracting Officer: A person with authority to enter into, administer, and/or terminate contracts, and make related determinations and findings on behalf of the Government. Note: The only individual who can legally bind the Government.

2.1.3. Contracting Officer’s Representative: An employee of the U.S. Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.4. Defective Service: A service output that does not meet the standard of performance associated with the PWS.

2.1.5. Deliverable: Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.

2.1.6. Government Furnished Property (GFP) or Government Property (GP): Property in the possession of, or directly acquired by, the Government and subsequently made available to the Contractor.

2.1.7. Key Personnel: Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS.

2.1.8. Physical Security: Actions that prevent the loss or damage of Government property.

2.1.9. Quality Assurance: The Government procedures to verify that services being performed by the Contractor are acceptable IAW established standards and requirements of this contract.

2.1.10. Quality Assurance Surveillance Plan: An organized written document specifying the surveillance methodology to be used for surveillance of Contractor performance.

2.1.11. Quality Control: All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.

2.2. Acronyms:

ADP Automated Data Processing AKO Army Knowledge Online ALMS Army Learning Management System AOR Area of Responsibility AR Army Regulation AT Anti-terrorism ATCTS Army Training Certification Tracking System ATO Anti-Terrorism Officer AUP Acceptable Use Policy CAC Combined Arms Center CAC Common Access Card CCC Classified Container Custodian CFR Code of Federal Regulations CIO Command Information Officer CMR Contract Manpower Reporting CONUS Continental United States (excludes Alaska and Hawaii) COR Contracting Officer Representative COTS Commercial-Off-the-Shelf CS/IA Cyber Security/Information Assurance DA Department of the Army

DAA Designated Approval Authority DD254 Department of Defense Contract Security Requirement List DFARS Defense Federal Acquisition Regulation Supplement DMDC Defense Manpower Data Center DoD Department of Defense FAR Federal Acquisition Regulation FLVN Fort Leavenworth FPCON Force Protection Condition FY Fiscal Year GFP Government Furnished Property HQDA Headquarters, Department of Army IA Information Assurance IAW In accordance with ICAN Installation Campus Area Network ID Identification Badge IPR In-Progress Review IT Information Technology JPAS Joint Personnel Adjudication System KO Contracting Officer LCAMS Leavenworth Commercial Alarm Monitoring System MCNS Mission Critical Network – SECRET MCNU Mission Critical Network – UNCLASSIFIED NACI National Agency Check with Inquiries NATO North Atlantic Treaty Organization NDAA National Defense Authorization Act NLT Not Later Than NEC Network Enterprise Center NIPRNET Non-Secure Internet Protocol Router Network OCI Organizational Conflict of Interest OCONUS Outside Continental United States (includes Alaska and Hawaii) ODC Other Direct Costs O&O Operations & Organization OPSEC Operations Security OR Operations research OSA Open Storage Area PIC Personal Identification Code PIPO Phase In/Phase Out PKI Public Key Infrastructure POC Point of Contact PRS Performance Requirements Summary PSIP Personnel Security Investigation Portal PMO Provost Marshall Office PWS Performance Work Statement PSD Performance Start Date QA Quality Assurance QAP Quality Assurance Program

QASP Quality Assurance Surveillance Plan QC Quality Control QCP Quality Control Program SF Standard Form SHARP Sexual Harassment and Assault Response Prevention SIPRNET Secure Internet Protocol Routing Network SMO Security Management Office SOP Standard Operating Procedures SSM Site Security Manager TARP Threat Awareness and Reporting Program TRAC TRADOC Analysis Center TRAC-FLVN TRADOC Analysis Center – Fort Leavenworth TRAC@FLVN TRADOC Analysis at Fort Leavenworth (Includes TRAC-HQ &

TRAC-FLVN)

TRAC-HQ HQ, TRADOC Analysis Center TRADOC Training and Doctrine Command

3. GOVERNMENT FURNISHED ITEMS AND SERVICES:

3.1. Services: The Government will provide the Contractor access to the SIPRNET and to TRAC’s internal classified network. Contractor personnel may be communicating with and passing data between other Government agencies via the SIPRNET. TRAC will arrange for a SIPRNET account if necessary. Additionally, access to TRAC’s internal and external unclassified networks will be made available to Contractor personnel, as well as the necessary administration accounts to accomplish the tasks specified under this PWS.

3.2. Facilities: The Government will provide the necessary workspace for two (2) Contractor staff to provide the support outlined in the PWS to include desk space, telephones, computers, and other items necessary to maintain an office environment.

3.3. Utilities: The Government will provide all utilities associated with paragraph 3.2 for the Contractor’s use in performance of tasks outlined in this PWS. The Contractor shall instruct employees in utilities conservation practices. The Contractor shall be responsible for operating under conditions that preclude the waste of utilities.

3.4. Equipment: The Contractor shall use Government property only for performing this contract, unless otherwise provided for in this contract or approved by the Contracting Officer. Modifications or alterations of Government property are prohibited. Contractor personnel will be required to sign for electronics equipment provided herein. If travel is required, the Contractor assumes responsibility for the Government equipment when not located at the primary place of performance.

3.5. Materials: The Government will provide all documents necessary for contract performance, to include, any computer hardware and software required to execute this contract. Materials as a minimum will include:

TRAC@FLVN Security SOP.

TRAC@FLVN Open Storage Area (OSA) Operating Policy TRAC@FLVN Security/Building Lock-Up SOP(s).

TRAC@FLVN Operations Security (OPSEC) SOP.

TRAC@FLVN Security for Events Support SOP.

4. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES:

4.1. General: The Contractor shall furnish all supplies, equipment, facilities and services required to perform work under this contract that are not listed under Section 3 of this PWS.

4.2. Materials: See paragraph 4.1, above.

4.3. Equipment: See paragraph 4.1, above.

5. SPECIFIC TASKS: The Contractor shall maintain a comprehensive security program including multiple OSAs within the TRAC@FLVN facilities. This program is based upon requirements identified in ARs 25-2, 190-13, and 380-5 and shall entail all facets of information, personnel, physical security, and the control of visitors to and from the TRAC@FLVN facilities. Associated tasks are divided between: coordinating, writing, and implementing major portions of the requisite information security assurance accreditation documents and security-related SOPs; and assembling / consolidating documents from input prepared by others for inclusion into these documents. In the performance of these duties, the Contractor shall adjust operating hours as necessary to accomplish these tasks and ensure at a minimum the office is staffed during the operating hours of 7:15 a.m. to 5:45 p.m. each work day.

5.1. Task 1. Information Security and Assurance (Approximately 40% of duties): The Contractor shall support a comprehensive information security program including information assurance for all automated data processing (ADP) systems in Funston and McNair Halls. The Contractor shall perform the following support tasks associated with the information security and assurance mission for TRAC@FLVN.

5.1.1. Subtask 1. Security Inspection: The Contractor shall provide technical and administrative support within TRAC@FLVN in preparation for, and the execution of, the annual (normally in the spring) information and physical security inspection conducted jointly by the Combined Arms Center (CAC) G-2 Security Office and the local Provost Marshall’s Office (PMO) Physical Security Office. The Contractor shall also conduct the TRAC HQ Annual Security Assistance Visit.

5.1.1.1. Deliverables: NLT six weeks in advance of the announced inspection dates, the Contractor shall conduct preparatory security audits and assistance visits of all directorates to ensure organizational readiness for the scheduled security inspection.

Upon receipt of the Report of Information and Physical Security Inspection memo from PMO, within 30 days the Contractor shall rectify all possible security deficiencies identified during the formal security inspection. For those deficiencies that cannot be corrected within three working days, the Contractor shall report them, via e-mail, to the SSM for assistance in resolution.

5.1.1.2. Standard: The Contractor shall not fail to rectify more than one inspection deficiency within the required 30 days.

5.1.2. Subtask 2. Information Security Appendix to SOP: Contractor shall review and update, as necessary, the existing Information Security Appendix to the TRAC@FLVN Security SOP to ensure continued accuracy, relevance, and conformance to current Army policies and regulations. Contractor shall compare existing procedures and develop and document new ones to ensure that the appendix addresses all known information security regulatory requirements, procedures, and issues.

5.1.2.1. Deliverable: Document revisions shall be submitted in MS Word format and provided to the SSM or designated representative NLT 15 September and 15 March.

The SSM will review recommended changes to the SOP and return to Contractor NLT five working days from receipt. Finally, within ten working days of approval, Contractor shall implement approved revisions and procedures as appropriate.

5.1.2.2. Standard: No more than 25% of the approved revisions fail to be implemented after the specified date.

5.1.3. Subtask 3. Cyber Awareness Challenge Training (formerly known as Information Assurance (IA) Refresher Training):

5.1.3.1. Deliverable: Contractor shall organize and monitor completion of the annual on-line Cyber Awareness Challenge training for all TRAC@FLVN personnel in accordance with CAC G6 directives. In addition, the Contractor shall record and verify that every TRAC employee has signed an Acceptable Use Policy (AUP) annually.

5.1.3.2. Standard: The Contractor shall verify 100% accountability of all TRAC@FLVN in terms of status of training and signed AUPs.

5.1.4. Subtask 4. Monthly Security Assistance Assessments: The Contractor shall perform monthly assistance security compliance assessments of randomly-selected TRAC@FLVN directorates. The Contractor shall use a security checklist provided by the SSM or designated representative for the conduct of these assessments. For example, the Contractor shall verify that daily security checks are performed, Standard Forms (SF) 701/702 are current, documents are marked and filed correctly in classified containers, document inventory sheets are current, keys are accounted for, and classified container combinations are changed annually, or as needed following change in appointment of classified container custodian (CCC) or transfer of authorized personnel.

5.1.4.1. Deliverable: Security compliance assessments shall be conducted NLT the 10th day of each month with results documented in an e-mail provided to Government representatives within five working days following the assessment.

5.1.4.2. Standard: Not more than one monthly, random security compliance assessment fails to be performed by the specified suspense date, per six month period.

5.1.5. Subtask 5. Classified Container Custodians (CCC): The Contractor shall maintain a master list showing the identification number and location of all classified containers and the designated CCC who is responsible for each container.

5.1.5.1. Deliverable: Upon change in appointment of a CCC, the Contractor shall follow-up within seven working days with the losing directorate to ensure that appointment orders designating a new CCC was completed and the container lock combination was changed.

5.1.5.2. Standard: The Contractor shall not fail to follow-up within seven working days on more than one occasion per six month period.

5.1.6. Subtask 6. Classified Container Combinations and Access Codes: The Contractor shall train and assist directorate personnel with changing combinations and access codes for a wide variety of lock types/manufacturers.

5.1.6.1. Deliverable: Combinations shall be changed annually (NLT 28 February) or as otherwise warranted by change or transfer of personnel.

5.1.6.2. Standard: The Contractor shall advise directorate personnel if there are two or more combinations that will fail to be changed within 15 days after the suspense date noted in paragraph 5.1.6.1.

5.1.7. Subtask 7. Classified Waste Destruction: The Contractor shall, following coordination with the SSM or designated representative and coordinate, schedule, and oversee the destruction of classified waste.

5.1.7.1. Deliverable: In conjunction with paragraph 5.1.4, monthly security assistance visits, the Contractor shall coordinate and schedule the destruction of classified material as needed based on accumulation of classified waste. Destruction of classified waste will be achieved through the use of Government owned equipment (i.e., approved crosscut shredders or MX-500 High Security Disintegrator). Equipment is physically located within the TRAC facilities. Contractor will be escorted by an authorized Government employee if transport of material is required between buildings.

5.1.7.2. Standard: Not more than one monthly, destruction of accumulated classified waste fails to be accomplished, per six month period.

5.2. Task 2. Personnel Security (Approximately 35% of duties): The Contractor shall coordinate, implement, and maintain a personnel security program to ensure that TRAC employees, Contractors, and visitors meet all requirements for access to classified facilities, documents, and information. For the purpose of supporting this vital mission, the Security Office shall adjust operating hours as necessary to accomplish these tasks and ensure at a minimum the office is staffed during the operating hours of 7:15 a.m. to 5:45 p.m. each work day.

5.2.1. Subtask 1. Personnel Security Appendix to SOP: Contractor shall review the existing Personnel Security Appendix to the TRAC@FLVN Security SOP to ensure continued accuracy, relevance, and conformance to current Army policies and regulations. Contractor shall compare existing procedures and develop and document new ones to ensure that the appendix addresses all known personnel security regulatory requirements, procedures, and issues.

5.2.1.1. Deliverable: Document revisions shall be submitted in MS Word format and provided to the SSM or designated representative for approval NLT 15 September and 15 March. The SSM will review recommended changes to the brief and return to Contractor NLT five working days from receipt. Within ten working days of approval, Contractor shall implement approved revisions and procedures as appropriate.

5.2.1.2. Standard: No more than 25% of the approved revisions fail to be implemented after the specified date.

5.2.2. Subtask 2. Personnel Clearances Status and Submissions: The Contractor shall monitor security clearance status’ utilizing the Joint Personnel Adjudication System (JPAS) for all Government employees and/or Contractors working within the TRAC@FLVN facilities, as well as those personnel visiting from other organizations.

5.2.2.1. Deliverable: The Contractor shall verify that all TRAC employees, (civilian, military, and Contractor) and visitors have a current security clearance before granting access to TRAC@FLVN facilities.

5.2.2.2. Standard: Not more than two instances during the period of performance shall the Contractor fail to verify the security clearance information for personnel accessing

TRAC@FLVN.

5.2.3. Subtask 3. Periodic Review: Based on information contained in JPAS and other local databases, Contractor shall notify each Government employee NLT 40 calendar days prior to the expiration date of a their security clearance.

5.2.3.1. Deliverable: Forty (40) calendar days before a Government employee’s clearance expires, the Contractor shall initiate a request through the Personnel Security Investigation Portal (PSIP) that a reinvestigation is required. The Contractor shall continue to monitor progress of the investigation through notices from PSIP until the investigation and adjudication is completed. The Contractor shall monitor visit notifications for in-house Contractor personnel and notify the TRAC@FLVN COR one month prior to expiration date so that either an extension or new clearance request can be initiated thru the appropriate security office.

5.2.3.2. Standard: Not more than three instances during the period of performance shall the Contractor fail to notify personnel by the specified date.

5.2.4. Subtask 4. Visitor Access Notification: The Contractor shall prepare a visitor notification in JPAS for TRAC@FLVN travelers and monitor the status of TRAC employee visitor notifications to various locations and activities external to TRAC.

5.2.4.1. Deliverables: Once the requisite information is provided by respective directorates on the traveler needing the visit notification, the Contractor shall prepare the notification in JPAS to the appropriate Security Management Office (SMO). The visit notifications for TRAC@FLVN personnel can be reviewed in JPAS Visit Person Summary screen.

5.2.4.2. Standard: The Contractor shall prepare and submit updated visit notification within 36 hours of notice, and shall not exceed that timeframe more than four times during the period of performance. In addition, the Contractor shall not fail to provide the visit notification renewal reminder notices on more than three instances during the period of performance. Finally, NLT the last working day of each month, the Contractor shall update the Excel database file and save this updated Excel database to Public Folders.

5.2.5. Subtask 5. New Employee In-Processing: The Contractor shall perform the following in-processing tasks for all new employees reporting for duty at TRAC@FLVN:

(1) Inform new employees of the procedures to request an AKO account and to obtain their common access card (CAC); (2) Ensure all new employees complete the mandatory Cyber Awareness Challenge Training and then obtain their signature on the latest TRAC AUP; (3) Present a security and OPSEC in-briefing (approximately 10-15 minutes in duration). During this indoctrination, the Contractor shall either upload the individuals CAC information into the system and/or provide each new employee with a magnetic access badge, and assign a personal identification code (PIC) to employees requiring access to the OSA; (4) Present a desk-side PowerPoint briefing on TRAC@FLVN security policies; and (5) the Contractor shall initiate the process for issuing both NIPRNET and SIPRNET accounts by completion and submission of the DD2875 System Authorization Access Request (SAAR) form.

5.2.5.1. Deliverable: The Contractor shall begin in-processing all new TRAC employees within the first working day of their arrival. In addition, the Contractor shall review the in-briefing for currency, provide briefing revisions to the COR or designated representative in MS PowerPoint format for approval, NLT 60 calendar days following the PSD, the SSM will review recommended changes to the brief and return to Contractor NLT five working days from receipt. Contractor shall incorporate the approved changes into the briefing within ten working days of approval.

5.2.5.2. Standard: The Contractor shall not fail to in-process new personnel within one working day of arrival on more than three instances during the period of performance.

Contractor shall be no more than five working days late in either identifying revisions or incorporating those revisions into the in-briefing after approval. Contractor personnel operating any part of the Public Key Infrastructure (PKI) are subject to the same criteria as a US Government employee and are cleared to the level of information protected by the certificates the PKI issues. The Contractor shall be held liable for any loss associated with any violation of the Certificate Policy or misuse of equipment provided.

5.2.6. Subtask 6. Badging: The Contractor shall manage the magnetic badges used to access the OSAs.

5.2.6.1. Deliverable: This task includes issuing badges or uploading CAC information for authorized personnel during in-processing, determining and programming the access level of each badge, providing badge authorization and support for exercises and meetings, gathering badges from departing employees, and maintaining an accurate inventory of magnetic badges.

5.2.6.2. Standard: The Contractor shall issue access badges only to authorized personnel during the period of performance.

5.2.7. Subtask 7. Visitor Authorization Procedures: The Contractor shall annually review existing SOP and procedures for granting access to visitors attending exercises, games, meetings, and workshops.

5.2.7.1. Deliverable: After reviewing SOPs, recommended revisions shall be prepared in MS Word format and shall be submitted to the COR or designated representative for approval NLT 15 September and 15 March. The SSM will review recommended changes to the SOP and return to Contractor NLT five working days from receipt.

Finally, within ten working days of approval, Contractor shall implement approved revisions, modifying written SOP and procedures as appropriate.

5.2.7.2. Standard: The Contractor shall be no more than five working days late in either identifying revisions, incorporating those approved revisions, or implementing those approved revisions.

5.2.8. Subtask 8. Support to conferences and other TRAC@FLVN sponsored events:

5.2.8.1. Deliverable: Contractor shall coordinate with the event POC, issue temporary badges after validating clearances, provide support when needed with escort duties, and execute all other established visitor authorization procedures.

5.2.8.2. Standard: The Contractor shall not fail to provide the required support on more than one instance during the period of performance.

5.2.9. Subtask 9. Visitor Program and Database: The Contractor shall coordinate and maintain a visitor security program to ensure that all visitors to TRAC@FLVN meet the requirements for access to TRAC facilities and networks. Coordination shall include verification of visitor’s clearance status through JPAS.

5.2.9.1. Deliverable: The Contractor shall maintain a database consisting of names and organizations of all approved visitors, TRAC POCs, expiration date of visit notification, and reason for visit (i.e., meeting/wargame/training, etc.). Contractor shall update a list of approved visitors, by posting a copy inside the entryway to Funston Hall and on TRAC Outlook Public Folders. The list shall be provided in an MS Office-based format and shall be updated weekly and re-posted by noon on Wednesday of each week, or as warranted by visit notifications received.

5.2.9.2. Standard: The Contractor shall not fail to update and publish the list on more than three Wednesdays during the period of performance.

5.2.10. Subtask 10. Visitor Escorts/POCs: The Contractor shall verify that all visitors have a TRAC@FLVN point of contact for accountability purposes and to serve as their escort during their visit.

5.2.10.1. Deliverable: The Contractor shall provide escorts to other authorized visitors to the OSA (i.e., Directorate of Public Works maintenance personnel, contract maintenance technicians, custodial staff, vending company personnel, etc.).

5.2.10.2. Standard: The Contractor shall not fail to perform escort duties for visitors on more than 10 instances during the period of performance.

5.3. Task 3. Physical Security (Approximately 25% of duties): The Contractor shall coordinate, implement, and maintain a physical security program to prevent unauthorized access to facilities, offices, equipment, materials, supplies, and documents, safeguarding them against espionage, sabotage, damage, or theft.

5.3.1. Subtask 1. Physical Security Appendix to SOP: The Contractor shall review the existing Physical Security Appendix to the TRAC@FLVN Security SOP to ensure continued accuracy, relevance, and conformance to current Army policies and regulations. Contractor shall compare existing procedures and develop and document new ones where needed to ensure that the appendix addresses all known physical security regulatory requirements, procedures, and issues.

5.3.1.1. Deliverable: The Contractor shall document revisions and submit in MS Word format to COR or designated representative NLT 15 September and 15 March. The SSM will review recommended changes to the SOP and return to Contractor NLT five working days from receipt. Finally, within ten working days of approval, Contractor shall implement approved revisions and procedures as appropriate.

5.3.1.2. Standard: No more than 25% of the approved revisions fail to be implemented after the specified date.

5.3.2. Subtask 2. Physical Security End-of-Day Facilities Lock-Up: The Contractor shall execute end-of-day building lock up for Funston Hall (building 314) starting at 5:30 p.m.

and complete not later than 5:45 p.m. each workday.

5.3.2.1. Deliverable: The Contractor shall complete building lock-up procedures IAW TRAC-FLVN MEMORANDUM ATRC-F-380-5-2012-01, Funston Hall - Building 314 Security/Building Lock-Up SOP (or current version). The Contractor shall verify all directorate areas have completed end-of-day checks by reviewing the end-of-day directorate sign-out board and upon verification, activate the Leavenworth Commercial Alarm Monitoring System (LCAMS) and secure the Funston Hall OSA entrance X09 lock, and initial/date the SF 701. If a directorate area does not reflect end-of-day checks complete on the sign-out board, the Contractor shall sign the Funston Hall OSA end-of-day building lock-up responsibility over to the directorate military or Government civilian remaining in the building past 5:45 p.m. The Government will provide back-up personnel should the contract workforce be unavailable during pre-coordinated periods.

5.3.2.2. Standard: On a weekly basis, the Contractor shall provide a written record verifying completion of Funston Hall end-of-day checks for each workday of the previous week or listing the Government individual plus date/time to whom the responsibility was passed.

5.3.3. Subtask 3. Electronic Security Systems: The Contractor shall be familiar with the capabilities, operation, and maintenance of the electronic intrusion detection, access control, and monitoring equipment in both Funston and McNair Halls. That familiarity shall include the capability to make minor operational adjustments (e.g., open, close, reset) to the systems when warranted. The Contractor shall also maintain the existing SOP and associated instructional material that the Contractor shall use in presenting a formal 15-minute “hands-on” training session (complete with handouts) for TRAC personnel on opening and closing the various security zones and buildings, as well as responding to intrusion detection system-related alarms after normal working hours in both Funston and McNair Halls.

5.3.3.1. Deliverable: The SOP and instructional material revisions shall be prepared in MS Word format and submitted to the SSM or designated representative for approval NLT 15 September and 15 March. The SSM will review recommended changes to the SOP and return to Contractor NLT five working days from receipt. Finally, within 30 days of approval, Contractor shall implement approved revisions, modifying written SOP, instructional material, and procedures as appropriate.

5.3.3.2. Standard: The Contractor shall be no more than five working days late in either identifying revisions, incorporating those approved revisions, or implementing those approved revisions.

5.3.4. Subtask 4. Electronic Security System Trouble Calls: After receiving authorization from a designated Government representative, the Contractor shall serve as the primary POC for trouble calls to electronic security system personnel.

5.3.4.1. Deliverable: The Contractor shall maintain a MS Word or MS Excel log of all occurrences where security system maintenance personnel have to be called in, indicating date and time the call was made, the reason for the call, and the actual date, time, and duration of the maintenance response. The Contractor shall maintain an updated log and be able to produce it upon request from the SSM or COR. This log will be used by the Government to identify recurring problems with supporting electronic security systems.

5.3.4.2. Standard: The Contractor shall provide an updated spreadsheet within one working day after receiving a request from the SSM or COR.

5.3.5. Subtask 5. After Duty Notification Call-in Roster: In conjunction and coordination with the TRAC military tasking officer, the Contractor shall maintain a call-in roster which identifies three military personnel responsible to perform emergency, after-hours response in the event of a physical security violation discovered by the military police or LCAMS alarm activation.

5.3.5.1. Deliverable: The Contractor shall prepare and publish the roster every month, furnish copies to the personnel on the roster, their appropriate supervisors, and the PMO. In the event that none of the TRAC personnel on the call-in roster can be contacted by the PMO after hours, Contractor shall respond and perform the requisite building inspection function in conjunction with the military police, until the Government Site Security Manager can be notified and determine the appropriate action. After duty call-in roster shall be prepared in MS Word format and published NLT five working days prior to the start of the next month.

5.3.5.2. Standard: The Contractor shall publish the rosters on…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .