FY17 SpiderOak CloudSync SW Maintenance

Awarded Award Notice Posted

Solicitation number
N00421-17-C-0039
Agency
Naval Air Warfare Center Naval Air Systems Command, Department of Defense
Awarded
to Spideroak Inc.
Set-aside
No set-aside

Opportunity facts

Contract number
N00421-17-C-0039 Federal contract award
NAICS code
541511 Custom Computer Programming Services
PSC
Not on record

Notice details come from SAM.gov. Updated .

Notice text

2 versions

Update #2 · Latest ·


In performance of this contract, the contractor may have access to Department of Defense (DoD) information. The contractor agrees (a) to use and protect such information from unauthorized disclosure in accordance with DoD Instruction 8582.01: Security of Unclassified DoD Information on Non-DoD Information Systems; (b) to use and disclose such information only for the purpose of performing this contract and to not use or disclose such information for any personal or commercial purpose; (c) to comply with other current Federal and DoD information protection and reporting requirements for specified categories of information (e.g., medical, proprietary, critical program information (CPI), personally identifiable information, export controlled); (d) to obtain permission of the Government Requiring Activity before disclosing/discussing such information with a third party; (e) to return and /or electronically purge, upon Government request, any DoD information no longer required for contractor performance; and (f) to advise the Contracting Officer and/or Contracting Officer's Representative of any unauthorized release of such information.



NAVAIR's Cybersecurity Program is a unified approach to protect unclassified, sensitive or classified information, and is established to consolidate and focus efforts in securing that information, including its associated systems and resources. Cybersecurity is required operationally throughout the DON. The DON CIO is responsible for IT within the Navy, as mandated by the Clinger-Cohen Act, and is the lead for departmental compliance with the Federal Information Security Management Act of 2002. All Cybersecurity shall be in compliance with the following listed instructions:


a. ASD (NII) Directive-Type Memorandum (DTM) 08-027 - Security of Unclassified


DoD Information on Non-DoD Information Systems, 31 July 2009


Source IRM Office UPDATED: July 29, 2014 Page 6


b. Chairman of the Joint Chiefs of Staff Instruction CJCSI 3170.01H (series), Joint Capabilities


Integration and Development System, 10 January 2012


c. CJCSI 6211.02D Defense Information System Network (DISN): Policy and


Responsibilities, 24 Jan 2012


d. CJCSI 6212.01F Net Ready Key Performance Parameter (NR KPP), 21 March 2012


e. CJCSI 6251.01D Narrowband Satellite Communications Requirements, 30 Nov 2012


f. CJCSI 6510.01F, Information Assurance (IA) and Support to Computer Network Defense


(CND), 09 Feb 2011, certified current 10 Oct 2013


g. Chairman of the Joint Chiefs of Staff Manual CJCSM 6510.01B - Incident Handling


Program 10 July 2012


h. Chief of Naval Operations/Headquarters, United States Marine Corps CNO


N614/HQMC C4 - Navy-Marine Corps Unclassified Trusted Network Protection (UTNProtect)


Policy, Version 1.0, 31 October 2002


i. Defense Acquisition Guidebook - Chapter 7, Acquiring Information Technology,


Including National Security Systems, Section 7.5 Information Assurance (IA)


j. DoD 5220.22-M, National Industrial Security Program Operating Manual, February


28, 2006 (NISPOM)


k. DoD 8570.01-M, Information Assurance Workforce Improvement Program, 19 Dec


2005 (Incorporating Change 3, 24 Jan 2012)


l. DoDD 8000.01 Management of the Department of Defense Information Enterprise, 10


February 2009


m. DoDD 8100.02, Use of Commercial Wireless Devices, Services, and Technologies in the


Department of Defense (DoD) Global Information Grid (GIG), 14 April 2004, Certified


Current as of 23 April 2007


n. DoDD 8570.01 Information Assurance Training, Certification, and Workforce


Management, 15 August 2004, Certified Current as of 23 April 2007


o. DoDI 4630.8, Procedures for Interoperability and Supportability of Information


Technology (IT) and National Security Systems (NSS), 30 June 2004


p. DoDI 8500.1, Cybersecurity, 14 March 2014


Source IRM Office UPDATED: July 29, 2014 Page 7


q. DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT),


12 March 2014


r. DoDI 8520.2, Public Key Infrastructure (PKI) and Public Key (PK) Enabling, 01 April


2004


s. DoDI 8551.1, Ports, Protocols, and Services Management (PPSM), 13 August 2004


t. DoDI 8580.1, Information Assurance in the Defense Acquisition System, 9 July 2004


u. DoDI 8581.01, Information Assurance (IA) Policy for Space Systems Used by the


Department of Defense, 8 June 2010


v. DON CIO Memo 02-10, Department of the Navy Chief Information Officer


Memorandum 02-10 Information Assurance Policy Update for Platform Information


Technology, 26 April 2010


w. DON letter 5239 NAVAIR 726/2322 of 18 Feb 09, NAVAIR Data at Rest Policy


x. Federal Information Processing Standards Publications (FIPS PUB)


http://www.nist.gov/itl/fips.cfm


y. National Security Telecommunications and Information Systems Security Policy


NSTISSP No. 11, Revised Fact Sheet National Information Assurance Acquisition


Policy, July 2003.


aa. Office of the Chief of Naval Operations OPNAV INST 5239.1C, Navy


Information Assurance (IA) Program, 20 Aug 08


bb. SECNAV M-5239.1, Department of the Navy Information Assurance Program;


Information Assurance Manual, November 2005


cc. SECNAVINST 5230.15, Information Management/Information Technology Policy for


Fielding of Commercial Off the Shelf Software, 10 April 2009


dd. SECNAVINST 5239.3B, Department of the Navy Information Assurance Policy, 17 June


2009


ee. SECNAVINST 5239.19, Department of the Navy Computer Network Incident Response


and Reporting Requirements, 18 March 2008


ff. The National Security Act of 1947


Source IRM Office UPDATED: July 29, 2014 Page 8


gg. Title 40/Clinger-Cohen Act


hh. Title 44/ Federal Information Security Management Act



Approved contractor-owned equipment shall be permitted connections to NAVAIR/DoD Networks in order to carry out the performance of this contract. All Contractor-owned hardware and/or software shall meet DoDI 8500.1. Cybersecurity, is subject to validation scanning and must be approved by the NAVAIR site IA Manager prior to connection.



Contractor Furnished Equipment (CFE) employed for remote access to a Government network must meet or exceed equivalent Government Furnished Equipment (GFE) cyber security computing requirements. The contractor shall ensure that all CFE (hardware and software) employed to access these environments meet the following minimum Government cyber security requirements and provide periodic certification of compliance as a pre-requisite to being granted network access.


•(1) Use of personally owned systems is prohibited;


•(2) Operating systems and applications must be configured for compliance with the applicable Security Technical Implementation Guides (STIGs);


•(3) DoD approved anti-virus and anti-spyware software must be installed and signatures must be configured to automatically update on a daily basis;


•(4) DoD approved host-level firewall must be utilized and configured to permit traffic by exception only, dropping all other traffic. If the host-level firewall provides intrusion detection or prevention, the signatures or rules must be updated at the same intervals as the anti-virus software;


•(5) Computers must be Information Assurance Vulnerability Management (IAVM) compliant;


•(6) Computers must be scanned with the currently approved DoD scanner solution at a minimum of every 30 days. All vulnerabilities must be remediated and reported to the cognizant Information Assurance Manager;


•(7) Contractor employees must possess a current Government issued Common Access Card (CAC) and install Government certified CAC readers; and


•(8) Verification of compliance with these requirements must be provided to an appointed government representative on a monthly basis.



The following specific criteria must be met before the contractor can be connected to any DoD or NAVAIR network in support of this contract. Requirements include:




  1. Network Vulnerability Scanning. NAVAIR Deputy CIO for Information Assurance maintains authorized auditing tools and shall provide for firewall/port scans, device discovery scan, vulnerability assessment, and other requirements as required to ensure secure interoperability with DoD networks. The contractor shall be responsible for the remediation of any equipment that fails these audits prior to the connection of the system to the networks; Results of approvals shall be documented via Memorandum of Agreement with the Facility Security officer and the Defense Security Service Representative for that contractor;




  1. Extent of Validation Scanning. To prevent scanning of corporate assets, all such networks, equipment and connections shall be physically segregated from any government/contractor corporate networks that are not in direct support of DoD contracts;




  1. Circuit Provisioning. Any circuit or connection between NAVAIR and/or DoD site and the contractor site shall be provisioned via the Defense information Security Agency and comply with CJCSI 6211.02D, Defense Information System Network (DISN): Policy and Responsibilities, 24 Jan 2012.





  1. Servicing Systems from a Remote Contractor Site. Remote Access Service connections that allow off-station operation and/or administration of contractor owned systems, located at any NAVAIR facility or site, shall not be permitted, with the exception of those systems connecting to the Command via the Outreach Services identified in Section 6, Enterprise Architecture;




  1. Memorandum of Agreement and Inter-connection Agreements. A Cybersecurity Memorandum of Agreement (MOA) between the contractor owning the equipment and AIR-7.2.6 shall be developed and signed before the equipment can be connected to NAVAIR networks. Failure to comply with the signed MOA shall be grounds for disconnection from the network.




Information Technology Security


The DON Automated Data Processing (ADP) Security Program outlined in SECNAVINST 5239.3A, 'DON Information Assurance Policy' and SECNAV M-5239.1, 'DON Information Assurance Manual,' applies to efforts under this task order. Contractor personnel providing services under this task order shall comply with all federal, DOD, and DON IA policies. The Contractor shall comply with SECNAVINST5510.30B and SECNAV M-5510.30 to assure that the proper investigation (SSBI) is conducted for those contractor personnel that require IT Level 1 access. The Contractor shall coordinate with the TPOC to identify applicable positions.


System Authorization Access Request (SAAR)


The Contractor shall submit a Systems Authorization Access Request (SAAR-N) Form (OPNAV 5239/14 Sep 2011 or latest version thereof) for each contractor employee tasked under this task order that requires access to Government IT systems in accordance with NAVAIR Clause 5252.204-9505. The Contractor shall submit Privileged Access Authorization forms and System Administration letters as dictated in the policies mentioned within this paragraph and any follow-on policies released.



DOD Directive 8570.01-M Information Assurance Workforce Improvement Program


DOD Directive 8570.01-M provides guidance for the identification and categorization of positions and certification of personnel conducting IA functions within the DOD Workforce supporting the DOD Global Information Grid (GIG) per DOD Instruction 8500.2 (Reference (b)). The DOD IA Workforce includes, but is not limited to, all individuals performing any of the IA functions described in Directive 8570.01-M. All contractor personnel performing under this contract must comply with DOD Directive 8570.01-M, where applicable, and any training required to comply with this directive is at the expense of the Contractor. The TPOC will assign the appropriate certification category based on the duties and responsibilities being performed, relative to the current published DOD 8570 Manual. Upon subsequent release of DODI 8140.01, the contractor shall adhere to updated guidance on cyber security workforce qualifications and comply with all the necessary submission of paperwork and submission for access approval.

. Awarded Vendors: SpiderOak Inc.. Contract Award Dollar Amount: $240,800.00. Contract Award Date: 2017-06-08.

Update #1 ·

Added: Jun 13, 2017 10:38 am  

In performance of this contract, the contractor may have access to Department of Defense (DoD) information.  The contractor agrees (a) to use and protect such information from unauthorized disclosure in accordance with DoD Instruction 8582.01: Security of Unclassified DoD Information on Non-DoD Information Systems; (b) to use and disclose such information only for the purpose of performing this contract and to not use or disclose such information for any personal or commercial purpose; (c) to comply with other current Federal and DoD information protection and reporting requirements for specified categories of information (e.g., medical, proprietary, critical program information (CPI), personally identifiable information, export controlled); (d) to obtain permission of the Government Requiring Activity before disclosing/discussing such information with a third party; (e) to return and /or electronically purge, upon Government request, any DoD information no longer required for contractor performance; and (f) to advise the Contracting Officer and/or Contracting Officer's Representative of any unauthorized release of such information.


 


NAVAIR's Cybersecurity Program is a unified approach to protect unclassified, sensitive or classified information, and is established to consolidate and focus efforts in securing that information, including its associated systems and resources. Cybersecurity is required operationally throughout the DON. The DON CIO is responsible for IT within the Navy, as mandated by the Clinger-Cohen Act, and is the lead for departmental compliance with the Federal Information Security Management Act of 2002.  All Cybersecurity shall be in compliance with the following listed instructions:


a. ASD (NII) Directive-Type Memorandum (DTM) 08-027 - Security of Unclassified


DoD Information on Non-DoD Information Systems, 31 July 2009


Source IRM Office UPDATED: July 29, 2014 Page 6


b. Chairman of the Joint Chiefs of Staff Instruction CJCSI 3170.01H (series), Joint Capabilities


Integration and Development System, 10 January 2012


c. CJCSI 6211.02D Defense Information System Network (DISN): Policy and


Responsibilities, 24 Jan 2012


d. CJCSI 6212.01F Net Ready Key Performance Parameter (NR KPP), 21 March 2012


e. CJCSI 6251.01D Narrowband Satellite Communications Requirements, 30 Nov 2012


f. CJCSI 6510.01F, Information Assurance (IA) and Support to Computer Network Defense


(CND), 09 Feb 2011, certified current 10 Oct 2013


g. Chairman of the Joint Chiefs of Staff Manual CJCSM 6510.01B - Incident Handling


Program 10 July 2012


h. Chief of Naval Operations/Headquarters, United States Marine Corps CNO


N614/HQMC C4 - Navy-Marine Corps Unclassified Trusted Network Protection (UTNProtect)


Policy, Version 1.0, 31 October 2002


i. Defense Acquisition Guidebook - Chapter 7, Acquiring Information Technology,


Including National Security Systems, Section 7.5 Information Assurance (IA)


j. DoD 5220.22-M, National Industrial Security Program Operating Manual, February


28, 2006 (NISPOM)


k. DoD 8570.01-M, Information Assurance Workforce Improvement Program, 19 Dec


2005 (Incorporating Change 3, 24 Jan 2012)


l. DoDD 8000.01 Management of the Department of Defense Information Enterprise, 10


February 2009


m. DoDD 8100.02, Use of Commercial Wireless Devices, Services, and Technologies in the


Department of Defense (DoD) Global Information Grid (GIG), 14 April 2004, Certified


Current as of 23 April 2007


n. DoDD 8570.01 Information Assurance Training, Certification, and Workforce


Management, 15 August 2004, Certified Current as of 23 April 2007


o. DoDI 4630.8, Procedures for Interoperability and Supportability of Information


Technology (IT) and National Security Systems (NSS), 30 June 2004


p. DoDI 8500.1, Cybersecurity, 14 March 2014


Source IRM Office UPDATED: July 29, 2014 Page 7


q. DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT),


12 March 2014


r. DoDI 8520.2, Public Key Infrastructure (PKI) and Public Key (PK) Enabling, 01 April


2004


s. DoDI 8551.1, Ports, Protocols, and Services Management (PPSM), 13 August 2004


t. DoDI 8580.1, Information Assurance in the Defense Acquisition System, 9 July 2004


u. DoDI 8581.01, Information Assurance (IA) Policy for Space Systems Used by the


Department of Defense, 8 June 2010


v. DON CIO Memo 02-10, Department of the Navy Chief Information Officer


Memorandum 02-10 Information Assurance Policy Update for Platform Information


Technology, 26 April 2010


w. DON letter 5239 NAVAIR 726/2322 of 18 Feb 09, NAVAIR Data at Rest Policy


x. Federal Information Processing Standards Publications (FIPS PUB)


http://www.nist.gov/itl/fips.cfm


y. National Security Telecommunications and Information Systems Security Policy


NSTISSP No. 11, Revised Fact Sheet National Information Assurance Acquisition


Policy, July 2003.


aa. Office of the Chief of Naval Operations OPNAV INST 5239.1C, Navy


Information Assurance (IA) Program, 20 Aug 08


bb. SECNAV M-5239.1, Department of the Navy Information Assurance Program;


Information Assurance Manual, November 2005


cc. SECNAVINST 5230.15, Information Management/Information Technology Policy for


Fielding of Commercial Off the Shelf Software, 10 April 2009


dd. SECNAVINST 5239.3B, Department of the Navy Information Assurance Policy, 17 June


2009


ee. SECNAVINST 5239.19, Department of the Navy Computer Network Incident Response


and Reporting Requirements, 18 March 2008


ff. The National Security Act of 1947


Source IRM Office UPDATED: July 29, 2014 Page 8


gg. Title 40/Clinger-Cohen Act


hh. Title 44/ Federal Information Security Management Act


 


Approved contractor-owned equipment shall be permitted connections to NAVAIR/DoD Networks in order to carry out the performance of this contract. All Contractor-owned hardware and/or software shall meet DoDI 8500.1.  Cybersecurity, is subject to validation scanning and must be approved by the NAVAIR site IA Manager prior to connection.


 


Contractor Furnished Equipment (CFE) employed for remote access to a Government network must meet or exceed equivalent Government Furnished Equipment (GFE) cyber security computing requirements.  The contractor shall ensure that all CFE (hardware and software) employed to access these environments meet the following minimum Government cyber security requirements and provide periodic certification of compliance as a pre-requisite to being granted network access.


•(1)   Use of personally owned systems is prohibited;


•(2)   Operating systems and applications must be configured for compliance with the applicable Security Technical Implementation Guides (STIGs);


•(3)   DoD approved anti-virus and anti-spyware software must be installed and signatures must be configured to automatically update on a daily basis;


•(4)   DoD approved host-level firewall must be utilized and configured to permit traffic by exception only, dropping all other traffic.  If the host-level firewall provides intrusion detection or prevention, the signatures or rules must be updated at the same intervals as the anti-virus software;


•(5)   Computers must be Information Assurance Vulnerability Management (IAVM) compliant;


•(6)   Computers must be scanned with the currently approved DoD scanner solution at a minimum of every 30 days.  All vulnerabilities must be remediated and reported to the cognizant Information Assurance Manager;


•(7)   Contractor employees must possess a current Government issued Common Access Card (CAC) and install Government certified CAC readers; and


•(8)   Verification of compliance with these requirements must be provided to an appointed government representative on a monthly basis.


 


The following specific criteria must be met before the contractor can be connected to any DoD or NAVAIR network in support of this contract. Requirements include:


 



  1. Network Vulnerability Scanning.  NAVAIR Deputy CIO for Information Assurance maintains authorized auditing tools and shall provide for firewall/port scans, device discovery scan, vulnerability assessment, and other requirements as required to ensure secure interoperability with DoD networks. The contractor shall be responsible for the remediation of any equipment that fails these audits prior to the connection of the system to the networks; Results of approvals shall be documented via Memorandum of Agreement with the Facility Security officer and the Defense Security Service Representative for that contractor;


 



  1. Extent of Validation Scanning. To prevent scanning of corporate assets, all such networks, equipment and connections shall be physically segregated from any government/contractor corporate networks that are not in direct support of DoD contracts;


 



  1. Circuit Provisioning. Any circuit or connection between NAVAIR and/or DoD site and the contractor site shall be provisioned via the Defense information Security Agency and comply with CJCSI 6211.02D, Defense Information System Network (DISN): Policy and Responsibilities, 24 Jan 2012.


 


 



  1. Servicing Systems from a Remote Contractor Site. Remote Access Service connections that allow off-station operation and/or administration of contractor owned systems, located at any NAVAIR facility or site, shall not be permitted, with the exception of those systems connecting to the Command via the Outreach Services identified in Section 6, Enterprise Architecture;


 



  1. Memorandum of Agreement and Inter-connection Agreements. A Cybersecurity Memorandum of Agreement (MOA) between the contractor owning the equipment and AIR-7.2.6 shall be developed and signed before the equipment can be connected to NAVAIR networks. Failure to comply with the signed MOA shall be grounds for disconnection from the network.


 


 


Information Technology Security


The DON Automated Data Processing (ADP) Security Program outlined in SECNAVINST 5239.3A, 'DON Information Assurance Policy' and SECNAV M-5239.1, 'DON Information Assurance Manual,' applies to efforts under this task order.  Contractor personnel providing services under this task order shall comply with all federal, DOD, and DON IA policies.  The Contractor shall comply with SECNAVINST5510.30B and SECNAV M-5510.30 to assure that the proper investigation (SSBI) is conducted for those contractor personnel that require IT Level 1 access.  The Contractor shall coordinate with the TPOC to identify applicable positions.


System Authorization Access Request (SAAR)


The Contractor shall submit a Systems Authorization Access Request (SAAR-N) Form (OPNAV 5239/14  Sep 2011 or latest version thereof) for each contractor employee tasked under this task order that requires access to Government IT systems in accordance with NAVAIR Clause 5252.204-9505.  The Contractor shall submit Privileged Access Authorization forms and System Administration letters as dictated in the policies mentioned within this paragraph and any follow-on policies released.


 


DOD Directive 8570.01-M Information Assurance Workforce Improvement Program


DOD Directive 8570.01-M provides guidance for the identification and categorization of positions and certification of personnel conducting IA functions within the DOD Workforce supporting the DOD Global Information Grid (GIG) per DOD Instruction 8500.2 (Reference (b)). The DOD IA Workforce includes, but is not limited to, all individuals performing any of the IA functions described in Directive 8570.01-M.  All contractor personnel performing under this contract must comply with DOD Directive 8570.01-M, where applicable, and any training required to comply with this directive is at the expense of the Contractor.  The TPOC will assign the appropriate certification category based on the duties and responsibilities being performed, relative to the current published DOD 8570 Manual. Upon subsequent release of DODI 8140.01, the contractor shall adhere to updated guidance on cyber security workforce qualifications and comply with all the necessary submission of paperwork and submission for access approval.

Attachments

Files attached to this notice, newest first
File Type Posted
SPIDEROAK_BRAND_NAME.pdf PDF

On GovTribe

Work this opportunity on GovTribe

  • Track it in your pipeline
  • Find teaming partners
  • Similar opportunities
  • Ask GovTribe AI about this opportunity