1-A1 System Requirements Questionnaire.xlsx

XLSX spreadsheet 35 KB Posted

Attached to
Cyber Security Managed Detection and Response Service State and local contract opportunity
Solicitation number
26-081P
Issued by
Fairbanks North Star Borough, Alaska

About this file

The document is a System Requirements Questionnaire for a Cyber Security Managed Detection and Response (MDR) Service solicitation by the Matanuska-Susitna Borough (MSB) in Alaska. The questionnaire details comprehensive technical evaluation criteria for potential vendors, covering areas such as employee qualifications, service methodology, security event monitoring, vulnerability management, security device management, and analytics reporting. The procurement seeks a MDR service that can provide advanced cybersecurity monitoring, threat detection, incident response, and comprehensive reporting capabilities, with vendors required to demonstrate specific technological capabilities and service delivery models.

The questionnaire indicates that MSB is seeking a vendor with dedicated security professionals, scalable service offerings, and robust technological capabilities, including fully operated Security Operation Centers, integration with existing Microsoft Defender systems, and advanced threat detection methodologies. Key requirements include proactive threat hunting, real-time event correlation, zero-day exploit detection, vulnerability scanning, and a web-based portal with role-based access control. The evaluation prioritizes vendors who can provide comprehensive services without requiring MSB to purchase additional proprietary technology, with a strong emphasis on collaborative implementation, continuous threat intelligence, and flexible, customizable reporting and monitoring solutions.

View the file

Other files for this state and local contract opportunity

Other files attached to Cyber Security Managed Detection and Response Service, newest first.
File Type Posted
3-26-081P Cyber Security Managed Detection and Response Service.pdf PDF
2-A2 Data Security Questionnaire.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Proponent Questionnaire 26-081P Cyber Security Managed Detection And Response Service: System Requirements Questionnaire

Vendor:
Complete the questionnaire by selecting compliance, adding comments and explaining non-applicable items with evidence where possible.
Employee QualificationsPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The organization maintains a dedicated internal staff of MDR professionals to meet client needs, without the reliance on subcontractors for core service delivery.Required5
The service offering is scalable to accommodate both small and large customers, with flexible licensing and deployment models.Required1
The vendor utilizes a thorough screening and hiring process for MDR staff, including background checks and technical skill assessments.Required1
Service MethodologyPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The vendor will conduct a detailed assessment of the environment during onboarding to make informed and relevant security recommendations.Required1
The vendor provides a clear distribution of employees across delivery, project management, and customer service, with defined geographical locations.Optional3
The MDR/MSSP offering supports integration with key MSB-owned systems, including EDR solutions and ticketing systems. (Currently we use Microsoft Defender)Optional3
Required technology for this contract, including any log collection and analysis components, resides in the MDR/MSSP facilities.Desired3
The vendor owns and operates fully dedicated Security Operation Centers (SOCs) to support MDR/MSS services.Required3
The vendor has a defined customer notification and escalation process, which includes a pre-defined frequency for notifications and multiple methods of communication.Required4
MSB can be alerted to potential security incidents and can request support via multiple channels, including a dedicated portal, email, and phone support.Required3
During the normalization phase, the provider's interaction with the customer is collaborative and focused on a joint effort to fine-tune event triage and alarm handling.Required3
Meetings or teleconferences to review performance, issues, and the threat environment occur at a defined frequency, with participation from both analyst and account management support staff.Required3
The service includes a data export feature that allows MSB to retrieve all log data, with a clear process and timeline defined for data retrieval upon contract termination.Desired3
Service Onboarding and ImplementationPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The services do not require MSB to purchase or install proprietary technology, with all necessary components provided by the vendor.Desired3
The services are delivered within MSB's internal virtual infrastructure, accommodating scaling of the environment with minimal implications for technology deployment and without additional license costs.Desired1
The service includes integration capabilities with enterprise directories and configuration management databases (CMDBs), which support the delivery of core services.Desired3
Security Event MonitoringPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The service provides monitoring capabilities for a wide range of data sources, including firewalls, intrusion detection/prevention systems (IDS/IPS), and vulnerability data.Desired3
MDR analysts utilize proactive threat hunting methodologies beyond advanced analytics to identify and contain threats.Desired3
The service includes a methodology for analyzing data, providing real-time event correlation between data sources, and generating real-time alerts for security incidents and system health.Desired3
The vendor maintains an automated and continuous process for updating signatures and rules to defend against new and future threats.Desired3
The service supports the creation and management of customized correlation rules, with clear capabilities and limitations available to MSB's staff.Desired3
The service has a defined methodology for detecting custom or targeted attacks directed at MSB's users or systems.Desired3
Custom alert rules can be configured for specific events, such as administrative logins at unusual times.Desired3
The vendor has a well-defined methodology for reducing false positives and negatives.Desired3
The service utilizes multiple mechanisms to detect zero-day exploits and ransomware infections, including behavioral analysis and threat intelligence.Desired3
The service includes a clear process for managing and incorporating false positive feedback from MSB, with regular reporting and communication.Desired3
The vendor's typical workflow for an alert is a defined process that includes automated and manual steps for triage, validation, prioritization, and customer notification.Desired3
The working relationship and responsibilities between the vendor's security staff and MSB's security staff are clearly defined, including the use of a RACI matrix for incident assessment, investigation, and response.Desired1
Vulnerability ManagementPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The service includes capabilities to execute and analyze both internal and external vulnerability scans.Desired4
The vendor utilizes a combination of commercial and open-source technologies to conduct vulnerability scans.Desired4
The service includes a defined methodology for collecting and analyzing vulnerability and asset data from all in-scope sources.Desired4
Vulnerabilities are triaged and prioritized before reporting, with the integration of previous scan results and a common vulnerability management (VM) data source for MDR services.Desired3
Vulnerability scans can be scheduled, initiated, managed, and viewedDesired3
The VM services include application-specific scanning capabilities.Desired3
Security Device ManagementPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The service includes capabilities to manage security technologies in scope, such as firewalls, IDS/IPS, and identity and access management (IAM) systems.Desired3
The vendor has a non-intrusive process for updating software, including signature updates and system patches.Optional3
For device management services, all changes are reviewed to assess potential risks, exposures, or effects on system capacity.Desired4
Security Information and Event ManagementPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The vendor utilizes a defined method to determine pertinent logs for ingestion into the SIEM, with a cost structure that is not solely based on data volume.Desired3
Logs are compressed and encrypted in transit, with a guaranteed delivery via a store-and-forward solution.Optional3
MSB staff has direct capabilities to search and browse original log data within the platform.Desired3
MSB staff can create and modify reports based on collected log data, with clear limitations on the number and complexity of queries.Desired3
The vendor has strong controls in place to secure log data, including encryption, access controls, and comprehensive logging.Desired3
MSB is provided with read-only remote access to its log data on the MDR/MSSP SIEM systems for incident management, analysis, and visualization.Optional3
Standard data retention policies are clearly defined, with the ability to modify them to meet business and compliance requirements.Desired4
Log retention can be offered for a minimum and maximum number of days, with a clear distinction between actively available and offline storage, and a transparent pricing model for specific retention periods.Desired4
The vendor retains a defined amount of data (size and length of time) as part of its standard service.Desired3
Analytics and ReportingPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The vendor utilizes a User and Entity Behavior Analytics (UEBA) methodology to profile and monitor entity and user activities, with specific models and algorithms applied.Desired3
The service supports the implementation and management of both provider-defined and customer-defined watchlists.Desired4
The service utilizes predictive analytics with defined approaches and models/algorithms to anticipate threats.Desired3
The service offers specific network monitoring and forensics features to detect advanced, targeted attacks.Desired3
The service includes specific payload analysis capabilities to detect advanced, targeted attacks.Desired3
The service provides specific endpoint behavior analysis and forensics capabilities to detect advanced, targeted attacks.Desired3
Data and threat visualization capabilities are available to MSB via a dedicated portal.Desired3
The vendor's threat intelligence includes coverage from proprietary research, as well as licensed feeds from well-known sources, and provides insights from dark web monitoring.Desired3
Portals, Reports, and DashboardsPriorityComplianceCommentsPhase 2 Technical Evaluation Criteria
The vendor provides a web-based portal or console that meets MSB's minimum software requirements, with features that include role-based access control (RBAC) and customization.Required3
All services and features, including those delivered by partners, are available via a single portal, regardless of region or business unit.Required3
The portal provides support for federated identity management (FIM).Desired3
The service supports bidirectional threat intelligence using open standards such as STIX/TAXII/OpenIoC.Required3
The service has integration capabilities with third-party service desk and ticketing tools via APIs, with bidirectional support at no additional cost.Optional3
The service provides comprehensive operational, regulatory compliance, and executive reporting capabilities.Required3
MSB can create custom reports via a defined process within the portal.Desired3
The service includes a library of pre-built reports, including compliance reports for regulations such as [list specific regulations, e.g., PCI DSS, HIPAA, GDPR].Desired3

&"Calibri"&10&K008000 General - Recommended for internal use&1#_x000D_

Key

PriorityDefinition
RequiredThis functionality is required and a vendor will be excluded if this functionality is not met.
DesiredThis functionality is desired and expected to be provided by the vendor. Though not vital for the acceptance of this RFP it is weighted in scoring.
OptionalThis functionality is considered “nice to have” but is not vital for acceptance of this RFP.
ComplianceDefinition
NativeFeature/requirement is a standard feature in the current offering.
LicensedFeature/requirement can be achieved through procuring additional licensing through the respondent.
Third-PartyFeature/requirement can be achieved through procuring additional licensing through a third-party.
Not SupportedFeature/requirement cannot be met.

&"Calibri"&10&K008000 General - Recommended for internal use&1#_x000D_

File details come from the government source that posted it. Updated .