1-A1 System Requirements Questionnaire.xlsx
XLSX spreadsheet 35 KB Posted
- Attached to
- Cyber Security Managed Detection and Response Service State and local contract opportunity
- Solicitation number
- 26-081P
- Issued by
- Fairbanks North Star Borough, Alaska
About this file
The document is a System Requirements Questionnaire for a Cyber Security Managed Detection and Response (MDR) Service solicitation by the Matanuska-Susitna Borough (MSB) in Alaska. The questionnaire details comprehensive technical evaluation criteria for potential vendors, covering areas such as employee qualifications, service methodology, security event monitoring, vulnerability management, security device management, and analytics reporting. The procurement seeks a MDR service that can provide advanced cybersecurity monitoring, threat detection, incident response, and comprehensive reporting capabilities, with vendors required to demonstrate specific technological capabilities and service delivery models.
The questionnaire indicates that MSB is seeking a vendor with dedicated security professionals, scalable service offerings, and robust technological capabilities, including fully operated Security Operation Centers, integration with existing Microsoft Defender systems, and advanced threat detection methodologies. Key requirements include proactive threat hunting, real-time event correlation, zero-day exploit detection, vulnerability scanning, and a web-based portal with role-based access control. The evaluation prioritizes vendors who can provide comprehensive services without requiring MSB to purchase additional proprietary technology, with a strong emphasis on collaborative implementation, continuous threat intelligence, and flexible, customizable reporting and monitoring solutions.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| 3-26-081P Cyber Security Managed Detection and Response Service.pdf | ||
| 2-A2 Data Security Questionnaire.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Proponent Questionnaire 26-081P Cyber Security Managed Detection And Response Service: System Requirements Questionnaire
| Vendor: | ||||
| Complete the questionnaire by selecting compliance, adding comments and explaining non-applicable items with evidence where possible. | ||||
| Employee Qualifications | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The organization maintains a dedicated internal staff of MDR professionals to meet client needs, without the reliance on subcontractors for core service delivery. | Required | 5 | ||
| The service offering is scalable to accommodate both small and large customers, with flexible licensing and deployment models. | Required | 1 | ||
| The vendor utilizes a thorough screening and hiring process for MDR staff, including background checks and technical skill assessments. | Required | 1 | ||
| Service Methodology | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The vendor will conduct a detailed assessment of the environment during onboarding to make informed and relevant security recommendations. | Required | 1 | ||
| The vendor provides a clear distribution of employees across delivery, project management, and customer service, with defined geographical locations. | Optional | 3 | ||
| The MDR/MSSP offering supports integration with key MSB-owned systems, including EDR solutions and ticketing systems. (Currently we use Microsoft Defender) | Optional | 3 | ||
| Required technology for this contract, including any log collection and analysis components, resides in the MDR/MSSP facilities. | Desired | 3 | ||
| The vendor owns and operates fully dedicated Security Operation Centers (SOCs) to support MDR/MSS services. | Required | 3 | ||
| The vendor has a defined customer notification and escalation process, which includes a pre-defined frequency for notifications and multiple methods of communication. | Required | 4 | ||
| MSB can be alerted to potential security incidents and can request support via multiple channels, including a dedicated portal, email, and phone support. | Required | 3 | ||
| During the normalization phase, the provider's interaction with the customer is collaborative and focused on a joint effort to fine-tune event triage and alarm handling. | Required | 3 | ||
| Meetings or teleconferences to review performance, issues, and the threat environment occur at a defined frequency, with participation from both analyst and account management support staff. | Required | 3 | ||
| The service includes a data export feature that allows MSB to retrieve all log data, with a clear process and timeline defined for data retrieval upon contract termination. | Desired | 3 | ||
| Service Onboarding and Implementation | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The services do not require MSB to purchase or install proprietary technology, with all necessary components provided by the vendor. | Desired | 3 | ||
| The services are delivered within MSB's internal virtual infrastructure, accommodating scaling of the environment with minimal implications for technology deployment and without additional license costs. | Desired | 1 | ||
| The service includes integration capabilities with enterprise directories and configuration management databases (CMDBs), which support the delivery of core services. | Desired | 3 | ||
| Security Event Monitoring | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The service provides monitoring capabilities for a wide range of data sources, including firewalls, intrusion detection/prevention systems (IDS/IPS), and vulnerability data. | Desired | 3 | ||
| MDR analysts utilize proactive threat hunting methodologies beyond advanced analytics to identify and contain threats. | Desired | 3 | ||
| The service includes a methodology for analyzing data, providing real-time event correlation between data sources, and generating real-time alerts for security incidents and system health. | Desired | 3 | ||
| The vendor maintains an automated and continuous process for updating signatures and rules to defend against new and future threats. | Desired | 3 | ||
| The service supports the creation and management of customized correlation rules, with clear capabilities and limitations available to MSB's staff. | Desired | 3 | ||
| The service has a defined methodology for detecting custom or targeted attacks directed at MSB's users or systems. | Desired | 3 | ||
| Custom alert rules can be configured for specific events, such as administrative logins at unusual times. | Desired | 3 | ||
| The vendor has a well-defined methodology for reducing false positives and negatives. | Desired | 3 | ||
| The service utilizes multiple mechanisms to detect zero-day exploits and ransomware infections, including behavioral analysis and threat intelligence. | Desired | 3 | ||
| The service includes a clear process for managing and incorporating false positive feedback from MSB, with regular reporting and communication. | Desired | 3 | ||
| The vendor's typical workflow for an alert is a defined process that includes automated and manual steps for triage, validation, prioritization, and customer notification. | Desired | 3 | ||
| The working relationship and responsibilities between the vendor's security staff and MSB's security staff are clearly defined, including the use of a RACI matrix for incident assessment, investigation, and response. | Desired | 1 | ||
| Vulnerability Management | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The service includes capabilities to execute and analyze both internal and external vulnerability scans. | Desired | 4 | ||
| The vendor utilizes a combination of commercial and open-source technologies to conduct vulnerability scans. | Desired | 4 | ||
| The service includes a defined methodology for collecting and analyzing vulnerability and asset data from all in-scope sources. | Desired | 4 | ||
| Vulnerabilities are triaged and prioritized before reporting, with the integration of previous scan results and a common vulnerability management (VM) data source for MDR services. | Desired | 3 | ||
| Vulnerability scans can be scheduled, initiated, managed, and viewed | Desired | 3 | ||
| The VM services include application-specific scanning capabilities. | Desired | 3 | ||
| Security Device Management | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The service includes capabilities to manage security technologies in scope, such as firewalls, IDS/IPS, and identity and access management (IAM) systems. | Desired | 3 | ||
| The vendor has a non-intrusive process for updating software, including signature updates and system patches. | Optional | 3 | ||
| For device management services, all changes are reviewed to assess potential risks, exposures, or effects on system capacity. | Desired | 4 | ||
| Security Information and Event Management | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The vendor utilizes a defined method to determine pertinent logs for ingestion into the SIEM, with a cost structure that is not solely based on data volume. | Desired | 3 | ||
| Logs are compressed and encrypted in transit, with a guaranteed delivery via a store-and-forward solution. | Optional | 3 | ||
| MSB staff has direct capabilities to search and browse original log data within the platform. | Desired | 3 | ||
| MSB staff can create and modify reports based on collected log data, with clear limitations on the number and complexity of queries. | Desired | 3 | ||
| The vendor has strong controls in place to secure log data, including encryption, access controls, and comprehensive logging. | Desired | 3 | ||
| MSB is provided with read-only remote access to its log data on the MDR/MSSP SIEM systems for incident management, analysis, and visualization. | Optional | 3 | ||
| Standard data retention policies are clearly defined, with the ability to modify them to meet business and compliance requirements. | Desired | 4 | ||
| Log retention can be offered for a minimum and maximum number of days, with a clear distinction between actively available and offline storage, and a transparent pricing model for specific retention periods. | Desired | 4 | ||
| The vendor retains a defined amount of data (size and length of time) as part of its standard service. | Desired | 3 | ||
| Analytics and Reporting | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The vendor utilizes a User and Entity Behavior Analytics (UEBA) methodology to profile and monitor entity and user activities, with specific models and algorithms applied. | Desired | 3 | ||
| The service supports the implementation and management of both provider-defined and customer-defined watchlists. | Desired | 4 | ||
| The service utilizes predictive analytics with defined approaches and models/algorithms to anticipate threats. | Desired | 3 | ||
| The service offers specific network monitoring and forensics features to detect advanced, targeted attacks. | Desired | 3 | ||
| The service includes specific payload analysis capabilities to detect advanced, targeted attacks. | Desired | 3 | ||
| The service provides specific endpoint behavior analysis and forensics capabilities to detect advanced, targeted attacks. | Desired | 3 | ||
| Data and threat visualization capabilities are available to MSB via a dedicated portal. | Desired | 3 | ||
| The vendor's threat intelligence includes coverage from proprietary research, as well as licensed feeds from well-known sources, and provides insights from dark web monitoring. | Desired | 3 | ||
| Portals, Reports, and Dashboards | Priority | Compliance | Comments | Phase 2 Technical Evaluation Criteria |
| The vendor provides a web-based portal or console that meets MSB's minimum software requirements, with features that include role-based access control (RBAC) and customization. | Required | 3 | ||
| All services and features, including those delivered by partners, are available via a single portal, regardless of region or business unit. | Required | 3 | ||
| The portal provides support for federated identity management (FIM). | Desired | 3 | ||
| The service supports bidirectional threat intelligence using open standards such as STIX/TAXII/OpenIoC. | Required | 3 | ||
| The service has integration capabilities with third-party service desk and ticketing tools via APIs, with bidirectional support at no additional cost. | Optional | 3 | ||
| The service provides comprehensive operational, regulatory compliance, and executive reporting capabilities. | Required | 3 | ||
| MSB can create custom reports via a defined process within the portal. | Desired | 3 | ||
| The service includes a library of pre-built reports, including compliance reports for regulations such as [list specific regulations, e.g., PCI DSS, HIPAA, GDPR]. | Desired | 3 |
&"Calibri"&10&K008000 General - Recommended for internal use&1#_x000D_
Key
| Priority | Definition |
| Required | This functionality is required and a vendor will be excluded if this functionality is not met. |
| Desired | This functionality is desired and expected to be provided by the vendor. Though not vital for the acceptance of this RFP it is weighted in scoring. |
| Optional | This functionality is considered “nice to have” but is not vital for acceptance of this RFP. |
| Compliance | Definition |
| Native | Feature/requirement is a standard feature in the current offering. |
| Licensed | Feature/requirement can be achieved through procuring additional licensing through the respondent. |
| Third-Party | Feature/requirement can be achieved through procuring additional licensing through a third-party. |
| Not Supported | Feature/requirement cannot be met. |
&"Calibri"&10&K008000 General - Recommended for internal use&1#_x000D_
File details come from the government source that posted it. Updated .