1.2.1-RFI_CDISS Recompete Draft SOW.pdf

PDF 739 KB Posted

Attached to
Request for Information - Cyber Defense and Intelligence Support Services (CDISS) Federal contract opportunity
Solicitation number
RFI-ICE-FY26-CCISS
Issued by
Immigration and Customs Enforcement

About this file

This document is a Statement of Work (SOW) for Cyber Defense and Intelligence Support Services (CDISS) for the U.S. Department of Homeland Security (DHS), U.S. Immigration and Customs Enforcement (ICE), Office of the Chief Information Officer (OCIO), and Information Assurance Division (IAD). The SOW outlines comprehensive cybersecurity services to support ICE's Cyber Defense and Intelligence Branch (CDIB), focusing on identifying, protecting, detecting, responding to, and recovering from cyber security threats across ICE's enterprise IT environment.

The contract requires a contractor to provide 24/7/365 monitoring, intrusion detection, and protective security services for ICE networks, including local and wide area networks, trusted internet connections, cloud-based infrastructure, security devices, servers, and workstations. Key capabilities include vulnerability scanning, penetration testing, continuous threat exposure management, cyber threat hunting, security operations center (SOC) support, incident response, forensic analysis, and data science enrichment. The contractor will support approximately 53,000 network devices and must maintain compliance with DHS Cybersecurity Service Provider (CSP) Framework Evaluator Scoring Metrics. The contract will be performed primarily in Chandler, AZ and Washington, DC, with the potential to support other DHS components.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information - Cyber Defense and Intelligence Support Services (CDISS), newest first.
File Type Posted
1.2.1-RFI_CDISS RFI.pdf PDF
1.2.1-RFI_Comment Matrix.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ICE-Internal: Internal agency information. Not for public or external dissemination.

Statement of Work (SOW) 5

Cyber Defense and Intelligence Support Services (CDISS) 7

U.S. Department of Homeland Security (DHS) 10 U.S. Immigration and Customs Enforcement (ICE) 11

Office of the Chief Information Officer (OCIO) 12 Information Assurance Division (IAD) 13

Office of the Chief Information Officer 19 Washington, DC 20

July 8, 2025 24

1.0 PROJECT TITLE 28

Cyber Defense and Intelligence Support Services (CDISS) 29

2.0 BACKGROUND 30

The U.S. Department of Homeland Security (DHS), U.S. Immigrations and Customs 31 Enforcement (ICE), Office of the Chief Information Officer (OCIO), Information Assurance 32 Division (IAD), implements an agency level cybersecurity program, managed by the ICE Chief 33 Information Security Officer (CISO). The ICE CISO is responsible for compliance with Federal 34 law, regulation, and policy regarding information technology and security, including the 35 Computer Security Act, Federal Information Security Management Act (FISMA), Office of 36 Management and Budget (OMB) Circular A-130, Executive Orders, Homeland Security 37 Presidential Directives, National Institute of Standards and Technology (NIST) guidance, and 38 DHS Information Security Policy. 39

The ICE CISO requires specialized technical services to support the Cyber Defense and 40 Intelligence Branch (CDIB). 41

The Cyber Defense and Intelligence Branch (CDIB) delivers comprehensive services to meet 42 the standards set forth in the DHS Cybersecurity Service Provider (CSP) Framework 43 Evaluator Scoring Metrics (ESM). CDIB manages all the functional areas within the DHS 44 CSP ESM which includes but is not limited to the technology aspects of security incident 45 response and forensics (classified, personal identifiable information (PII), intrusion attempts, 46 etc.), and provides ICE management with information assurance threat and vulnerability 47 information through vulnerability scanning, and penetration test reports and quarterly 48 classified threat briefings. CDIB provides ICE with cyber threat intelligence, planning, and hunt 49 capabilities. It analyzes data and prepares reports and dashboards that document 50 vulnerabilities from network based attacks and recommends actions to prevent, repair or 51 mitigate these vulnerabilities. CDIB coordinates with the ICE SOC and DHS Network 52 Operations and Security Center (NOSC), and other DHS Components to ensure relevant and 53 timely communication in reference to discovered security issues and their recommended 54 solutions. This information is in turn communicated to the ICE SOC. All aspects of this 55 contract support the entirety of the ICE Cyber Defense and Intelligence Branch (CDIB) 56

3.0 SCOPE OF WORK 57

The purpose of this Statement of Work (SOW) is to obtain quality professional support services to 58 improve the ability of ICE to Identify, Protect, Detect, Respond and Recover from cyber security 59 threats and/or incidents and events. The Contractor shall work closely and collaborate with all parties 60 to ensure adherence to policies and procedures and provide support needed to perform the necessary 61 actions to adhere to the DHS CSP ESM and maintain the ICE CSP Authority to Operate (ATO) as 62 well as the Center of Excellence (COE) and Cybersecurity Services Provider (CSP) designations. 63 Currently ICE provides services for two (2) subscribers as baseline work, but the number of 64 subscribers is subject to increase or decrease during the life of the contract. This includes but is not 65 limited to 24/7/365 monitoring, intrusion detection, and protective security services supporting ICE 66 networks including local area networks (LANs), wide area networks (WAN), Trusted Internet 67 Connections (TIC), Cloud-based infrastructure, security devices, servers, and workstations. The 68 Contractor will also support other DHS Components as subscribers, under ICE oversight and from 69 ICE locations, as a DHS Cybersecurity Service Provider (CSP). Under this designation, Components 70 may purchase their SOC/Security services from a Provider of their choice. These services may be 71 provided by the ICE Contractor, at ICE facilities, and overseen by ICE Federal personnel with minor 72 exceptions as determined by the Government in the scope defined by the Provider/Subscriber 73 agreement. 74

The Contractor shall also provide CSP assessment support, vulnerability scanning and penetration 75 (“blue/red/purple team”) testing capabilities to support the ICE Security Authorization and Continuous 76 Monitoring processes as required by the Federal Information Security Modernization Act (FISMA) of 77 2014. The ICE SOC and CSIRC are responsible for the overall security of ICE Enterprise-wide 78 information systems and collect, investigate, and report any suspected and confirmed security 79 violations. The term “Classified” in reference to this SOW is defined as Top Secret/SCI level or 80 below. Additionally, ICE is designated as a DHS Center of Excellence (COE) and a DHS 81 Cybersecurity Service Provider (CSP). The Contractor must adhere to all requirements of the DHS 82 CSP Evaluator Scoring Metrics (ESM) current version as well as support any CSP-related assessments 83 and activities. Where the SOC does not have direct responsibility for a metric, they are required to 84 support the responsible teams where needed. This includes any new changes to DHS CSP ESM 85 metrics and/or maturity levels to maintain the COE and CSP certification requirements. The 86 Contractor should have experience either as a DHS CSP or a Department of Defense Cyber Security 87 Service Provider (CSSP). 88

Should the Department of Homeland Security adopt and implement the Cybersecurity Maturity Model 89 Certification (CMMC), the Contractor will comply with all mandates or directives put forth by the 90 Department in a timely manner. 91

4.0 OBJECTIVE 92

To utilize a cyber intrusion “kill chain” process to improve the identification, detection, 93 protection, and response to Advanced Persistent Threats (APT). The goal is to identify the 94 threat earlier in the “kill chain” process allowing for better risk management of ICE technology 95 resources. 96

The Contractor must utilize ICE-provided sensors, systems, and tools to achieve continuous 97 monitoring on all ICE and Subscriber systems, to include LANs, WANs, TICs, Stand-alone 98 Networks, and Cloud-based infrastructure (both Commercial and GovCloud or any cloud 99 services approved by ICE) for signs of intrusion, compromise, data disclosure, data 100 exfiltration, misuse, and compliance. 101

The Contractor will be responsible for: 102

• Providing scanning, analysis and reporting for approximately 53,000 network devices 103 for vulnerabilities and compliance; 104

• Ensuring Information Technology (IT) resources remain secure and available for ICE 105 personnel to achieve the mission; 106

• Providing support to non-ICE entities that rely on ICE data, applications, or IT 107 infrastructure; 108

• Supporting IT disaster recovery response strategies and plans; 109

• Supporting DHS Headquarters (HQ), field/Program Offices, and other DHS-ICE 110 identified users, including Component Subscribers, to meet these objectives; 111

• Act as a cybersecurity-focused liaison for Enforcement and Removal Operations 112 (ERO) and Homeland Security Investigations (HSI) on Operational briefings as 113 requested; 114

• Implementing a functional Security Operations Center (SOC) for all cybersecurity 115 responsibilities listed within the Statement of Work utilizing a tier-less methodology. 116

• Identifying, coordinating, recommending, and providing best practice solutions and 117 continuous process improvement strategies; 118

• Providing services in support of DHS ICE OCIO requirements, priorities, objectives, 119 and activities under challenging situations including, but not limited to, emergent 120 requirements, emergency situations, incidents of national significance, and other 121 priorities as identified by ICE in support of governmental activities; 122

• Providing ICE with the ability, capacity, and capability to redistribute and re-123 prioritize workload and resources to meet increased, changing and evolving 124 requirements; 125

• Providing ICE with the ability to scan and monitor for indicators of compromise 126 (IOC) on ICE LANs, WANs, TICs, Stand-alone Networks and Cloud-based 127 infrastructure; 128

• Providing vulnerability scanning and penetration testing services to identify 129 weaknesses in applications, databases, platforms, and network infrastructure; 130

• Providing continuous recommendations to improve security capabilities and reduce 131 security vulnerabilities; 132

• Continue implementation and maintenance of ICE Zero Trust roadmap and reporting; 133

• Implementing and verifying the continuous monitoring, detecting, and responding to 134 security events on ICE LANs to include WANs, TICs, Stand-alone Networks and 135 Cloud-based infrastructure; 136

• Providing configuration reviews of firewalls, routers, and switches as required. 137

• Support ICE with new and emerging cybersecurity initiatives and technologies such 138 as but not limited to: 139

• Preparing ICE for transition to Post-Quantum Computing (PQC) level encryption; 140

• Preparing ICE to mitigate internal and external cyber risks arising from AI/ML 141 technologies. 142

• Preparing ICE to modernize cybersecurity tools by securely adopting agentic 143 services, which involve autonomous agents that can make decisions and take 144 actions independently, or MCP-type services, which refer to Model Context 145 Protocol that standardizes the interaction between AI models and their operational 146 environments. 147

• Support any and all DHS CSP activities including the assessment for ATO renewal. 148

5.0 PLACE OF PERFORMANCE AND TELEWORK 149

Services will be provided primarily in Chandler, AZ and Washington, DC (National Capital 150 Region (NCR)). However, vulnerability testing/penetration testing services may require travel to 151 Contractor sites outside of these two locations, but still within the Continental United States 152 (CONUS). Local travel in the NCR may be required to better provide service to Subscribers and 153 will not be reimbursed by the Government. Travel outside the NCR may be required and, if 154 required by Subscriber’s geographic location, at cost to the Subscriber Component. Services will 155 be provided on-site (Government facility) or remotely, as determined by the type of service 156 being provided. Staff must be located within the local commuting area of either the Chandler, 157 AZ facility or the NCR and able to report on site as needed. Fully remote work may be approved 158 by the Government on a case-by-case basis. The Contractor may be required to scan non-159 government networks in specific circumstances, at the direction of the Government, however, the 160 majority will be on government systems and networks. The Contractor shall be granted access to 161 open/close and utilize appropriate DHS classified Homeland Secure Data Network (HSDN) and 162 DHS Top Secret/Secure Compartmentalized Information Facility (SCIF) spaces as required to 163 complete identified tasks. Staff with classified duties (as determined by the Government) must be 164 able to report to a DHS ICE-accessible SCIF within two (2) hours. 165

The SOC/CSIRC floor operates 24/7/365 on-site and the Contractor will work shifts accordingly 166 to support Security Operations and Continuous Monitoring. A Contractor Shift Supervisor will 167 be present on the SOC Floor at all times. At least two Contractor personnel must be physically 168 present on the floor at all times. Any exception to this requires Government notification and 169 approval and will only be granted for a temporary extenuating circumstance NTE 24 hours. 170 Federal staff is on-call 24/7/365 but is not on-site 24/7/365. Contractors are permitted to be in the 171 building when Government personnel are not due to the nature of these activities. 24/7/365 172 operations will be on-site and are not eligible for telework without prior Government approval. 173 Other task areas will work standard Monday-Friday schedules but may be called after hours 174 during incidents. Arrival/Departure may be adjusted however core hours of 9AM-3PM EST will 175 be observed unless otherwise approved by the Government. 176

This Contract will utilize telework flexibilities. Telework/remote work will be approved on a 177 situational basis and not all employees will be eligible for telework. The Government will 178 determine who is eligible and provide desk space for those who are not. The Contractor will 179 submit a telework plan for supervision, management, and quality assurance monitoring within 10 180 days of award for Government consideration. Contractors deemed eligible for telework will sign 181 a telework agreement. Telecommuting may be revised, restricted, or revoked at any time, based 182 on the Government discretion. Permanent, full-time telework (Remote Work) will be approved 183 on a case-by-case basis by the Government and COR prior to hiring a proposed Remote 184 employee or transitioning an employee to a remote status, and will be dependent on role. 185 Employees with classified duties must be able to report to a DHS/ICE SCIF within 2 hours. 186 Local travel/commuting for teleworking employees will not be reimbursed by the Government. 187

Non-local travel on the contract will be very limited. Any non-local travel at the request of the 188 Government shall be in compliance with FAR 31.205-46. Travel will be approved by the 189 Government. The Government will not pay for local travel in the NCR to Customer sites. 190

5.1 Observance of Legal Holidays and Excused Absence 191

The Government hereby provides notification that Government personnel observe the listed 192 days as holidays: These holidays only apply to services performed within the United States and 193 is provided for informational purposes only. 194

(1) New Year's Day 195

(2) Martin Luther King's Birthday 196

(3) President’s Day 197

(4) Memorial Day 198

(5) Juneteenth National Independence Day 199

(6) Independence Day 200

(7) Labor Day 201

(8) Columbus Day 202

(9) Veterans' Day 203

(10) Thanksgiving Day 204

(11) Christmas Day 205

In addition to the days designated as holidays, the Government observes the following days: 206

1. Any other day designated by Federal Statute 207

2. Any other day designated by Executive Order 208

3. Any other day designated by the President’s Proclamation 209

It is understood and agreed between the Government and the Contractor that observance of such 210 days by Government personnel shall not otherwise be a reason for an additional period of 211 performance, or entitlement of compensation except as set forth within this Task Order. This 212 provision does not preclude reimbursement for authorized overtime work if applicable to this 213 Task Order. 214

When the Federal and governmental entities grant excused absence to its employees, the 215 Contractor may also dismiss its assigned Contractor personnel; however, the Contractor may 216 not bill the government for time associated with such excused absences. The Contractor agrees 217 to continue to provide sufficient personnel to perform critical tasks already in operation or 218 scheduled and shall be guided by the instructions issued by the Task Order Contracting Officer 219 or the Task Order Contracting Officer Representative. 220

Nothing within this special requirement abrogates the rights and responsibilities of the parties 221 relating to stop work provisions as cited in other sections of this Task Order. If Government 222 personnel are furloughed, the Contractor shall contact the Task Order Contracting Officer or the 223 Task Order Contracting Officer Representative to receive direction. It is the Government’s 224 decision as to whether this Task Order and their respective prices will be affected. 225

Outside of these standard support hours of operation, the Contractor shall provide on-call 226 support and respond within one hour to emergency situations. In general, an emergency is when 227 there is a network outage, compromise, or other major incident requiring emergent response. An 228 emergency call tree will be provided and includes Federal oversight. If work is performed on 229 any T&M CLINs outside of regular support hours, the Contractor may charge but is expected to 230 flex hours within the same period unless overtime is authorized, in writing, by the ITPM and 231

COR. 232

Some tasks on this contract operate 24x7x365. For these tasks, Contractors will work regardless 233 of holiday, furlough, or any other event. The Government may direct work to be completed 234 from an alternate location in emergency or COOP situations, however the SOC floor will 235 continue to operate 24x7x365. 236

6.0 REFERENCES 237

The following documents are applicable to understanding the SOC/CSIRC requirements. 238

• Department of Homeland Security Cybersecurity Services Provider (CSP) Evaluator 239 Scoring Metrics 240

• Federal Information Security Modernization Act (FISMA) of 2014 241

• Privacy Act of 1974 242

• Computer Security Act of 1987 243

• Office of Management and Budget (OMB) Circular A-127, Financial Management 244 Systems 245

• OMB Circular A-130, Management of Federal Information Resources 246

• OMB Memorandum M-22-09, Moving the U.S. Government Toward Zero Trust 247 Cybersecurity Principles, January 26, 2022 248

• OMB Memorandum M-19-17, Enabling Mission Delivery through Improved Identity, 249 Credential, and Access Management, May 2019Federal Information System Controls 250 Audit Manual (FISCAM), latest version 251

• National Institute of Standards and Technology (NIST) Computer Security Resource 252 Center (CSRC) Standards, Guidelines, Special Publications 253

• NIST Special Publication (SP) 800-37, Revision 2, Risk Management Framework for 254 Information Systems and Organizations, December 2018 255

• NIST Special Publication 800-39, Managing Information Security Risk: 256 Organization, Mission, and Information System View, March 2011 257

• National Industrial Security Program Operating Manual (NISPOM) 258

• 'DHS 4300A Sensitive Systems Handbook, latest version 259

• 'DHS National Security Systems Policy Directive 4300B, Version 10.1, November 260 21, 2018' for NSS Collateral (Unclass, Secret or Top-Secret Collateral). 261

• ICE System Lifecycle Management (SLM) Handbook 262

• DHS Management Directives Volume 11000 – Security 263

• OMB Memorandum M-21-31 “Improving the Federal Government’s Investigative 264 and Remediation Capabilities Related to Cybersecurity Incidents,” August 27, 2021 265

• Executive Order 14028 “Improving the Nation’s Cybersecurity,” May 12, 2021 266

Upon award the Contractor will be provided with additional relevant documentation regarding 267 existing security requirements in order to better support the SOC/CSIRC activities. Please note 268 that if newer versions of these documents are released or new regulations are implemented, the 269 Contractor must comply with the updated version. 270

The Government will provide additional applicable documents as required at the task order level, 271 such as: 272

• DHS Sensitive Systems Policy Directive 4300A and DHS 4300A Sensitive Systems 273 Handbook, 274

• DHS National Security Systems Policy Directive 4300B and DHS 4300 National 275 Security Systems Handbook 276

• DHS CSP Framework Evaluator Scoring Metrics (ESM) 277

• DHS Technical Reference Model (TRM) 278

• DHS Configuration Guides 279

• DHS Security Authorization Guide 280

• International Information Systems Security Certification Consortium (ISC2) 281 Standards 282

7.0 SPECIFIC TASKS 283

All tasks in the below sections may include work for DHS Subscribers, as applicable. Subscriber 284 work is not guaranteed. All work will be performed at ICE facilities under ICE direction unless 285 otherwise directed by the Government. 286

7.1 Program Management Support 287

7.1.1 Senior Program Management Support 288

The Contractor shall be responsible for providing oversight and management of all 289 Contractor work effort out of the Washington, DC location. These duties are inclusive of 290 those associated with Zero Trust or any other unforeseen Special Projects associated with 291 Executive Orders or Federal mandates. The Senior Program Manager (PM) duties include, 292 but are not limited to: 293

• Monitoring the performance of Contract personnel, identifying any degraded quality 294 of service, and proposing corrective actions to the Government Contracting Officer’s 295 Representative (COR) and Federal Program Manager, up to and including employee 296 termination. 297

• Creating and maintaining Key Performance Indicators (KPIs), as agreed to by the 298 Government, for effectiveness of SOC Operations 299

• Ensuring that the quality of service delivered under this contract maintains a high-300 quality standard. 301

• Implements Subscriber outreach methods for Subscriber feedback 302

• Maintain Cybersecurity Service Provider (CSP) Service Catalog 303

• Ensuring reporting requirements and all other supporting documentation are adhered 304 to and delivered in accordance with guidelines and specifications as set forth in this 305 Statement of Work. 306

• Providing a draft project plan that encompasses the ICE Strategic, Tactical, and 307 Business objectives, with resources and milestones and submitted to the ICE Program 308 Manager for review. 309

• Maintaining a master schedule for CDIB projects and activities: 310

• Baseline schedules that identify schedule slippage, 311

• Resource mapping to projects and activities (contract personnel assigned), 312

• Critical path identification for high-priority projects. 313

• Providing weekly status reports to the Government PM and/or COR that include 314 individual project schedules with weekly progress tracking, status of ongoing 315 activities, issues, recommendations for problem resolution, and upcoming 316 projects/activities. 317

• Delivering weekly project/activity quad charts for ICE OCIO reporting. 318

• The Senior PM must work with the PM and/or COR to ensure that any activities 319 associated with the special projects are clearly identified and tracked and invoiced 320 appropriately on a separate Contract Line Item Number (CLIN). 321

• The Senior PM must meet with the PM and/or COR on a monthly or ad hoc basis. 322 All meetings shall have agendas planned in advance. 323

• Meeting minutes shall be provided to all meeting participants for all scheduled 324 meetings. 325

• The meeting minutes will capture at least the following information: subject, date, 326 attendees, major decisions, areas of non-agreement, and any action items assigned 327 during the meeting. 328

• Minutes shall be provided in electronic format in a timely manner, no later than one 329

(1) business day after the conclusion of the meeting, so as to reflect real time 330 consideration for the actions to be undertaken or issues addressed. A master action 331 item list will be maintained by the Contractor’s Senior PM. 332

• The Senior PM must facilitate the coordination of meetings (IAD will identify 333 meeting spaces and the Contractor shall send out invitation and background 334 information). Crosscutting issues/risks identified in meetings will be promulgated to 335 the appropriate IAD representative. 336

• The Contractor shall develop a final Quality Assurance Plan (QAP) 30 days after 337 award. 338

• The QAP shall include the purpose of the plan, scope, quality objectives, 339 documentation produced or key performance objectives, standards or guidelines used 340 to determine compliance, artifacts for the review, a review plan to include testing, 341 roles and responsibilities, problem resolution, and maintenance of quality records. 342

The QAP will also detail the review process for content, technical editing, and 343 timeliness. The QAP will also serve as supporting documentation for government 344 performance monitoring. The monthly Quality Assurance Review shall include the 345 previous month’s QAP score showing trending information over a minimum of 6 346 previous months 347

• The QAP will also detail the review process for content, technical editing, and 348 timeliness, and shall be incorporated into the Contractors monthly reporting 349 requirements and serve as supporting documentation for government performance 350 monitoring. 351

• The Senior PM must submit a financial report of the previous month’s completed 352 travel expenses, labor costs, overtime, and any travel. This Financial Report shall be 353 cumulative for the contract period and include projected burn rates for the balance of 354 the contract. The Financial Report is due by the 10th business day of the month. 355

7.2 Security Operations Center/Computer Security Incident Response Center 356

(SOC/CSIRC) 357

7.2.1 SOC Management 358

7.2.1.1 Security Operations Center (SOC) - Team Lead Support 359

The Contractor must provide a Team Lead for the SOC. The Team Lead is responsible for 360 providing the oversight and management of the day-to-day duties of SOC/CSIRC team located in 361 SOC/CSIRC West (Chandler, Arizona facility). 362

The Contractor’s Team Lead is responsible for ensuring that all activities are accomplished 363 within the general scope of the contract including: 364

• Monitoring and ensuring adequate availability of the funds for authorized work; 365

• Resolving management and programmatic issues 366

• Monitoring/ensuring performance within budget and schedule 367

• Monitoring appropriate approval procedures for the authorization of travel 368

• Facilitating/maintaining effective interaction and coordination between ICE 369 Government project leads and the Contractor project leads 370

• Closely monitoring all work within the SOC/CSIRC to support and provide advanced 371 notification of any deviation from budget, schedule, or resources 372

The Contractor shall provide Shift Supervisors who will be the lead technical manager for each 373 shift in SOC/CSIRC West. A Shift Supervisor must be on duty and provide continuous support 374 during the defined operational hours for the SOC/CSIRC West team. The SOC team will develop 375 and maintain detailed Standard Operating Procedure (SOP) documents and playbooks to 376 document all processes and procedures. These will be updated annually or with any major 377 changes or process improvements. 378

7.2.1.2 SOC – Chandler, AZ – On Site Facility 379

The ICE Security Operations Center (SOC) provides comprehensive services to meet the 380 standards set forth in the DHS Cybersecurity Service Provider (CSP) Framework Evaluator 381

Scoring Metrics (ESM), DHS 4300A, and other applicable policies, mandates, and orders related 382 to cybersecurity, and improve the ability of ICE to Identify, Protect, Detect, Respond and 383 Recover cyber security threats as a DHS Center of Excellence (COE) and CSP. The ICE SOC’s 384 functions include: 385

• Continuous monitoring of ICE's networks and users to detect and respond to threats in 386 real-time. 387

• Incident Response to take immediate action to address and mitigate cyber incidents and 388 insider threats. 389

• Cyber Forensics to support investigative and intelligence organizations internally and 390 across DHS with forensic analysis to recreate events and incidents, including 391 preservation and storage of forensically sound data for law enforcement usage. 392

The Contractor shall design and implement a Functional SOC Methodology incorporating the 393 functional task areas defined below that does not rely on a traditional tiered SOC structure, but 394 should incorporate all functional areas and have identifiable points of escalation. Multiple 395 functions may be performed by the same Labor Category (eg, a SOC Analyst may conduct 396 incident response and malware analysis functions) as long as all functions can be performed 397 effectively and efficiently. 398

7.2.1.3 Auditing 399

The Contractor in the SOC/CSIRC West facility shall conduct weekly audits on the 400 configuration of security event monitor devices. The Contractor shall create a detailed 401 Auditing Plan for verifying the continuous monitoring, detecting, and responding to security 402 events on the ICE network. Weekly audits must include, but are not limited to, log reviews of 403 successful and failed authentication attempts, file accesses, security policy changes, account 404 changes (account creation, account deletion, and account privilege assignments), and use of 405 privileges. The Contractor shall provide audit results in a weekly report for the devices listed 406 and demonstrate and report the status of remediation efforts in weekly and monthly reports. 407 These reports will incorporate various metrics as they are used in audit and other findings 408 made available to and/or by the Contractor or government PM and other governing 409 government entities. 410

7.2.1.4 Coordinating 411

The Contractor in the SOC/CSIRC West facility shall coordinate with other DHS and US 412 Government agencies continually. Coordination shall be two-way in nature and provide ICE and 413 DHS Components with information regarding security incidents in the ICE network. The 414 Contractor shall use information from other agencies to improve ICE security posture and quickly 415 react to fast moving threats directed at USG networks. 416

For Subscribers, the ICE Security Operations Center (SOC) will: 417

• Lead bi-weekly situational briefs with Subscriber to notify of any 418 identified/confirmed cyber incidents, attacks or misuse. ICE SOC shall ensure 419 overall impact to Subscriber environment is included in all reporting. At the 420 Subscriber’s request, these briefs may be more or less frequent, or not held with 421 approval from ICE CSP PMO. 422

• Prepare & distribute bi-weekly & monthly written reports covering SOC actions, 423 trends & status of high-profile investigations. At the Subscriber’s request, these 424 reports may be more or less frequent, or not sent with approval from ICE CSP PMO. 425

• Maintain awareness of environmental security posture by 24x7 monitoring of SIEM 426 & other security tools. 427

• Maintain regular communication with Subscriber relating to cyber threats & ongoing 428 incidents and maintain a Subscriber-specific call tree for incident response. 429

• Coordinate with the Subscriber on any SOC-related activities as required by the 430 Subscriber MOA, including high-level support of their CSP assessment (only in the 431 role of the Provider), if requested. 432

7.2.2 Monitoring, Automation, and Reporting 433

7.2.2.1 Monitoring and Detection Development 434

• Enrichment of current monitoring capabilities to automate detection of alerts and 435 initial triage. 436

7.2.2.2 Intrusion Detection System (IDS) Operations and Maintenance: 437

The IDS Operations and Maintenance functional area shall: 438

• Provide monitoring of the ICE IDS for signs of compromise, misuse, compliance, and 439 general health within ICE networks. 440

• Prioritize IDS events or alerts according to risk and severity. 441

• Tailor existing IDS rule sets, policies and signatures to ICE network environment and 442 systems. 443

• Customize, review and tune IDS signature sets. 444

• Provide configuration, deployment and maintenance of IDS network and host based 445 sensors. 446

• Tuning of sensor policies to reduce false positives 447

7.2.2.3 Reporting (Daily and Monthly Situation Reporting) SOC/CSIRC 448

The Contractor in the SOC/CSIRC West facility shall provide daily and monthly situation 449 reporting. The daily reporting must cover each day’s activities, the issues being tracked, and 450 the status of each issue. The monthly report must contain at least the following items: 451

• Duty Roster 452

• Summary of critical or urgent security issues being tracked 453

• Status of each area of responsibility 454

• Summary of critical or urgent administrative issues being tracked 455

• List of any needs/actions from the Government. 456

• Conduct trend analysis on threats/intelligence 457

The Contractor shall: 458

• Upload and maintain these reports in the ICE document management system. 459

• Use the ICE and DHS-provided portal for tracking security event current status, 460 details of event, and information relevant to incidents. This portal shall be the 461 primary repository of security event information. 462

• Use the ICE and DHS-provided collaboration capability. 463

• Create a watch log and a watch supervisor turnover log and store these logs in the 464 document management system. 465

• Work closely with the ICE Computer Security Incident Response Center (CSIRC). 466

7.2.3 Threat Detection and Analysis 467

7.2.3.1 Security Event Investigation/Analysis 468

The Security Event Investigation / Analysis functional area will be responsible for 469 monitoring, detecting, scanning, recording, auditing, analyzing, reporting, remediating, 470 coordinating, and tracking security related events for ICE IT Systems. The analysts will 471 support 24 x 7, 365 days per year SOC Operations to prevent, detect, contain, and 472 eradicate cyber security threats targeting ICE systems and networks using Intrusion 473 Detection Systems (IDS), Security Information and Event Management (SIEM) and 474 other security tools. The Security Event Investigators/Analysts shall: 475

• Monitor the logs, alerts, and unusual network activity as outlined by SOC/CSIRC 476 SOPs for trend analysis to spot patterns within ICE networks and develop 477 representations of normal activities. This will be tailored to meet ICE’s needs based 478 on current prioritizations. 479

• Develop, maintain, and follow Standard Operating Procedures (SOPs) for computer forensics 480 collection and analysis (Reference DHS 4300A SENSITIVE SYSTEMS HANDBOOK 481 ATTACHMENT F – INCIDENT RESPONSE), which describes how & when events are to 482 be escalated, to include both administrative & technical escalation. 483

• Meets all requirements as defined by the DHS CSP ESM Incident Handling metrics. 484

• Coordinate with Subscriber personnel regarding any incidents on or affecting their systems or 485 endpoints. 486

• Support and coordinate with appropriate DHS organizations, including but not limited to, the 487 DHS NOSC, Cybersecurity and Infrastructure Security Agency (CISA), Chief Information 488 Officer (CIO), CISO, Office of the Inspector General (OIG), Homeland Security 489 Investigations (HSI), Office of Professional Responsibility (OPR), other ICE organizations, 490 and other DHS Component SOCs. 491

• Coordinate with Law Enforcement and Intelligence organizations as appropriate. 492

• Report the results of computer/cyber forensics activities to the ICE, DHS SOC, CISA and 493 other appropriate parties. Cyber Forensics is also called Computer Forensics. The aim of 494 cyber forensics is to determine who is responsible for what exactly happened on the 495 computer while documenting the evidence and performing a proper investigation. 496

• Follow ICE and DHS disclosure and privacy guidance. 497

• Comply with Office of Professional Responsibility (OPR) instruction concerning performing 498 computer forensic activities in support of ongoing investigations. 499

• Work with the ICE Privacy Office to address suspected or confirmed privacy incidents to 500 ensure timely validation and reporting. 501

• Comply with DHS NOSC procedures for cyber security events and incident response 502 analysis (Reference DHS 4300A SENSITIVE SYSTEMS HANDBOOK ATTACHMENT F 503

– INCIDENT RESPONSE). 504

• Act as primary coordinator of all actions taken in support of incident response, including 505 Subscribers. 506

• Maintain “call tree” to enable quick response to cyber attacks, ensuring key personnel 507 respond in a timely manner, including for Subscribers 508

• Conduct daily log analysis for identifying security incidents, policy violations, and malicious 509 code. 510

• Perform correlation of Network and Host Intrusion Detection System (NIDS/HIDS) logs 511 with other records such as firewall\proxy logs, anti-virus, server audit trails as well as 512 vulnerability information on ICE targets in near-real time. 513

• Prioritize resources for daily analysis of security logs to detect incidents on ICE network and 514 assist in remediation. 515

• Create visual trend reporting dashboards with analysis, which will be available via real-time 516 dashboard to ICE personnel and leadership at all times and reviewed weekly on Operational 517 calls, including but not limited to: 518

• Security events prioritize by Threat Level 519

• Open and Closed incidents 520

• Blacklisted or suspicious source IPs targeting ICE targets 521

• Prohibited or suspicious protocols and ports active on ICE network. 522

• Recurring vulnerabilities 523

• Analyze suspected or confirmed security incidents to determine overall impact to Subscriber 524 network. 525

• Conduct threat hunting investigations in support of the Cyber Threat Hunting Program 526 performing the following actions: 527

• Perform repeatable process to confirm if cyber threat exposure intel affects the ICE 528 environment. 529

• Analyze data from multiple disparate sources to provide new insight into threats to the 530 ICE environment. 531

• Identify, monitor, and investigate endpoint, network, and cloud-based threats. 532

• Perform data analysis on User Entity and Behavior Analytics (UEBA) detections to 533 enrich threat hunting, monitoring, and detection capabilities. 534

• Identify attack vector used & document any vulnerabilities/exploits leveraged. 535

• Apply external security classification standards (specifically but not limited to MITRE 536 ATT&CK and D3FEND Frameworks) to all event notifications 537

• Determine root cause & produce RCA (root-cause analysis) document on an as-needed basis. 538

• Communicate all response actions to DHS management via NOSC-designated system to 539 ensure DHS CIO has situational awareness of incident. 540

• Classify each security event into a particular category based on DHS 4300 guidelines 541

• Produce cyber incident notifications that inform subscriber of pertinent details & pending 542 action items 543

7.2.3.2 Malware Analysis 544

The Contractor at the SOC/CSIRC West will be responsible for SIEM (Security Information & 545 Event Management) Operations and Maintenance. This work is primarily done out of the 546 SOC/CSIRC West facility but must be able to be done anywhere with capabilities in the NCR as 547 well. The malware analysis functional area shall include: 548

• Provide monitoring of the existing Component SIEM for signs of compromise, 549 misuse, compliance, and general health within Component networks and/or 550 Subscriber networks, as applicable. 551

• Prioritize SIEM events or alerts according to risk and severity. 552

• Tailor existing SIEM rule sets, policies and signatures to ICE network environment 553 and systems. 554

• Customize, review and tune SIEM signature sets. 555

• Provide configuration, deployment and maintenance of SIEM & host-based sensors. 556

• Tuning of SIEM correlation searches to reduce false positives 557

• The Contractor will deploy and/or assist other engineering groups with the 558 deployment of new and existing security tools as needed. 559

• The Contractor will determine best practices to schedule malware scans to ensure 560 systems are protected and users’ business needs are not impacted. 561

• The Contractor will continually tune security policies to ensure systems are protected 562 in the most efficient way possible to minimize impact to user business practices. 563

• The Contractor will utilize existing deployment frameworks to monitor and ensure 564 compliance for endpoint anti-malware signatures and other periodic updates 565

• The Contractor will configure anti-malware policies to scan data-at-rest (i.e., time-566 based scheduled scans) and data-in-motion (i.e., scanning data as it is read or written 567 to disk) 568

• The Contractor will additionally configure process containment and heuristic based 569 scanning to aid in detecting and preventing file less malware or 0day attacks from 570 spreading. 571

• The Contractor will configure anti-malware software to be able to begin scans 572 remotely to aid with immediate incident response 573

• The Contractor will provide recommendations to Subscribers based on industry 574 standard best practices as well as organization specific data obtained by internal ICE 575 SOC research. 576

7.2.3.3 Forensic Analysis 577

The Forensic Analysis functional area will support the SOC investigative and Incident Response 578 processes. They will provide support daily Monday through Friday during core business hours. 579 and after hours on an on-call basis, for advanced network and digital media analysis activities, 580 and malicious code reverse engineering and analysis. Functional tasks include: 581

• Access/Image remotely using Enterprise Forensic tools. 582

• Secure and preserve the state of any equipment suspected of being involved in a cyber 583 incident. 584

• Package and ship equipment to a designated computer forensic analysis team. 585

• Configure queries for target file and word searches on ICE network systems. 586

• Configure and maintain Forensic and Log Management tools in support of identifying rogue 587 and malicious software of ICE systems. 588

• Configure Forensic and Log Management tools in support of identifying suspicious and 589 unapproved activities on ICE systems. 590

• Adhere to existing policies and procedures for preserving chain of custody of equipment as 591 part of investigations, as required. 592

• Maintain adequate facilities to store equipment during a forensic investigation in accordance 593 with DHS MD 11042.1, “Safeguarding Sensitive but Unclassified Information”. 594

• Maintain the appropriate digital media analysis tools and equipment (i.e. spare hard drives 595 for replication) are maintained. 596

• Conduct personnel training and maintain certifications in digital media analysis processes 597 and the specific tools selected, to include use of distributed Enterprise digital media analysis 598 tools deployed to remote systems. 599

• Provides computer forensic support to high technology investigations in the form of evidence 600 seizure, computer forensic analysis, and data recovery. 601

• Perform reverse engineering of malicious code and identify signs of malicious code infection 602 on target systems. 603

• Maintain a malware analysis lab, which includes Virtual Machine (VM) sandboxing, 604 simulated Internet connectivity, multiple Antivirus vendor scanning capabilities, and other 605 methods to safely determine malware affects and indicators. 606

• Maintain effective policies for host-based anti-malware software, including antivirus, host 607 intrusion prevention, application containment, data loss prevention and mobile threat 608 detection, as well as log aggregation for these security tools. 609

• Continually evaluate both updates to existing security solutions, as well as new software that 610 can augment or replace existing products. 611

• Utilize threat logs from protected systems as well as external threat intelligence to develop 612 new signatures as threats are identified. 613

• The Contractor will provide updates and information to affected system personnel as needed 614 and/or requested during an investigation. 615

• Respond to email attacks by: 616 o Performing digital media analysis to identify and block malicious domains, sender 617 addresses, source IP address, and other pieces of metadata associated with e-mail (e.g. 618 header information, attachment attributes, etc.). 619

• Provide remedial recommendations and produce consistent comprehensive reports on 620 findings. 621

• Report results of all analyses to the Government Program Manager. 622

• Develop, maintain, and follow internal Standard Operating Procedures (SOPs) for computer 623 forensics collection and analysis, in accordance with DHS 4300A or other applicable policies 624 or requirements. 625

• Additional ad hoc activities may include: 626 o Advanced code analysis of detected malicious code. 627 o Offline analysis in an isolated lab environment. 628 o Advanced traffic analysis (at the packet level) and reconstruction of network traffic to 629 discover anomalies, trends, and patterns affecting DHS networks. 630 o Analysis and recommendation of hardware and/or software tools that will assist in traffic 631 analysis. 632 o Implementation, training, and SOP development and maintenance of implemented 633 solutions. 634 o Hard drive analysis of suspected systems impacted by malicious activity, to include 635 occasional hard drive imaging. 636 o In-depth Web log analysis to determine trend, patterns, and suspicious activity. 637 o Pattern analysis, trend analysis, behavior analysis and other specialized analysis. 638

7.2.3.4 Mobile Device Tools and Incident Response 639

The mobile device tools/incident response functional area shall monitor and perform incident 640 response on mobile devices across the ICE environment, approximately 53,000 endpoints. 641

• Perform tuning and optimization of the Mobile Threat Detection (MTD) System 642

• The contractor shall proactively hunt for mobile threats from internal and/or external 643 sources. 644

• The contractor shall develop, follow, and maintain mobile incident response SOPs 645 on the mobile devices when the device is compromised or attacked. 646

• The contractor shall take measures to protect the data on lost/stolen mobile devices by 647 initiating data wipe process on the devices. 648

• The contractor shall conduct forensic investigations on mobile devices for insight into 649 attack TTPs and improvement of monitoring capabilities and produce forensic reports 650 with recommendations. 651

• The contractor shall work with security tools and teams to ensure mobile devices 652 conform to the acceptable usage policies 653

• The contractor shall work with existing tools and teams to remove unwanted 654 applications from the mobile devices. 655

• The contractor shall adhere to and follow classified data spill protocol if the 656 compromised mobile devices are suspected to contain classified data. 657

• The contractor shall provide limited end users support in remediating issues with 658 security software on mobile devices. 659

• The contractor shall provide administration and management of security software(s) 660

• The contractor shall facilitate integration of mobile security and software(s) to 661 other systems. 662

• Address mobile security issues routed through the ICE ticketing system and/or 663 generate tickets through the ICE ticketing system as required. 664

7.2.4 Incident Response and Remediation 665

7.2.4.1 Incident Response 666

The incident response functional area will coordinate incident response, investigations, and 667 report and escalate incidents to the DHS SOC per DHS 4300A Attachment F policy and the DHS 668 CSP ESM requirements. They will work with the ICE Privacy Office to address suspected or 669 confirmed privacy incidents to ensure timely validation and reporting. The Incident Responders 670 will be able to: 671

• Take appropriate actions to contain a potential cyber incident, such as: 672

• Isolation of device(s), either by switchport disable or through IPSEC policy 673

• Remote mobile-phone wipe 674

• Custom e-mail filter rule to block messages with specific characteristics 675

• Custom EDR policy to prevent further compromise 676

• Create firewall “block” requests to prevent future traffic to malicious destinations 677

• Maintain “call list” to enable quick response to cyber-attacks, ensuring key personnel 678 respond in a timely manner 679

• Acquire & store data in a forensically sound manner (logical evidence files) on ICE SOC 680 forensic servers (to include any pulls of volatile memory) as required. 681

• Document & collect incident data within SEN investigation & DHS portal. Data will include 682 all relevant investigation findings, notes, analysis & recommendations. Data will be 683 available for future audit. 684

7.2.4.2 Remediating 685

The Contractor in the SOC/CSIRC West facility shall work with ICE Divisions and 686 other entities as identified by the Government Task Monitor. 687

• The Contractor shall oversee the resolution of security issues and report and brief out 688 how ICE implements its 3 primary methods of remediation: installation of a software 689 patch, changes of a configuration setting, and the removal of the affected ICE asset. 690

• The Contractor shall assist where required to provide a remediation plan that lists 691 opened security issues with their steps and projected timelines for remediation. 692 Remediation shall be tracked via the online portal mentioned in the previous section. 693

• The Contractor shall participate in engineering remediation solutions as required. 694

• The Contractor shall support the ISSO/System Owner in patching/remediation of all 695 security tools FISMA systems. These FISMA systems will contain ICE CDIB security 696 tools and be owned/maintained by CDIB personnel with compliance support from 697 other IAD personnel. Currently, there are two (2) main FISMA systems for CDIB, 698 however, the FISMA boundaries and tools within are subject to change and support 699 will be required regardless of the number of systems to maintain each system’s 700 Authorities to Operate (ATO). 701

7.3 Proactive Defense (Cyber Intelligence and Threat Emulation Teams) 702

7.3.1 Continuous Threat Exposure Management Program (C-TEMP) 703

ICE Continuous Threat Exposure Management Program (C-TEMP) gathers and establishes cyber 704 threat exposure requirements and priorities through the synthesis and curation of cyber threat 705 intelligence to address mission needs, technology risks and strategic direction.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .