Attachment 2 SOW 5.13.2020_0001.pdf

PDF 516 KB Posted

Attached to
Computer Security Monitoring, Incident Response, a Federal contract opportunity
Solicitation number
140A1620R0018
Issued by
Department of the Interior Bureau of Indian Affairs Central Office

About this file

This statement of work outlines computer security monitoring, incident response, and security engineering support services required by the Department of the Interior's Bureau of Indian Affairs. Key requirements include monitoring the agency's IT infrastructure using government-furnished security tools, conducting vulnerability analyses, responding to cybersecurity incidents, and providing security engineering support. The contractor must staff positions such as senior network security engineers, security engineers, security analysts, and security administrators. Services will be provided at locations in Reston, VA and Albuquerque, NM. The base period of performance is one year with four optional one-year extensions. The contractor must comply with all security screening and suitability requirements for contractor personnel and safeguard all government information, systems, and facilities.

View the file

Other files for this federal contract opportunity

Other files attached to Computer Security Monitoring, Incident Response, a, newest first.
File Type Posted
Attachment 2 SOW A0002_0002.pdf PDF
QA 5.13.2020_0001.pdf PDF
Appendix C-Baseline Compliance Contract Requirements_0001.pdf PDF
B09 SF30 140A1620R0018 A0001_0001.pdf PDF
Sol_140A1620R0018.pdf PDF
B08 Attachment 1 - Pricing Schedule.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sensitive But Unclassified—For Official Use Only

Indian Affairs (IA) Information Technology Division of Information Security (DIS)

Computer Security Monitoring, Incident

Response, and Security Engineering Support Statement of Work (SOW)

Document Created: 15 September 2014 Last Updated: 13 May 2020

Version: 2.2

Statement of Work Version 1.0

January 8, 2015

Prepared by DIS i

Revision History

Author Version Revision Date Revision Summary

Stephen M. Dean 1.0 15 September 2014 Document created Stephen M. Dean 1.0 17 October 2014 First revision

Stephen M. Dean 2.0 8 January 2015 Second revision

Stephen M. Dean 2.1 2 February 2015 Minor revision for number of personnel

Prepared by DIS ii

Table of Contents

SECTION 1: PURPOSE ....................................................... ERROR! BOOKMARK NOT DEFINED.

SECTION 2: SCOPE

SECTION 3: PLACES OF PERFORMANCE

SECTION 4: PERIOD OF PERFORMANCE

SECTION 5: DELIVERABLES AND DELIVERABLES SCHEDULE

5.1 DELIVERABLES

5.2 GOVERNMENT ACCEPTANCE PERIOD

5.3 ANTICIPATED LEVEL OF EFFORT

5.4 INSPECTION AND ACCEPTANCE CRITERIA

5.5 GENERAL ACCEPTANCE CRITERIA

SECTION 6: ADMINISTRATIVE CONSIDERATIONS

6.1 CORRESPONDENCE

6.2 ATTENDANCE AT MEETINGS

6.3 POINTS OF CONTACT

6.4 GOVERNMENT-FURNISHED FACILITIES

SECTION 7: DISCLOSURE OF INFORMATION

SECTION 8: INFORMATION NON-DISCLOSURE

SECTION 9: LIMITED USE OF DATA

SECTION 10: PERSONNEL PERFORMANCE/REPLACEMENT

SECTION 11: INVOICING

SECTION 12: CONTRACTOR INTERFACES

SECTION 13: SUITABILITY DETERMINATIONS

13.1 SECURITY SCREENING

13.2 OTHER SPECIFIC SECURITY REQUIREMENTS

13.3 OTHER SPECIAL REQUIREMENTS

13.4 REMOVAL OF CONTRACT EMPLOYEES

SECTION 14: LIABILITY

SECTION 15: DATA ENCRYPTION

SECTION 16: ASSURANCES

SECTION 17: QUALITY ASSURANCES

17.1 DELIVERABLE ACCEPTANCE

SECTION 18: USE OF GOVERNMENT COMPUTER SYSTEMS

APPENDIX A: NON DISCLOSURE AGREEMENT .................................................................. A-33

APPENDIX B: EVALUATION CRITERIA ................................................................................. B-34

Prepared by DIS iii

Table of Figures

Figure 1: Deliverables Figure 2: Anticipated Level of Effort

Prepared by DIS 1

Section 1: Purpose

Indian Affairs (IA) must sustain, document, and implement an information assurance/security program to provide adequate security for the information assets that support the operation of the agency. Required services include assistance in fulfilling obligations to comply with OMB Circular A-130, the Department of the Interior (DOI) IT Security Standards (as amended), the Federal Information Security Management Act (FISMA), and other appropriate laws, directives, policies, standards and guidelines.

The purpose of this statement of work (SOW) is to identify the efforts and expertise required to provide Computer Network Defense (CND) Monitoring, Cyber Incident Response Team (CIRT), and Cyber Security Systems Engineering and Integration (CSSE&I) support to approved projects to Indian Affairs (IA) Indian Affairs is defined as the Bureau of Indian Affairs (BIA), the Bureau of Indian Education (BIE) and the Office of the Assistant Security – Indian Affairs (AS-IA), hereafter referred to as Indian Affairs (IA). Whenever IA is used in this document it refers to the whole of BIA, BIE and AS-IA, otherwise the individual acronyms will be used.

The contractor shall: provide technical and management support to IA in planning, development and testing of technologies; provide technical analysis in support of development and test activities for new systems and emerging technologies; facilitate development of future requirements and architectures that enable transition of new systems and technologies into the operational baseline; and coordinate future technology development efforts with internal and external partners and operational users.

In accordance with Department of the Interior (DOI) policy, all bureau security programs shall have an Incident Response Capability and Information Security Engineering program that must be implemented in accordance with the following National Institute of Standards and Technology (NIST) Special Publications (SP) (Revisions reflected below or as amended) and NIST Federal Information Processing Standards (FIPS) as well as any other relevant directive or regulations (this is not a comprehensive list):

NIST SP 800-27 Rev. A, Engineering Principles for Information Technology Security (A Baseline for Achieving Security)

NIST SP 800-40, Version 2.0, Creating a Patch & Vulnerability Management Program NIST SP 800-53 Rev. 3, Recommended Security Controls for Federal Information Systems and

Organizations NIST SP 800-61 Rev. 1, Computer Security Incident Handling Guide NIST SP 800-83, Guide to Malware Incident Prevention and Handling NIST SP 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal

Information Systems: A Security Lifecycle Approach NIST SP 800-55 Revision 1, Performance Measurement Guide for Information Security NIST SP 800-56A, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete

Logarithm Cryptography NIST SP 800-63, Electronic Authentication Guideline NIST SP 800-64, Security Considerations in the System Development Life Cycle NIST SP 800-77, Guide to IPsec VPN NIST SP 800-83, Guide to Malware Incident Prevention and Handling NISP SP 800-88, Guidelines for Media Sanitization NIST SP 800-92, Guide to Computer Security Log Management

Prepared by DIS 2

NIST SP 800-97, Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11 NIST SP 800-111, Guide to Storage Encryption Technologies for End User Devices NIST SP 800-113, Guide to SSL VPNs NIST SP 800-114, User’s Guide to Securing External Devices for Telework and Remote Access NIST SP 800-115, Technical Guide to Information Security Testing and Remote Assessment NIST SP 800-118, Guide to Enterprise Password Management NISP SP 800-121, Guide to Bluetooth Security NISP SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information

(PII)

NISP SP 800-123, Guide to General Server Security NISP SP 800-124, Guidelines on Cell Phone and PDA Security FIPS 140-2, Security Requirements for Cryptographic Modules FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

The DOI policy requires all bureaus to:

1. Ensure the establishment of a formal incident response team,

2. Provide formally documented procedures, including an identified points-of-contact in the event of an incident ,

3. Ensure the reporting of incidents to appropriate authorities in a timely and consistent manner.

The Division of Information Security (DIS) reports to the Senior Advisor for Information Resources— Indian Affairs (SAIR-IA) located in Reston, VA. The SAIR is responsible for Information Technology (IT) for IA, The Division of Information Security is responsible for the Information Security and Information Assurance program for Indian Affairs (IA).

IA has established an IT Security Program for identifying and addressing risk, improving and institutionalizing security policy, process and practices within the business processes, practices, and operations of IA.

The IA IT Security Program is intended to support IA commitment to protecting the security of its systems and data to ensure their confidentiality, availability, and integrity by applying effective oversight of the processes governing the life cycle of applications and systems and implementing effective controls to adequately safeguard assets.

Section 2: Scope

The Period of Performance is 1 base year, and 4 option years. The scope of this SOW includes IA CSSE&I, CND and CIRT support for IA. The Contractor is responsible for the planning, acquisition, and management of personnel (as defined) to successfully conduct all activities and provide all deliverables defined in this document. The Contractor shall provide personnel with demonstrated knowledge, skills, and experience in the following functional areas:

• State-of-the-Art Systems Engineering and Integration methods, practices, and tools

• Multi-disciplinary knowledge in modern cyber defense techniques, including common CND technologies such as Security Information and Event Management (SIEM) systems, Host-and Network-based Intrusion Detection/Prevention Systems (HIDS/HIPS, NIDS/NIPS), malware analysis systems, endpoint assessment and other advanced technologies

• Program and Project Management

Prepared by DIS 3

• Configuration Management, Schedule Management, and Vulnerability Management

• Operational readiness, verification, and validation reviews

• Program protection and Information Assurance

• Document and briefing/graphics production

• Development and evaluation of communications systems and information technology strategic plans, roadmaps, architectures, and program/project plans

• Enterprise systems including information solutions engineering, multimedia, systems management, desktop information management, and computer network defense

The Contractor will work with IA staff and other IA contractors that are engaged in providing information technology security services. The IA Director of DIS, who is also the Bureau Chief Information Security Officer (BCISO) or appropriate designee, will provide technical oversight for the activities and tasking to be performed by the contractor and in establishing work priorities as set forth in this SOW and task orders. DIS staff and other IA management and staff (as designated) will work with the contractor’s on-site Lead to establish and clarify all security questions and technical issues.

The purpose of this contract is to provide computer security monitoring to rapidly detect incidents, conduct vulnerability analysis, identify weaknesses, and analyze logs, tracking of incidents and restoration of IT operations after an incident occurs. It also includes identification of metrics to establish baseline measurements and develop incident reporting mechanisms. It further includes security solution administration, engineering services and security architectural support as well as contract management duties.

Task 1: Computer Network Defense Monitoring, Cyber Incident Response Team, and Vulnerability Management Support

The Contractor shall provide IA with computer security monitoring to rapidly detect incidents, conduct vulnerability analysis, identify weaknesses, and analyze logs, tracking of incidents and restoration of IT operations after an incident occurs. It also includes identification of metrics to establish baseline measurements and develop incident reporting mechanisms as well as contract management duties related to these tasks.

Objective: The SAIR-IA requires security monitoring of the deployed sensor grid using Government furnished security tools. Monitoring is required Monday through Sunday 24 hours per day, including Federal Government Holidays. IA also requires incident detection and vulnerability management activities as set forth below and in the relevant task order document. Contractor shall provide appropriate contact information in the event that on-call assistance is required outside of normal operating hours. The BCISO will be contacted and in turn will make the determination as to the appropriate level of assistance required.

Activity 1a: Computer Network Defense Security Monitoring, Intrusion Detection, and Analysis

The contractor shall monitor all IA Infrastructure using Government furnished security tools.

Government furnished tools adhere to the approved hardware/software list in the Technical Reference Model (TRM). Any new tools are approved by the BCISO. Monitoring is limited to networks and subnets to which the contractor has access and tools to monitor.

Intrusion detection is the process of actively monitoring systems for evidence of an intrusion or misuse.

This is accomplished by collecting information from numerous sources and then analyzing the information for symptoms of a security compromise. Information is then used to alert management and other security experts to determine the relevance and severity of the incident.

Prepared by DIS 4

The Cyber Incident Response Team (CIRT) will use government furnished tools to include Intrusion Detection/Protection Systems to assist in accomplishing the following activities:

monitor and analyze user, system, and network access audit system configurations and vulnerabilities assess the integrity of system and data files recognize activity patterns that may indicate an incident analyze logs for abnormal use patterns operate system auditing

Key activities for this subtask will be included in the applicable task order.

Activity 1b: Cyber Security Incident Response

The Contractor must perform incident response, as defined by The Federal Information Security Management Act (FISMA) of 2002 which requires Federal agencies to establish incident response capabilities. Contractor will follow the Standard operating procedures (SOPs) as delineated by IA for specific technical processes, techniques, checklists, and forms to be used by the incident response team.

The response will include local area networks and one separate, wide area network. Education Native American Network (ENAN). Only government-furnished equipment (GFE) equipment shall be used to perform CIRT functions.

If the CIRT determines that a digital forensic analysis is needed for any event or incident, the CIRT shall inform the BCISO or designated appointee. The Contractor shall operate in accordance with all IA and DOI Security Standard Operating Procedures which requires compliance with all reporting and documentation requirements. If an incident or event is deemed to require travel to a site for additional security investigation and analysis, the BCISO and the Contracting Officer Representative COR may request the contractor to dispatch staff along with GFE within 3 business days to IA site locations. Travel is authorized by the COR in conjunction with the BCISO as long as sufficient funds are available.

Incident response management performed by CIRT will include the following activities:

1. Coordinate the notification and distribution of incidents should they occur. Use the escalation path as defined in SOPs.

2. Mitigate the risk of an incident by minimizing disruptions, and work with management if it appears that the mitigation will have an associated cost.

3. Assemble security staff to conduct threat analysis and resolve potential incident.

4. Monitor system logs for application to potential incident (consult SOPs for log management).

5. The contractor is responsible for accurately categorizing all security incidents per DOI and IA policy and procedure and shall report within the specific timeframes identified.

6. Define metrics and capture metrics which will be used for reporting capability.

7. Provide post-mortem for each incident. Any action to be taken, if requested by BCISO, will be based on severity and type of incident.

8. Provide “after action report” for any major incidents as defined by and requested by the BCISO. Any action to be taken if requested by BCISO will be based on severity and type of incident.

9. All security incidents shall be recorded or logged into an electronic format using government-furnished software. These logs will provide the information for reporting purposes.

10. Based on incident severity (consult SOPs), the contractor shall report all security incidents, (as directed by DIS) to the DOI Computer Incident Response Center (DOI-CIRC).

Prepared by DIS 5

Key activities for this subtask will be included in the applicable task order.

Activity 1c: Vulnerability Management (scanning, analysis, and notification) IA needs to gather comprehensive endpoint and network intelligence and apply advanced analytics to identify and prioritize the vulnerabilities that pose the most risk to critical systems. IA has a need for vulnerability management to cover its operating systems, applications and vulnerabilities found in its enterprise network. The contractor will work closely with DIS local and field staff [including Information System Security Officers (ISSOs)] in coordinating and conducting this activity. To support vulnerability management, the Contractor shall support the following vulnerability management activities, as requested by the BCISO or Government Lead Incident Responder:

1. Perform appropriate vulnerability scans of all components within the IA local area network (LAN) infrastructure; including computer equipment, computer peripheral devices and network devices using Government furnished scanning devices or software.

2. Scan results shall be analyzed, tracked and reported on using IA software and developed processes and procedures (see SOPs for incident handling and scanning). Follow-up, as requested, to ensure that the remediation has been completed within DIS approved timeframes (see SOPs). The findings will be tracked for additional analysis and reporting.

3. If remediation does not occur within specified time frames, advise government staff that remediation has not occurred so that any necessary escalation can occur.

4. Conduct monthly scans and ad hoc scans coming from the other IA security staff and field support staff in the field

5. Update the GFE vulnerability management tools with the latest signatures, provided by the vendor, to keep the GFE current. Work with Configuration Management in updating the documentation to keep the Government furnished tool configurations current.

Activity 1d: Working Technical Lead

DIS requires onsite contract management support Monday-Friday, excluding Federal Government holidays. The Contractor shall provide sufficient management to ensure that this task is performed efficiently, accurately, on time, and in compliance with the requirements of this document. Specifically, the Contractor shall designate a “Working Technical Lead” to oversee the tasking and supervise staff assigned to this task as well as be a working member of the contractor team. A “Working Technical Lead” is a person with strong technical skills and incident response experience who assumes oversight of and final responsibility for the quality of the technical work that the entire incident response team undertakes and can provide analyst and engineering support, as needed due to CIRT staff outages. The contract management and CIRT Technical Lead tasks will be performed by the contract Program Manager or designated appointee.

Prepared by DIS 6

Task 2: Cyber Security Architecture, Administration, CND Engineering and Security Engineering and Integration Support

The Contractor shall provide IA with development engineering and system integration support of CND tools and capabilities. The Contractor shall assist with the tracking, planning, development and implementation of new CND capabilities into all IA systems, enterprise networks, and sites. A "system of systems" CSSE&I approach shall be used to ensure that all developed capabilities are fully integrated into the operational baseline(s). The contractor shall continue to execute systems integration activities on legacy systems for new and revised capabilities. The Contractor shall work with the appropriate service management and operations management activities to provide Tier 3 level expertise and support to resolution of service incidents and the root cause of network problems related to IA-DIS components. The contractor shall provide IA with development engineering and system integration support to Division of Program Management and Business Services (DPMBS) for all approved projects to ensure security engineering best business practices are followed and security requirements are integrated into systems during the development lifecycle. The Contractor shall provide System Administration/Security Administration for Security tools deployed in support of the Information Assurance of IA systems and Computer Network Defense.

Objective: DIS requires security architecture and engineering services support Monday through Friday from 8:00AM – 5:00PM (Local Time), excluding Federal Government holidays. On call status for engineering services may be required on an occasional basis. DIS requires security systems administration support Monday through Friday from 8:00AM – 5:00PM (Local Time), excluding Federal Government Holidays. On call status for administration services may be required on an occasional basis.

Activity 2a: Security Architecture

The Contractor shall provide support for:

1. Development of FISMA compliant Security Configuration Baselines

2. Support resolution of Plan of Action and Milestones (POA&M)

3. Upgrades to IA infrastructure

4. Changes to IA network architecture

5. Change management activities with the development/review of implementation plans, back out plans, and security impact analyses

6. Security engineering services in support of new applications following SDLC

Key activities for this subtask will be included in the applicable task order.

Activity 2b: Security Infrastructure Administration, Maintenance and Evaluation

The Contractor shall be responsible for evaluating, configuring, implementing, administering, and maintaining IA Security tools as directed in the relevant task order with oversight provided, as required, by DIS managment.

Key activities for this subtask will be included in the applicable task order.

Activity 2c: Engineering Support Services to Include Upgrades or configuration changes to government furnished security equipment and software and CND Engineering Support

The contractor shall provide the expertise and services necessary to upgrade vendor software with patch updates, new releases, new signatures and rules as applicable and work with the appropriate

Prepared by DIS 7 groups/individuals to implement updates/upgrades to equipment. The contractor will work with the appropriate groups/individuals to ensure that the proper documentation and processes are completed and followed to adhere to the IA Change Management requirements.

The Contractor shall provide strategic multi-disciplinary CND expertise supporting the full range of CND engineering, including architecture development, systems engineering, integration, and implementation of new CND capabilities. The Contractor shall follow industry, systems, IT, and CND Engineering best practices to engineer and develop CND capabilities, and coordinate with DIS, Branch of Security Operations (DIS-BSO) to operationalize these capabilities, prior to transitioning them to IA DIS-BSO for sustained operations. The Contractor shall investigate the application of new CND technologies and tools to improve efficiencies and to provide advanced data correlation and information protection capabilities that will assist with the increasing needs of IA to interoperate with information dissemination and the transformation to service management in support of the DOI IT Transformations initiative. The Contractor shall provide a full set of engineering support services for approved projects to DPMBS to include the planning and management security requirements and integration into approved projects. The contractor will support security engineering of routers, firewalls, LAN, WAN, Virtual Private Networks (VPN), vulnerability scanning, data warehousing, data management, cloud computing and supporting processes, procedures, tasks, milestones, documentation, and other security artifacts.

The contractor shall provide Engineering Support Services to include providing subject matter expertise to collaborate with the Division of Information Operations (DIO) and other DOI/IA entities.

The contractor shall provide subject matter expertise in Security Engineering Services on an “as required” basis to collaborate/critique/review network architectures, security policy, update software to improve business processes or meet new or improved requirements for security services to entities within IA and

DOI.

Key activities for this subtask will be included in the applicable task order.

Activity 2d: Support to the DOI Advanced Security Operations Center (ASOC)

Based on availability, the contractor shall provide a security analyst staff member to support the DOI ASOC team to utilize ASOC tools and capabilities to monitor IA Equities. This collaboration places a CSIRT member expert to serve as team member in the ASOC.

Key activities for this subtask will be included in the applicable task order.

Activity 2e: Disaster Recovery Support

In the event of a disaster that would require IA to implement any or all parts of its COOP, the contractor shall provide support and assistance in the execution of the contingency and/or COOP security processes.

A contingency event may necessitate travel. Identified key contractor personnel may travel to an identified COOP site, stand-up the security function for the network, and perform regular day-to-day security functions within the confines of the COOP working environment.

Key activities for this subtask will be included in the applicable task order.

Activity 2f: CIRT Standard Operations/Procedures Manuals Updates

The Contractor shall update the current CIRT Operations/Procedures manuals and maintain the manuals for IA. The manual must document all standard procedures related to IA CIRT operations and shall include templates for all required checklists and reports. This shall be accomplished by completing an annual internal control review (ICR) for incident response-related controls (IAW NIST SP 800-53 as amended). All controls that are determined to be less than satisfied shall be remediated within 30 days.

Prepared by DIS 8

Key activities for this subtask will be included in the applicable task order.

Security Engineering Support Tasks Activity 2g: Continuous Monitoring Dashboard Creation and Maintenance

The Indian Affairs (IA) Splunk Continuous Monitoring System (Splunk CMS) will support ongoing and periodic Federal Information Security Management Act (FISMA) reporting activities as part of the NIST 800-37 Guide for Applying the Risk Management Framework to Federal Information Systems. The term Splunk CMS will be used herein to distinguish between the COTS product (Splunk) and the IA customized implementation (Splunk CMS). The intent of Splunk CMS is not to duplicate existing capabilities but rather to correlate data across these existing data sources. This correlation will permit non-technical visualization of security information in a format that supports executive decision making for ongoing FISMA reporting activities.

Contractor shall provide administrative service for support, maintenance and the development, configuration and deployment of enhancements to the Splunk CMS, to include requests from DIS and other internal IA stakeholders. The contractor shall recommend changes and/or further acquisitions by IA of modules or other needed hardware/software. The contractor shall identify and include all appropriate data sources (examples: firewall, IDS, OS and application event logs etc.) for processing and correlation of events.

Key activities for this subtask will be included in the applicable task order.

Activity 2h: Security Information and Event Manager (SIEM) Administration and Enhancements

Contractor shall provide administrative service for support, maintenance and the development, configuration and deployment of enhancements to this IA purchased Security Information and Event Manager (SIEM). The contractor shall identify and include all appropriate data sources (examples:

firewall, IDS, OS and application event logs etc.) into the SIEM for processing and correlation of events.

Key activities for this subtask will be included in the applicable task order.

Activity 2i: Contingency and COOP Planning

The Contractor shall complete the following activities in support of tasks identified in this contract:

1. Updating of contingency (short term) and COOP (long-term) plans for security-related functions, processes and procedures

2. Participate in review of IT security contingency capability to recover and reconstitute data

3. Provide improved security testing mechanisms to ensure the relevancy and effectiveness of IA contingency processes

4. Participate in “Table Top” assessment of IT contingency plans to verify effectiveness (to include fail-over to another designated COOP site). In the event of a contingency, the contractor shall provide support and assist in the execution of the contingency and/or COOP security process. A contingency event may necessitate travel. Identified key contractor personnel may travel to an identified COOP site, stand-up the security function for the network, and perform regular day-to-day security functions within the confines of the COOP working environment.

Key activities for this subtask will be included in the applicable task order.

Task 3: Contract Management

Activity 3a: Incident Training, Testing, and Exercises

Prepared by DIS 9

The Contractor shall provide initial and refresher incident response training to all their contractor employees and will conduct a test of the incident response capability no less than annually.

Key activities for this subtask will be included in the applicable task order.

Activity 3b: Reporting

The Contractor will provide the following reports to the applicable designee(s) as identified in the task order.

1. Daily Stand Up Planning and Execution

The Contractor shall prepare a daily status report and will participate in or lead (as required) a daily operational status discussion with other IA stakeholders.

Key activities for this subtask will be included in the applicable task order.

2. Weekly Incident Response and Sensor grid Status Report

A weekly status report and briefing is to be provided to the DIS director or designated appointee.

Key activities for this subtask will be included in the applicable task order.

3. Monthly Progress Report

A monthly status report is to be made available to the DIS director or designated appointee providing the metrics for the Incident Response and Service Center ticketing activity for the month, the high level details for the number of configuration changes for each government furnished security tool and whether the change was directly related to a known vulnerability or threat and status of all on-going IA projects involving Security Engineering support activity.

Key activities for this subtask will be included in the applicable task order.

4. Monthly Contract Management Reports:

• Contract and Subcontract Expenditures - The Contractor shall ensure that a Monthly Progress Report is submitted outlining the expenditures, billings, progress, status, and any problems/issues encountered in the performance of this task. If applicable, the Contractor shall prepare and deliver a Subcontract Expenditures Report that discloses actual subcontract expenditures.

• Quality Control Plan - The Contractor shall prepare and adhere to a Quality Control Plan (QCP). QCP will initially be submitted with the proposal and will be updated upon award. At a minimum, QCP must include a self-inspection plan, an internal staffing plan, and an outline of the procedures that the Contractor will use to maintain quality, timeliness, responsiveness, customer satisfaction, and any other requirements set forth in this solicitation.

Key activities for this subtask will be included in the applicable task order.

Activity 3c: Contract Personnel Requirements Increase (Optional)

The Contractor will be prepared to execute personnel requirements growth as needed with appropriate contract modification.

Section 3: Places of Performance

The Contractor shall perform primary activities in Reston, VA and Albuquerque, NM.

Prepared by DIS 10

Section 4: Period of Performance

The period of performance shall be for a base period of 12 months with 4 twelve month option periods.

Section 5: Deliverables and Deliverables Schedule

5.1 Deliverables

In fulfillment of this effort, the Contractor shall complete the following deliverables—Figure 1.

Contract Deliverable Line Items

Data Item Descriptions

Task # (location in the

SOW)

Format or Media

Delivery Date

Deliver to Whom

Non- Disclosure Agreement

Signed statements from each employee and subcontractor agreeing not to disclose information gained due to work assignments

Appendix A

MS Word or Adobe PDF in soft and hard copy

Due prior to start of work on contract

COR

Daily Stand Up Planning and Execution

The Contractor shall provide a daily Security operational status report for presentation to and discussion with other IA stakeholders.

3b Verbal Due daily As Designated

Weekly Status Report

A weekly Incident Response, Service Center ticketing and Sensor grid status report and briefing.

3b MS Word, Excel and/or PowerPoint

Due Weekly

BCISO

Designated Mgmt

Monthly Contract Management Report

A report outlining the expenditures, billings, progress, status, and any problems/issues encountered in the performance of this task.

3b MS Word in soft copy

1 week after close of month

COR

BCISO

Monthly Progress Report

A report outlining the monthly IR and Service Center activity and security tool configuration changes and issues and status of all on-going IA projects involving Security Engineering support activity.

3b MS Word, Excel and/or PowerPoint

1 week after close of month

BCISO

COTR

Quality Control Plan

QCP must include a self-inspection plan, an internal staffing plan, and an

3b MS Word 2 weeks after Task Award

COR

Prepared by DIS 11

Contract Deliverable Line Items

Data Item Descriptions

Task # (location in the

SOW)

Format or Media

Delivery Date

Deliver to Whom outline of the procedures that the Contractor will use to maintain quality, timeliness, responsiveness, customer satisfaction, and any other requirements set forth in this solicitation.

BCISO

Tech. Task

Leader

Configuration Setting Management

(CSM)

Upon request, assist with review and recommends for changes or exceptions to existing DOI and/or IA Security Baseline settings.

2a

MS Word In soft copy

When request by BCISO or Designee

BCISO

Tech. Task Leader

Metrics to support Continuous Monitoring

Identify Metrics which support the continuous monitoring activities.

These will be developed in collaboration with DIS director and other staff.

2a, 2b MS Word or Excel As required BCISO

Technical Analysis and Security Review of Security Tools

Review current configurations and provide assessment concerning the State of Security Tools.

Analyze and provide suggested industry standards to improve IA’s security posture.

2a, 2b, 2c, 2d and 2f

MS Word, Excel or

PowerPoint

When request by BCISO or Designee

BCISO

Tech. Task

Leader

Figure 1: Deliverables

Additional deliverables will be outlined in the specific task orders.

5.2 Government Acceptance Period

The COR or appropriate technical official will have five (5) workdays to review draft deliverables and make comments. The Contractor shall have two (2) workdays to make corrections. Upon receipt of the final deliverables, the COR or appropriate technical official will have two (2) workdays for final review prior to acceptance or providing documented reasons for non-acceptance.

The COR in consultation with the appropriate technical official will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted proposal. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor shall have five (5) workdays to correct the rejected deliverable and return it per delivery instructions.

Prepared by DIS 12

5.3 Anticipated Level of Effort

The following is the estimated annual level of effort.

Labor Category Estimated Hours 1 - Senior Network Security Engineer / Technical Lead (Reston)

1 - Security Engineer – Senior (Reston) 1880 4 - Security Engineer (1 – Reston/3 - Albuquerque)

8 - Security Analyst/Incident Response Analyst (3 – Reston/5 Albuquerque)

15,040

1 – Senior Security Administrator (Albuquerque)

1 - Security Administrator (Reston) 1880 Total Estimated Hours 30,080

Figure 2: Anticipated Level of Effort

5.3.1 Expected Qualifications

The contractor shall provide the optimum mix of personnel and technical expertise to perform the tasks specified in this SOW. The following minimum qualifications shall be considered for each labor category:

Security Analyst/Incident Response:

Requirements:

Five years of experience in a Windows and Unix/Linux environment with demonstrated substantial knowledge of the following:

o various Internet protocols (e.g., TCP/IP, DNS, BGP, SMTP, HTTP) o computer system and Internet security issues o various security technologies (e.g., encryption, firewalls, and anti-virus/anti-malware products) o security auditing practices o underlying software defects that routinely result in security vulnerabilities (e.g., input validation errors) o understanding of intruder techniques and software exploitation methods o system, database, and/or network administration o operational details of multiple operating systems o cryptographic principles and common cryptographic protocols o anti-virus/anti-malware alerting o network and vulnerability scanning technologies o incident response techniques and procedures o the collection of incident details and supporting information o isolation techniques for malicious activity

Prepared by DIS 13

In addition, the successful candidates will:

o have an interest in and have extensive knowledge of network and computer security issues o have the ability to analyze software to discover vulnerabilities, including the ability to read and comprehend logs (extracted from GFE) o be able to develop and explain technical decisions o be able to separate fact from opinion and speculation o have excellent work prioritization, planning, and organizational skills o interact effectively with vulnerability reporters, system and network administrators, vendors, experts, Internet users, sponsors, policy makers, news reporters, managers and staff (i.e., stakeholders in the vulnerability disclosure process) o be able to work with closely coordinated team during emergencies o have excellent analytical, reasoning, and creative problem solving skills o have excellent written, oral communication skills o recognize and deal appropriately with confidential and sensitive information o be able to work meticulously with careful attention to detail o be able to collaborate effectively and work closely within a coordinated team environment o be able to quickly learn new procedures, techniques, and approaches o maintain composure while dealing with difficult people o communicate and work effectively under normal and stressful situations o be motivated and able to meet inflexible deadlines o possess strong leadership and mentoring abilities o be motivated to tackle challenging problems

Security Engineer—Senior:

Requirements:

7+ years of broad work experience including administration, engineering and security 5+ years of experience in network and system design, access control and implementation Ability to work on multiple projects simultaneously and balance conflicting demands Strong sense of professionalism, integrity and ethics Ability to combine technical skills with an understanding of business needs to successfully protect assets Proven ability to communicate effectively, both verbally and in writing to technical and non-technical audiences CISSP, SANS GIAC, security+, MCSE, Linux certifications or equivalent certifications a plus Experience assessing and hardening security configurations for operating systems, applications and services In-Depth knowledge of TCP/IP (V4 and V6) addressing and standards including network design, firewall configuration, load balancing, remote access, strong authentication, vulnerability scanning, VPN and DMZ management

LAN and WAN network design, implementation, and configuration best practices

Prepared by DIS 14

High-availability and Continuity of Operations (COOP) Understanding of scripting languages and technologies such as shell scripting, Perl, JavaScript, VBScript or others Technical knowledge and experience with application security, content filtering, network protocols, access control, encryption, and 2 factor authentication technologies Understanding of common security protocols such as Kerberos, RADIUS, RSA, TACACS+, SSL, TLS, SSH, IPSec, S/MIME, PKI and SFTP Ability to perform ethical hacking, penetration testing, vulnerability assessments and web application security testing using various tools and provide a summary of issues and best practice resolutions Experience with (and strong understanding of) virtualization technologies and concepts, specific knowledge and extensive use of VMWare technologies including ESXi/VSphere and VCenter required Extensive knowledge in best-of-breeds commercial and free/open source network intrusion detection and prevention systems (NIDS/NIPS) (and similar network-based CND capabilities that support them) and host-based intrusion detection/prevention systems(HIDS/HIPS), including common use case scenarios, industry best practices, and deployment, integration, and troubleshooting in large enterprise IT environments. Experience should include specific knowledge and/or use of:

o Host-based Security Systems o Network packet capture and analysis appliances o Snort o Bro o Suricata o Argus o YARA o Yet Another Flowmeter (YAF)

Network Security Engineer—Senior:

Requirements

7+ years of broad work experience including administration, engineering and security 5+ years of experience in network and system design, access control and implementation Ability to work on multiple projects simultaneously and balance conflicting demands Strong sense of professionalism, integrity and ethics Ability to combine technical skills with an understanding of business needs to successfully protect assets Proven ability to communicate effectively, both verbally and in writing to technical and non-technical audiences CISSP, SANS GIAC, security+, MCSE or equivalent certifications a plus Experience assessing and hardening security configurations for operating systems, applications and services

Prepared by DIS 15

In-Depth knowledge of TCP/IP addressing and standards including network design, firewall configuration, load balancing, remote access, strong authentication, vulnerability scanning, VPN and DMZ management

Understanding of scripting languages and technologies such as shell scripting, Perl, JavaScript, VBScript or others

Technical knowledge and experience with application security, content filtering, network protocols, access control, encryption, and 2 factor authentication technologies

Understanding of common security protocols such as Kerberos, RADIUS, RSA, TACACS+, SSL, TLS, SSH, IPSec, S/MIME, PKI and SFTP

Ability to perform ethical hacking, penetration testing, vulnerability assessments and web application security testing using various tools and provide a summary of issues and best practice resolutions

Security Engineer:

Requirements

5+ years of broad work experience including administration, engineering and security 3+ years of experience in network and system design, access control and implementation Ability to work on multiple projects simultaneously and balance conflicting demands Strong sense of professionalism, integrity and ethics Ability to combine technical skills with an understanding of business needs to successfully protect assets Proven ability to communicate effectively, both verbally and in writing to technical and non-technical audiences CISSP, SANS GIAC, security+, MCSE, Linux certifications or equivalent certifications a plus Experience assessing and hardening security configurations for operating systems, applications and services In-Depth knowledge of TCP/IP addressing and standards including network design, firewall configuration, load balancing, remote access, strong authentication, vulnerability scanning, VPN and DMZ management

Understanding of scripting languages and technologies such as shell scripting, Perl, JavaScript, VBScript or others

Technical knowledge and experience with application security, content filtering, network protocols, access control, encryption, and 2 factor authentication technologies

Understanding of common security protocols such as Kerberos, RADIUS, RSA, TACACS+, SSL, TLS, SSH, IPSec, S/MIME, PKI and SFTP

Ability to perform ethical hacking, penetration testing, vulnerability assessments and web application security testing using various tools and provide a summary of issues and best practice resolutions

Security Analyst - Senior:

Requirements

7+ years of broad work experience including administration, engineering and security 5+ years of experience in network and system design, access control and implementation

Prepared by DIS 16

3+ years of experience supporting the administration of the NIST Risk Management Framework (SP 800-37 , as amended) and the planning and implementation of security controls IAW NIST SP 800-53 (as amended).

Ability to work on multiple projects simultaneously and balance conflicting demands Strong sense of professionalism, integrity and ethics Ability to combine technical skills with an understanding of business needs to successfully protect assets Proven ability to communicate effectively, both verbally and in writing to technical and non-technical audiences CISSP, SANS GIAC, CISM, CISA or equivalent certifications a plus Experience assessing and hardening security configurations for operating systems, applications and services In-Depth knowledge of TCP/IP addressing and standards including network design, firewall configuration, load balancing, remote access, strong authentication, vulnerability scanning, VPN and DMZ management

Understanding of scripting languages and technologies such as shell scripting, Perl, JavaScript, VBScript or others

Technical knowledge and experience with application security, content filtering, network protocols, access control, encryption, and 2 factor authentication technologies

Understanding of common security protocols such as Kerberos, RADIUS, RSA, TACACS+, SSL, TLS, SSH, IPSec, S/MIME, PKI and SFTP

In addition, the successful candidate will:

o be able to separate fact from opinion and speculation o have excellent work prioritization, planning, and organizational skills o interact effectively with vulnerability reporters, system and network administrators, vendors, experts, Internet users, sponsors, policy makers, managers and staff (i.e., stakeholders in the vulnerability disclosure process) o be able to work with closely coordinated team during emergencies o have excellent analytical, reasoning, and creative problem solving skills o have excellent written, oral communication skills o recognize and deal appropriately with confidential and sensitive information o be able to work meticulously with careful attention to detail o be able to collaborate effectively and work closely within a coordinated team environment o be able to quickly learn new procedures, techniques, and approaches o maintain composure while dealing with difficult people o communicate and work effectively under normal and stressful situations o be motivated and able to meet inflexible deadlines o possess strong leadership and mentoring abilities o be motivated to tackle challenging problems

Prepared by DIS 17

Senior Security Administrator:

Requirements:

7+ years of broad work experience including administration, engineering and security 5+ years of experience in security technology administration Ability to work on multiple projects simultaneously and balance conflicting demands Strong sense of professionalism, integrity and ethics Ability to combine technical skills with an understanding of business needs to successfully protect assets Proven ability to communicate effectively, both verbally and in writing to technical and non-technical audiences CISSP, SANS GIAC, security+, MCSE or equivalent certifications a plus Experience assessing and hardening security configurations for operating systems, applications and services Administration of Network Intrusion Detection and Prevention Systems (NIDS & NIPS) Administration of Host Intrusion Detection and Prevention Systems (HIDS & HIPS) Administration of Network Access Control (NAC) Systems such as ForeScout

CounterAct Administration of/and deployment of Security Information Event Management Systems (SIEM), such as Splunk IDS, IPS, SIEM content management, policy tuning and signature development Ad-hoc scripting supporting process automation and data analysis New system integration and coordination with engineering Resource utilization analysis and performance tuning of IDS & SIEM servers & applications

Experience with virtualization technologies Experience in the deployment, operation, maintenance, upgrading and troubleshooting/repair of cyber defense systems to include but not limited to: network components, servers, analyst workstations, CND associated hardware and software

Security Administrator:

Requirements:

5+ years of broad work experience including administration, engineering and security 3+ years of experience in security technology administration Ability to work on multiple projects simultaneously and balance conflicting demands Strong sense of professionalism, integrity and ethics Ability to combine technical skills with an understanding of business needs to successfully protect assets Proven ability to communicate effectively, both verbally and in writing to technical and non-technical audiences CISSP, SANS GIAC, security+, MCSE or equivalent certifications a plus

Prepared by DIS 18

Experience assessing and hardening security configurations for operating systems, applications and services

Administration of Network Intrusion Detection and Prevention Systems (NIDS & NIPS) Administration of Network Access Control (NAC) Systems such as ForeScout

CounterAct Administration of Host Intrusion Detection and Prevention Systems (HIDS & HIPS) Administration of/and deployment of Security Information Event Management System (SIEM), such as Splunk IDS, IPS, SIEM content management, policy tuning and signature development Ad-hoc scripting supporting process automation and data analysis New system integration and coordination…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .