Attachment 2 SOW A0002_0002.pdf
PDF 957 KB Posted
- Attached to
- Computer Security Monitoring, Incident Response, a Federal contract opportunity
- Solicitation number
- 140A1620R0018
About this file
This statement of work outlines computer security monitoring, incident response, and security engineering support services required by the Department of the Interior Bureau of Indian Affairs. The contractor shall provide cybersecurity monitoring to rapidly detect incidents, conduct vulnerability analysis, and restore IT operations after incidents. The contractor must also provide security engineering architecture support, administration of cybersecurity tools, and engineering services for approved projects. The performance period is one base year with four optional one-year periods of performance. The solicitation was issued on December 19, 2019 with proposals due on January 17, 2020 and award anticipated by February 28, 2020. The work will be performed primarily in Reston, VA and Albuquerque, NM.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Appendix C-Baseline Compliance Contract Requirements_0001.pdf | ||
| B09 SF30 140A1620R0018 A0001_0001.pdf | ||
| Attachment 2 SOW 5.13.2020_0001.pdf | ||
| QA 5.13.2020_0001.pdf | ||
| Sol_140A1620R0018.pdf | ||
| B08 Attachment 1 - Pricing Schedule.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Cybersecurity Monitoring, Incident Response, and Security Engineering Support
12/19/2019
U.S. Department of the Interior Indian Affairs
Division of Information Security
Bureau of Indian Affairs
Table of Contents
Background 4
1.0 Scope 4
2.0 Tasks 7
Functional Area 1: Computer Network Defense Monitoring, Cyber Incident Response Team, and
Vulnerability Management Support 7
Task 1: Computer Network Defense Security Monitoring, Intrusion Detection, and Analysis 7
Task 2: Cyber Security Incident Response 8
Task 3: Vulnerability Management (scanning, analysis, and notification) 9
Task 4: Working Technical Lead 9
Functional Area 2: Cybersecurity Architecture, Administration, CND Engineering and Security
Engineering and Integration Support 9
Task 1: Cybersecurity Architecture 10
Task 2: Cybersecurity Infrastructure Administration, Maintenance and Evaluation 10
Task 3: Engineering support services to include upgrades or configuration changes to government furnished security equipment and software and CND engineering support 10
Task 4: Support to the DOI Advanced Security Operations Center (ASOC) 11
Task 5: Disaster Recovery Support 11
Task 6: Standard Operating Procedures (SOP) Updates 11
Task 7: Continuous Monitoring Dashboard Creation and Maintenance 11
Task 8: Security Information and Event Manager (SIEM) Administration and Enhancements 12
Task 9: Contingency and COOP Planning 12
3.0 Government Furnished Property and Other Resources 12
4.0 Contractor Furnished Items and Responsibilities 12
5.0 Support 13
5.1 Quality of Support 13
5.2 Travel for Incident Response/Security Engineering Support 13
5.3 Customer Relations 14
6.0 Transition Plan 14
7.0 Security Requirements 15
7.1 General 15
7.2 Performance at Government Sites 15
7.3 Contractor Personnel Security and Suitability Requirements 15
7.4 Identification Badges 16
8.0 Contract Management 16
9.0 Work Products/Deliverable 17
10 Limitation of Future Contracting 26
11 Personal Conflicts of Interest and Procurement Integrity 27
12 Contractor Interfaces 27
13 Management Plan 27
14 Overtime and Additional Hours 28
15 Personnel Performance/Replacement 28
16 Quality Assurance 28
17 Use of Government Computer Systems 29
Appendix A – Non-Disclosure Agreement 30
Appendix B – Abbreviations and Acronyms 31
Appendix C – Baseline Compliance Contract Requirements 33
Table of Figures
Figure 1: Deliverables 17 Figure 2: Anticipated Level of Effort 18
Background
The Office of Information Management Technology (OIMT) provides information technology (IT) support and services to the Assistant Secretary for Indian Affairs (AS-IA), the Bureau of Indian Affairs
(BIA) and the Bureau of Indian Education (BIE). OIMT also provides limited technical support for other related, but independent entities. Additionally, OIMT manages the complex and varied IT infrastructure for the Department of the Interior (DOI) Indian Affairs (IA) workforce of over 15,000 government and tribal employees located in urban and remote rural areas throughout the country. OIMT is divided into three areas: Division of Information Security (DIS), Division of Program Management and Business
Services (DPMBS) and Division of Information Operations (DIO). For efficiency, DIO is divided into
Zones and has Field Support Managers who, along with respective staff are assigned to the Regional
Offices to support Agencies, Schools, and Law Enforcement facilities under the purview of the
Department of the Interior (DOI), Indian Affairs (IA). Within OIMT, there are two data centers:
Albuquerque Data Center (ADC) and Sioux Falls Data Center (SDC). The ADC is the primary site for
DOI/IA, while SDC serves as the secondary site.
The Indian Affairs Associate Chief Information Security Officer (ACISO) is also the DIS Division Chief.
The ACISO is located at 12220 Sunrise Valley Drive, Reston, Virginia. The ACISO reports to the
Associate Chief Information Officer (ACIO).
DIS provides implementation and ongoing management of Indian Affairs cybersecurity activities in support and service to the ACIO, Indian Affairs stakeholders and customers across the United States. DIS is responsible for providing cybersecurity guidance that Indian Affairs can leverage to ensure that management, operational, and technical security controls are properly implemented and operating as intended. Cybersecurity activities must comply with federal mandates, such as the Federal Information
Security Modernization Act (FISMA), the Privacy Act of 1974, Office of Management and Budget
(OMB) memoranda and circulars, National Institute of Standards and Technology (NIST) guidance, and
Departmental Policy.
DIS is primarily located in two locations; Reston, VA and Albuquerque, NM. The majority of the work performed will occur in support of the OIMT, at both the Reston and Albuquerque locations; however, some work will be performed in various regions throughout the United States.
IA has established a cybersecurity program for identifying and addressing risk, improving, and institutionalizing security policy, process and practices within the business processes, practices, and operations of IA.
The IA cybersecurity program is intended to support IA commitment to protecting the security of its systems and data to ensure their confidentiality, availability, and integrity by applying effective oversight of the processes governing the life cycle of applications and systems and implementing effective controls to adequately safeguard assets.
1.0 Scope
Scope - DIS has a need to identify the efforts and expertise required to provide Computer Network
Defense (CND) Monitoring, Cyber Incident Response Team (CIRT), and Cyber Security Systems
Engineering and Integration (CSSE&I) support to approve projects to Indian Affairs. The contractor is to provide cybersecurity monitoring to rapidly detect incidents, conduct vulnerability analysis, identify weaknesses, analyze logs, track incidents, generate after action reports (AAR) when directed, and restore
IT operations after an incident. It also includes identification of metrics to establish baseline measurements and develop incident reporting mechanisms. It further includes security solution administration, engineering services and security architectural support as well as contract management duties.
The contractor shall provide technical and management support to IA in planning, development, and testing of technologies. The contractor shall provide technical analysis in support of development and test activities for new systems and emerging technologies. The contractor shall facilitate development of future requirements and architectures that enable transition of new systems and technologies into the operational baseline. The contractor shall coordinate future technology development efforts with internal and external partners and operational users.
The Contractor is responsible for the planning, acquisition, and management of the level of effort to successfully conduct all activities and provide all deliverables defined in this document. The Contractor shall provide the level of effort that has knowledge, skills, and experience in the following areas:
● State-of-the-Art Systems Engineering and Integration methods, practices, and tools
● Multi-disciplinary knowledge in modern cyber defense techniques, including common CND technologies such as Security Information and Event Management (SIEM) systems, Host- and
Network-based Intrusion Detection/Prevention Systems (HIDS/HIPS, NIDS/NIPS), malware analysis systems, endpoint assessment and other advanced technologies
● Program and Project Management
● Configuration Management, Schedule Management, and Vulnerability Management
● Operational readiness, verification, and validation reviews
● Program protection and cybersecurity
● Document and briefing/graphics production
● Development and evaluation of communications systems and IT strategic plans, roadmaps, architectures, and program/project plans
● Enterprise systems including information solutions engineering, multimedia, systems management, desktop information management
The Contractor will work with IA staff and other IA contractors that are engaged in providing cybersecurity services. The IA DIS Division Chief, who is also the IA ACISO or appropriate designee, will provide technical oversight for the activities and tasking to be performed by the contractor and in establishing work priorities as set forth in this SOW and task orders. DIS staff and other IA management and staff (as designated) will work with the contractor’s on-site Lead to establish and clarify all security questions and technical issues.
Security Compliance - In accordance with Department of the Interior (DOI) policy, all bureau security programs shall have an Incident Response Capability and Information Security Engineering program that must be implemented in accordance with the following National Institute of Standards and Technology
(NIST) Special Publications (SP) and NIST Federal Information Processing Standards (FIPS) as well as any other relevant directive or regulations. Use current revisions and/or amendments for all guidance, and the list is not a comprehensive list:
• NIST SP 800-27, Engineering Principles for Information Technology Security (A Baseline for
Achieving Security)
• NIST SP 800-40, Creating a Patch & Vulnerability Management Program
• NIST SP 800-53, Recommended Security Controls for Federal Information Systems and
Organizations
• NIST SP 800-61, Computer Security Incident Handling Guide
• NIST SP 800-83, Guide to Malware Incident Prevention and Handling
• NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information
Systems: A Security Lifecycle Approach
• NIST SP 800-55, Performance Measurement Guide for Information Security
• NIST SP 800-56A, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete
Logarithm Cryptography
• NIST SP 800-63, Electronic Authentication Guideline
• NIST SP 800-64, Security Considerations in the System Development Life Cycle
• NIST SP 800-77, Guide to IPsec VPN
• NIST SP 800-83, Guide to Malware Incident Prevention and Handling
• NIST SP 800-88, Guidelines for Media Sanitization
• NIST SP 800-92, Guide to Computer Security Log Management
• NIST SP 800-97, Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11
• NIST SP 800-111, Guide to Storage Encryption Technologies for End User Devices
• NIST SP 800-113, Guide to SSL VPNs
• NIST SP 800-114, User’s Guide to Securing External Devices for Telework and Remote Access
• NIST SP 800-115, Technical Guide to Information Security Testing and Remote Assessment
• NIST SP 800-118, Guide to Enterprise Password Management
• NIST SP 800-121, Guide to Bluetooth Security
• NIST SP 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information
(PII)
• NIST SP 800-123, Guide to General Server Security
• NIST SP 800-124, Guidelines on Cell Phone and PDA Security
• FIPS 140-2, Security Requirements for Cryptographic Modules
• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
The DOI policy requires all bureaus to:
1. Ensure the establishment of a formal incident response team,
2. Provide formally documented procedures, including an identified points of contact in the event of an incident, and
3. Ensure the reporting of incidents to appropriate authorities in a timely and consistent manner.
Federal Task Lead - The Federal Task Lead for each Task area defined below works with the COR and will serve as the day to day decision-maker, technical lead and Subject Matter Expert for the Government in the respective technical fields. The Contractor assigned will receive work assignments from the
Federal Task Lead, and will provide the Federal Task Lead with recommendations regarding work assignments.
Contracting Officer Representative (COR) - The COR is the individual within the Program
Management function who has overall responsibility for this effort.
The COR supports the CO during administration of this effort by
• Making final decisions regarding any recommended rejection of deliverables
• Providing clarification relative to overall contractual matters
• Providing advice and guidance to the Contractor in the preparation of deliverables and services
• Providing acceptance of deliverable products to assure compliance with requirements
• Monitor the Contractor’s technical progress, including surveillance and assessment of performance, and recommend to the CO, any changes in the requirement;
• Assist the Contractor in the resolution of technical problems encountered during performance;
and
• Perform inspection and acceptance or recommendation for rejection of Contractor deliverables and identify deficiencies in delivered items.
The COR and Federal Task lead do not have the authority to and may not issue any technical direction which:
• Constitutes an assignment of work outside the general scope of this effort
• Constitutes a change as defined in the “Changes” clause
• In any way causes an increase or decrease in cost or the time required for performance
• Changes any of the terms, conditions, or other requirements of this effort
• Suspends or terminates any portion of this effort
2.0 Tasks
Functional Area 1: Computer Network Defense Monitoring, Cyber Incident Response Team, and
Vulnerability Management Support
The Contractor shall provide IA with cyber security monitoring to rapidly detect incidents, conduct vulnerability analysis, identify weaknesses, analyze logs, track incidents, generate after action reports when directed, and restore IT operations after incidents. It also includes identification of metrics to establish baseline measurements and develop incident reporting mechanisms as well as contract management duties related to these tasks.
Objective: OIMT requires security monitoring of the deployed sensor grid using Government furnished security tools. Automated monitoring is required 24x7. Manned incident response (IR) analyst support is required on Federal business days (Monday through Friday, excluding Federal holidays) from 5:00AM –
6:00PM (MT). IA also requires incident detection and vulnerability management activities as set forth below and in the relevant task order document. Contractor shall provide appropriate contact information in the event that on-call assistance is required outside of normal operating hours. The identified IA federal lead(s) will be contacted and in turn will make the determination as to the appropriate level of assistance required. Situational telework is authorized per OIMT Telework Procedure and must be approved by the COR with consensus of the Federal Lead.
Task 1: Computer Network Defense Security Monitoring, Intrusion Detection, and Analysis
The contractor shall monitor all IA Infrastructure using Government furnished security tools.
Government furnished tools adhere to the approved hardware/software list in the Technical Reference
Model (TRM). Any new tools are approved by the IA Change Advisory Board (CAB). Monitoring is limited to networks and subnets to which the contractor has access and tools to monitor. Intrusion detection is the process of actively monitoring systems for evidence of an intrusion or misuse. This is accomplished by collecting information from numerous sources and then analyzing the information for symptoms of a security compromise. Information is then used to alert management and other security experts to determine the relevance and severity of the incident.
The Cyber Incident Response Team (CIRT) will use government furnished tools to include Intrusion
Detection/Protection Systems to assist in accomplishing the following activities:
⮚ monitor and analyze user, system, and network access
⮚ audit system configurations and vulnerabilities
⮚ assess the integrity of system and data files
⮚ recognize activity patterns that may indicate an incident
⮚ analyze logs for abnormal use patterns
⮚ operate auditing systems
Task 2: Cyber Security Incident Response
The Contractor must perform incident response, as defined by The Federal Information Security
Modernization Act (FISMA) which requires Federal agencies to establish incident response capabilities.
Contractor will follow the Standard operating procedures (SOPs) as delineated by IA for specific technical processes, techniques, checklists, and forms to be used by the incident response team. Only government-furnished equipment (GFE) shall be used to perform CIRT functions.
If the CIRT determines that a digital forensic analysis is needed for any event or incident, the CIRT shall inform the ACISO or designated appointee. The Contractor shall operate in accordance with all IA and
DOI Security Standard Operating Procedures which requires compliance with all reporting and documentation requirements. If an incident or event is deemed to require travel to a site for additional security investigation and analysis, the ACISO and the COR may request the contractor to dispatch staff along with GFE within 3 business days to IA site locations. Travel is authorized by the COR in conjunction with the ACISO as long as sufficient funds are available.
Incident response management performed by CIRT will include the following activities:
1. Coordinate the notification and distribution of incidents should they occur. Use the escalation path as defined in SOPs.
2. Mitigate the risk of an incident by minimizing disruptions, and work with management if it appears that the mitigation will have an associated cost.
3. Assemble security staff to conduct threat analysis and resolve potential incident.
4. Monitor system logs for potential incidents.
5. The contractor is responsible for accurately categorizing all security incidents per DOI and IA policy and procedure and shall report within the specific timeframes identified.
6. Define metrics and capture metrics which will be used for reporting capability.
7. Provide post-mortem for each incident. Any action to be taken, if requested by ACISO, will be based on severity and type of incident.
8. Provide after action report (AAR) for major incidents as defined by and requested by the ACISO.
Any action to be taken if requested by ACISO will be based on severity and type of incident.
9. All security incidents shall be recorded or logged into an electronic format using government-furnished software. These logs will provide the information for reporting purposes.
10. Based on incident severity, the contractor shall report all required security incidents, (as directed by
DIS) to the DOI Computer Incident Response Center (DOI-CIRC).
Task 3: Vulnerability Management (scanning, analysis, and notification)
IA needs to gather comprehensive endpoint and network intelligence and apply advanced analytics to identify and prioritize the vulnerabilities that pose the most risk to critical systems. IA has a need for vulnerability management to secure its operating systems, applications and vulnerabilities found in its enterprise network. The contractor will work closely with DIS federal staff in coordinating and conducting this activity. To support vulnerability management, the Contractor shall support the following vulnerability management activities, as requested by the ACISO or designated federal lead:
1. Perform appropriate vulnerability scans of all components within the IA infrastructure; including computer equipment, computer peripheral devices and network devices using government furnished scanning devices or software.
2. Scan results shall be analyzed, tracked and reported on using IA software and developed processes and procedures. Follow-up, as requested, to ensure that the remediation has been completed within DIS approved timeframes. The findings will be tracked for additional analysis and reporting.
3. If remediation does not occur within specified time frames, advise government staff that remediation has not occurred so that any necessary escalation can occur.
4. Conduct scans requested from the other IA staff and approved by DIS federal lead.
5. Update the GFE vulnerability management tools with the latest updates, provided by the vendor, to keep the GFE current. Work with Configuration Management in updating the documentation to keep the Government furnished tool configurations current.
Task 4: Working Technical Lead
DIS requires onsite contract management support Monday-Friday, excluding Federal Government holidays. The Contractor shall provide sufficient management to ensure that this task is performed efficiently, accurately, on time, and in compliance with the requirements of this document. Specifically, the contractor shall designate a “Working Technical Lead” to oversee the tasking and supervise staff assigned to this task as well as be a working member of the contractor team. A “Working Technical
Lead” is a person with strong technical skills and incident response experience who assumes oversight of and final responsibility for the quality of the technical work that the entire incident response team undertakes and can provide analyst and engineering support, as needed due to CIRT staff outages. The contract management and CIRT Technical Lead tasks will be performed by the contract Program
Manager or designated appointee. Situational telework is authorized per OIMT Telework Procedure and must be approved by the COR with consensus of the Federal Lead.
Functional Area 2: Cybersecurity Architecture, Administration, CND Engineering and Security
Engineering and Integration Support
The Contractor shall provide IA with development engineering and system integration support of CND tools and capabilities. The Contractor shall assist with the tracking, planning, development and implementation of new CND capabilities into all IA systems, enterprise networks, and sites. A "system of systems" CSSE&I approach shall be used to ensure that all developed capabilities are fully integrated into the operational baseline(s). The contractor shall continue to execute systems integration activities on legacy systems for new and revised capabilities. The Contractor shall work with the appropriate service management and operations management activities to provide Tier 3 level expertise and support to resolution of service incidents and the root cause of network problems related to IA-DIS components. The contractor shall provide IA with development engineering and system integration support for all approved projects to ensure security engineering best practices are followed and cybersecurity requirements are integrated into systems during the development lifecycle. The contractor shall provide System
Administration/Security Administration for OIMT cybersecurity tools, such as intrusion detection systems (IDS) and intrusion prevention systems (IPS).
Objective: DIS requires security architecture and engineering services support Monday through Friday from 6:00AM – 5:00PM (MT), excluding Federal Government holidays. The intent of these duty hours is to provide normal duty hour coverage for both Reston, VA, and Albuquerque, NM, duty locations. On call status for engineering services may be required on an occasional basis. DIS requires security systems administration support Monday through Friday from 6:00AM – 5:00PM (MT), excluding Federal
Government Holidays. On call status for administration services may be required on an occasional basis.
Situational telework is authorized per OIMT Telework Procedure and must be approved by the COR with consensus of the Federal Lead.
Task 1: Cybersecurity Architecture
1. The Contractor shall provide support for: Development of FISMA compliant cybersecurity configuration baselines
2. Support resolution of Plan of Action and Milestones (POA&M)
3. Upgrades to IA infrastructure
4. Changes to IA network architecture
5. Change management (CM) activities with the development/review of implementation plans, back out plans, and security impact analyses (SIA)
6. Cybersecurity engineering services in support of new applications following SDLC
Task 2: Cybersecurity Infrastructure Administration, Maintenance and Evaluation
The Contractor shall be responsible for evaluating, configuring, implementing, administering, and maintaining IA Cybersecurity tools as directed in the relevant task order with oversight provided, as required, by designated DIS federal staff.
Task 3: Engineering support services to include upgrades or configuration changes to government furnished security equipment and software and CND engineering support
The contractor shall provide the expertise and services necessary to upgrade vendor software with patch updates, new releases, new signatures and rules as applicable and work with the appropriate groups/individuals to implement updates/upgrades to equipment. The contractor will work with the appropriate groups/individuals to ensure that the proper documentation and processes are completed and followed to adhere to the IA Change Management requirements.
The Contractor shall provide strategic multi-disciplinary CND expertise supporting the full range of CND engineering, including architecture development, systems engineering, integration, and implementation of new CND capabilities. The Contractor shall follow industry, systems, IT, and CND Engineering best practices to engineer and develop CND capabilities, coordinate with designated DIS federal lead, and follow CM procedures to operationalize these capabilities prior to transitioning them to IA DIS for sustained operations. The Contractor shall investigate the application of new CND technologies and tools to improve efficiencies and to provide advanced data correlation and information protection capabilities.
The Contractor shall provide a full set of engineering support services for approved projects. The contractor will support cybersecurity engineering of routers, firewalls, LAN, WAN, Virtual Private
Networks (VPN), vulnerability scanning, data warehousing, data management, cloud computing and supporting processes, procedures, tasks, milestones, documentation, all networked hosts (servers, workstations, printers, etc.) and their associated Operating Systems, and other cybersecurity artifacts.
The contractor shall provide Engineering Support Services to include providing subject matter expertise to collaborate with the Division of Information Operations (DIO) and other IA entities.
The contractor shall provide subject matter expertise in Security Engineering Services on an “as required” basis to collaborate/critique/review network architectures, security policy, update software to improve business processes or meet new or improved requirements for security services to entities within IA and
DOI.
Task 4: Support to the DOI Advanced Security Operations Center (ASOC)
Based on availability and DOI approval, the contractor shall utilize DOI ASOC tools and capabilities to monitor IA assets, complying with all ASOC policies and guidance.
Task 5: Disaster Recovery Support
In the event of a disaster that would require IA to implement any or all parts of its COOP, the contractor shall provide support and assistance in the execution of the contingency and/or COOP security processes.
Refer to Contingency/COOP section below.
Task 6: Standard Operating Procedures (SOP) Updates
The Contractor shall update the current SOPs and maintain for IA. The SOPs must document all standard procedures related to comprehensive IA cybersecurity operations and shall include templates for all required checklists and reports. This shall be accomplished by completing an annual internal control review (ICR) for incident response-related controls (IAW NIST SP 800-53). All controls that are determined to be less than satisfactory shall be updated within 30 days.
Task 7: Continuous Monitoring Dashboard Creation and Maintenance
The Indian Affairs (IA) Splunk Continuous Monitoring System (IA-CMS) will support ongoing and periodic Federal Information Security Modernization Act (FISMA) reporting activities as part of the
NIST 800-37 Guide for Applying the Risk Management Framework to Federal Information Systems. The term IA-CMS will be used herein to distinguish between the COTS product (Splunk) and the IA customized implementation (IA-CMS). The intent of IA-CMS is not to duplicate existing capabilities but rather to correlate data across these existing data sources. This correlation will permit non-technical visualization of security information in a format that supports executive decision making for ongoing
FISMA reporting activities.
Contractor shall provide administrative service for support; maintenance; and the development, configuration and deployment of enhancements to the IA-CMS, to include requests from DIS and other internal IA stakeholders. The contractor shall recommend changes and/or further acquisitions by IA of modules or other needed hardware/software. The contractor shall identify and include all appropriate data sources (examples: firewall, IDS, OS and application event logs etc.) for processing and correlation of events.
Task 8: Security Information and Event Manager (SIEM) Administration and Enhancements
Contractor shall provide administrative services for support, maintenance and the development, configuration and deployment of enhancements to government furnished SIEM. The contractor shall identify and include all appropriate data sources (examples: firewall, IDS, OS and application event logs etc.) into the SIEM for processing and correlation of events.
Task 9: Contingency and COOP Planning
The Contractor shall complete the following activities in support of tasks identified in this contract:
1. Updating of contingency (short term) and COOP (long-term) plans for security-related functions, processes and procedures
2. Participate in review of IT security contingency capability to recover and reconstitute data
3. Provide improved security testing mechanisms to ensure the relevancy and effectiveness of IA contingency processes
4. Participate in “Table Top” assessment or other testing of IT contingency plans to verify effectiveness, to include fail-over to another designated COOP site. In the event of a contingency, the contractor shall provide support and assist in the execution of the contingency and/or COOP cybersecurity process. A contingency event may necessitate travel and/or extended hours. Identified key contractor personnel may travel to an identified COOP site, stand-up the cybersecurity function for the enterprise, and perform regular day-to-day cybersecurity functions within the confines of the COOP working environment.
3.0 Government Furnished Property and Other Resources
For work performed in the Government’s facilities, the Government shall provide the Contractor with
Government workspace, IT equipment, software, network access, and email.
Contractor employees shall be directly responsible for the care, use, safeguarding, and accounting for the
Government property issued to him/her. The equipment issued shall be applicable to DOI/IA policies and used only for authorized government purposes and not be used for personal use.
At no time shall this property be used for personal use, except for phone services in case of emergencies to call home, daycare, hospital, etc.
4.0 Contractor Furnished Items and Responsibilities
The Contractor shall provide all personnel, equipment, materials, supervision and other items and services necessary to perform the acquisition support services called for in this requirement. It is the expectation of DOI/IA that the Contractor provide personnel with requisite skills and proven talent.
Contractor personnel under this contract shall not be: (1) Placed in a position where they are under the supervision or evaluation of a Government employee; or (2) Placed in a position of command, supervision, administration or control over Government personnel, or personnel of other contractors.
Given the nature of the contract requirements and the working environment, it may be necessary for
Government and Contractor personnel to work as a team to accomplish work objectives, share knowledge, and work in a mutually supportive role. This should be accomplished while preserving the non-personal services nature of the contract. The operational need to work in concert should be accomplished in a manner consistent with preserving the management responsibilities of the contractor.
Work direction means a communication to Contractor personnel that directs or approves approaches, documents, presentations, or refinements to work; fills in details or otherwise completes the general description of work or documentation items; shifts emphasis among work areas or tasks; or furnishes similar instructions to Contractor personnel. Work direction includes requiring analyses and development of other products within the scope of work for the contract.
The Contractor is at all times responsible for the quality of contractor personnel work. It is the direct responsibility of the Contractor to perform all tasks normally associated with an employer-employee relationship, e.g., completing time cards, resolving quality of work issues, ensuring high motivation and morale, and resolving Government-identified contractor performance concerns. To ensure effective and efficient services, the Contractor supervisory personnel need to establish and maintain work procedures that facilitate close and continuous coordination with agency Contracting Officers, Contracting Officer
Representatives (CORs), and other program management personnel. In addition, DOI/IA frequently responds to politically sensitive, high level security support requirements with extremely short suspense actions. To function effectively and efficiently as a team member in this environment, the Contractor must ensure personnel provided possess a high degree of subject matter knowledge, skills and abilities to perform the tasks relating to the objective. The Contractor supervision of Contractor personnel must also reflect the need to sustain a high-performing, highly motivated and responsive team.
5.0 Support
5.1 Quality of Support
The Contractor shall ensure that all Contractor personnel are adequately trained, possess the requisite experience, and are otherwise fully qualified to provide the high level of support and delivery of IT services required by agency prior to being assigned to this contract. The contractor shall maintain the training levels of the contract staff throughout the performance of the contract and training will be commensurate with the technology used by DIS and the technology changes implemented by Indian
Affairs appropriate for the labor category. That includes all costs associated with maintaining appropriate training levels to include class/coursework fees, travel to training and maintenance of certifications. The contractor shall, at their cost, send contractors to technical conference, as directed by the ACISO.
5.2 Travel for Incident Response/Security Engineering Support
The Contractor may be required to travel to regional areas around the country to perform incident response and security engineering. All travel must receive prior approval from the COR or CO and follow all Federal Travel Regulations. An estimate of the costs for the trip, dates of travel and location of travel must be provided to the COR with a request for authorization of travel. All information derived from these business travel shall be used to facilitate the DOI/IA mission. In no case, shall the contractor use this information to bid on new contracts in direct violation of FAR Part 9.
5.3 Customer Relations
The Contractor shall provide customer relation services to ensure high customer satisfaction. The
Contractor shall provide customers with the ability to voice feedback through a Customer Satisfaction
Survey. Unresolved complaints shall be forwarded to the Federal Task Lead for resolution. Unless the complaint is a Performance Issue; the Federal Task Lead will escalate the complaint to the COR.
6.0 Transition Plan
Sixty days before the end of the contract, the Contractor shall provide a detailed and comprehensive plan for transitioning the work and the workforce in an effective and cost efficient manner. The Contractor shall ensure there will be no service degradation during the transition. The plan must describe the
Contractor management approach to all transition activities and discuss how continuity of operations will be maintained throughout the transition period.
In addition during the Contract, when a position is vacated, Contractor will provide the Federal Task Lead a closeout action plan to document and follow up with customers, federal supervisor(s) any commitment assignment(s) that are incomplete, currently being worked on or awaiting other resources to complete ticket closeout for customer satisfaction.
The Contractor shall plan for no more than a sixty (60) day transition period to the effective end date of the contract.
The Contractor shall include the following activities among the transition activities discussed in the plan, and a strategy for:
1. Notice to staff about status of contract and end date of employment with current company.
2. Notification to Contractor's subcontracts and other agreements and commitments.
3. Inventorying and transferring Government Property.
4. Establishing a forum for contract staff to address, but not limited to: employee benefits, employee concerns, and applicable collective bargaining agreements.
5. Avoiding disruption of service during transition.
6. Final report of deliverables currently being worked to be delivered to the COR and CO no less than 14 calendar days before the contract end date.
7. An impact analysis of work that will not be finished by end of contract date. This is to be delivered to the COR and CO no less than 14 calendar days before the contract end date.
8. The Transition Plan should also detail the Contractor’s involvement in knowledge transfer to sustain government operations, not only as the incoming contractor, but also as the outgoing contractor (exit strategy) in the event of future contract solicitation activities.
7.0 Security Requirements
7.1 General
The Office of Information Management Technology is subject to numerous requirements stemming from a variety of Laws, rules, regulations, directives, and standards at ensuring the protection of sensitive agency information and information systems. To ensure compliance with Security provisions, Appendix
C: Baseline Compliance Contract Requirements is provided.
The Office of Information Management Technology determined that performance under this contract requires a suitability clearance. If suitability clearance action reveals derogatory information, the individual may be unacceptable for work under the contract. The Government reserves the right to determine if such personnel shall continue work on the contract. The Contractor shall remove the individual(s) immediately upon official notification by the Government and identify a qualified replacement within 10 days (unless otherwise authorized by COR or CO). The information collected during this effort is considered unclassified, sensitive; therefore, Level 6C – High Risk Public Trust, is the sensitivity level. Background Investigations are required for Level 6C positions. Detailed compliance information is provided in Appendix C: Baseline Compliance Contract Requirements.
7.2 Performance at Government Sites
As the effort required by this contract is to be performed at specified Government facilities, the
Contractor shall abide by agency guidance and publications, “IT Systems Security,” regarding provisions for authorized entrance and facilities. The Contractor shall ensure compliance with Federal, Department of the Interior, Office of Information Management Technology, Security, Regulations and Policies.
Detailed compliance information is provided in Appendix C: Baseline Compliance Contract
Requirements.
7.3 Contractor Personnel Security and Suitability Requirements
The COR shall coordinate all Background Investigations activities with the DOI/IA Personnel Security
Program Office and with the contractor’s team leader. The COR will be the sole individual to communicate with the Security Office. The contractor and all contractor employees, including the contractor’s personnel POC, are to refrain from direct contact with the Personnel Security Office.
Detailed compliance information is provided in Appendix C: Baseline Compliance Contract
Requirements
7.3.1 Contractor Personnel Security Requirements for DOI/IA Information Technology Contracts
1. Contractor Responsibilities Regarding Access to DOI/IA facilities and Information Technology. The contractor and subcontractors are responsible for immediately reporting to the DOI/IA Security Program
Office (referenced above) any circumstance which may affect the suitability of an individual for access to
DOI/IA information technology resources or determination of suitability. Contractors and its subcontractors are responsible for reporting changes in employee roster, including new hires, termination, transfers to positions which are unrelated to this contract to the COR and the Federal Task Lead ten (10) calendar days prior of the change.
2. COR Responsibilities. The COR must direct all security concerns and issues directly with the DOI/IA
Personnel Security Program Office. If, subsequent to the date of award of this contract, risk designation and investigative requirements are changed by the Government, and the changes cause an increase or decrease in contractor costs or otherwise affect any other term or condition of this contract, the COR must notify the Contracting Officer in writing and the contract shall be modified, as if, the changes were directed under the Changes clause of the contract.
7.4 Identification Badges
The applicable Contractor personnel shall not begin working under contract until all security forms have been properly completed and submitted and cleared. All Contractor personnel shall be required to wear identification badges when working in Government facilities. Guidance and direction are provided in
DOI 1450-0016-001 Homeland Security Presidential Directive-12-Aug 2004 (HSPD-12). Detailed compliance information is provided in Appendix C: Baseline Compliance Contract Requirements
8.0 Contract Management
Incident Training, Testing, and Exercises - The Contractor shall provide initial and refresher incident response training to all their contractor employees and will conduct a test of the incident response capability no less than annually.
Incident Response Plan - The contractor shall provide an updated IR Plan annually. The plan shall be coordinated with the designated Government IR Chief and submitted to the ACISO for approval and signature. The IR Plan lays out procedures, checklists, definitions, and more. It ensures the Bureau
ACISO & Department CISO IR policies are followed and synchronized.
Management Plan - The contractor shall submit a management plan within 14 days of award. The management plan shall be clear, precise and unambiguous in all parts. The plan should state how the contractor shall manage all employees under contract, so as to ensure that no part of this contract, at any time, turns into or functions as a personal services contract. It is the contractor’s responsibility to ensure that their employees know the limitations and the Guidelines for Maintaining a Proper Government-
Contractor relationship. The plan should further outline how work will be assigned and who and how work instructions will reach all of the contract personnel.
Reporting - The Contractor will provide the following reports to the applicable designee(s) as identified in the task order.
1. Daily Stand Up Planning and Execution
The Contractor shall prepare a daily status report and participate in or lead (as required) a daily operational status discussion with other IA stakeholders.
2. Weekly Status Report
A weekly status report and briefing is to be provided to the DIS Chief or designated appointee.
Status should include significant updates in IR, projects, service center ticketing, and sensor grid.
3. Monthly Progress Report
A monthly status report is to be made available to the DIS Chief or designated appointee providing the metrics for the Incident Response and Service Center ticketing activity for the month, the high level details for the number of configuration changes for each government furnished cybersecurity tool and whether the change was directly related to a known vulnerability or threat, and status of all on-going IA projects involving cybersecurity engineering support activity.
4. Monthly Contract Management Reports:
● Contract and Subcontract Expenditures - The Contractor shall ensure that a Monthly Progress
Report is submitted outlining the expenditures, billings, progress, status, and any problems/issues encountered in the performance of this task. If applicable, the Contractor shall prepare and deliver a Subcontract Expenditures Report that discloses actual subcontract expenditures.
● Quality Control Plan - The Contractor shall prepare and adhere to a Quality Control Plan
(QCP). QCP will initially be submitted with the proposal and will be updated upon award. At a minimum, QCP must include a self-inspection plan, an internal staffing plan, and an outline of the procedures that the Contractor will use to maintain quality, timeliness, responsiveness, customer satisfaction, and any other requirements set forth in this solicitation.
Contract Personnel Requirements Increase (Optional) - The Contractor will be prepared to execute personnel requirements growth as needed with appropriate contract modification.
Places of Performance - The Contractor shall perform primary activities in Reston, VA, and
Albuquerque, NM.
9.0 Work Products/Deliverable
Correspondence
To promote timely and effective administration, correspondence shall be subject to the following procedures:
• Technical correspondence (where technical issues relating to compliance with the requirements herein) shall be addressed to the ACISO with an information copy to the Contracting Officer’s
Representative (COR).
• All other correspondence, including invoices, (that which proposes or otherwise involves waivers, deviations, or modifications to the requirements, terms, or conditions of this SOW) shall be addressed to the COR
Attendance at Meetings
Contractor personnel will be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel must make their contractor status known during introductions.
The Government will hold a Technical Interchange Meeting (TIM) to ensure a common understanding between the contractor and the Government on task order requirements.
All deliverables/work products of the Contractor shall remain categorized as “Official Use Gov’t Only.”
The release of any portion must be authorized in writing by the Contracting Officer.
All deliverables are required within 30 days of reception/notification by the contractor, to the applicable date, unless otherwise specified throughout this contract.
Deliverables that may be required during the course of this contract include, but are not limited to, the following:
Contract
Deliverable
Line Items
Data Item Descriptions
Section/Task
(location in the SOW)
Format or
Media
Delivery
Date
Deliver to
Whom
Non-
Disclosure
Agreement
(NDA)
Signed statements from each employee and subcontractor agreeing not to disclose information gained due to work assignments
Appendix A
MS Word or
Adobe PDF in soft and hard copy
Due prior to start of work on contract
COR
Transition
Plan
The Contractor shall provide a detailed and comprehensive plan for transitioning the work and the workforce in an effective and cost efficient manner.
Section 6.0
MS Word or
Adobe PDF in soft and hard copy
Sixty days before the end of the contract
COR
Daily Stand
Up Planning and
Execution
The Contractor shall provide a daily Security operational status report for presentation to and discussion with other IA stakeholders.
Section 8.0:
Reporting-
Number 1
Verbal Due daily As
Designated
Weekly
Status Report
A weekly IR, projects, service center ticketing, and Sensor grid status briefing and report.
Section 8.0:
Reporting-
Number 2
Verbal;
update DIS weekly report in writing
Due Weekly
Designated
Federal
Mgmt.
Monthly
Contract
Management
Report
A report outlining the expenditures, billings, progress, status, and any problems/issues encountered in the performance of this task.
Section 8.0:
Reporting-
Number 4
MS Word in soft copy
1 week after close of month
COR and
Designated
Federal
Lead
Monthly
Progress
Report
A report outlining the monthly IR and Service
Center activity and security tool configuration changes and issues and status of all on-going IA projects involving Security
Engineering support activity.
Section 8.0:
Reporting-
Number 3
MS Word, .pdf, Excel and/or
PowerPoint
1 week after close of month
ACISO or
Designee
Quality
Control Plan
QCP must include a self-inspection plan, an internal staffing plan, and an outline of the procedures
Section 8.0:
Reporting-
Number 4 MS Word
2 weeks after
Task Award COR and
Designated that the Contractor will use to maintain quality, timeliness, responsiveness, customer satisfaction, and any other requirements set forth in this solicitation.
Federal
Lead
Secure
Configuration
Management
(SecCM)
Upon request, assist with review and recommends for changes or exceptions to existing
DOI and/or IA cybersecurity baseline settings.
Functional
Area 2: Task
MS Word
In soft copy
When request by ACISO or
Designee
ACISO or
Designee
Metrics to support
Continuous
Monitoring
Identify Metrics which support the continuous monitoring activities.
These will be developed in collaboration with DIS director and other staff.
Functional
Area 2: Task
1 & Task 2
MS Word or
Excel As required
ACISO
Technical
Analysis and
Security
Review of
Cybersecurity
Tools
Review current configurations and provide assessment concerning the
State of Security Tools.
Analyze and provide suggested industry standards to improve IA’s cybersecurity posture.
Functional
Area 2: Task
1,2,3,4 & 6
MS Word, Excel or
PowerPoint
When request by ACISO or
Designee
ACISO or
Designee
Incident
Response
Plan (initial and annual update)
Coordinat…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .