QA 5.13.2020_0001.pdf

PDF 126 KB Posted

Attached to
Computer Security Monitoring, Incident Response, a Federal contract opportunity
Solicitation number
140A1620R0018
Issued by
Department of the Interior Bureau of Indian Affairs Central Office

About this file

This document contains questions and answers related to a solicitation for computer security monitoring, incident response, and security engineering support services for the Department of the Interior Bureau of Indian Affairs. The solicitation seeks proposals for providing services such as cybersecurity analysis, engineering, system administration, security tool management, incident response, security awareness training, and security program support. Key details include the solicitation number, a May 27, 2020 proposal due date, descriptions of the types of computer security tools currently in use, locations where support is required including Albuquerque and Reston, and clarification that the services do not involve classified data but may include personally identifiable information. The document also addresses questions on labor categories, security conferences, transition planning, and other contractual requirements.

View the file

Other files for this federal contract opportunity

Other files attached to Computer Security Monitoring, Incident Response, a, newest first.
File Type Posted
Attachment 2 SOW A0002_0002.pdf PDF
Attachment 2 SOW 5.13.2020_0001.pdf PDF
Appendix C-Baseline Compliance Contract Requirements_0001.pdf PDF
B09 SF30 140A1620R0018 A0001_0001.pdf PDF
Sol_140A1620R0018.pdf PDF
B08 Attachment 1 - Pricing Schedule.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Solicitation 140A1620R0018

Questions & Answers dated 5/13/2020

Q1: Will the Government allow the use of subcontractor’s past performance with 20% or more work-share? (iii. Factor 3 – Past Performance)

A1: The solicitation has been updated to add past performance for the subcontractors;

however, there should be a minimum of three (3) past performance records for the prime contractor if it exists.

Q2: Appendix C – Baseline Compliance Contract File is not able to be downloaded. (SOW)

A2: Appendix C will be posted as an attachment to amendment 0001.

Q3: Will the Government allow for smaller font in graphics, tables, headers, and footers, such as Arial Narrow 9? (Section L, 1.5)

A3: Yes, smaller font will be acceptable in graphics, tables, headers, and footers.

Q4: Will the Government please confirm that the Quality Control Plan is due post award? If not, can it be included as a separate attachment and not count as part of the page count? (SOW)

A4: Please see the deliverables table on pg 17. The Plan is due two (2) weeks after award.

Q5: The instructions on past performance required only 1 page per citation which limits the amount of detail in order to adequately represent the related work. Will the Government consider going to at least 2 pages and still stay within the 15-page section limit? (Addendum to FAR 52.212-1 Section 1.6)

A5: Two pages is allowable. The solicitation has been updated.

Q6: Identification of relevant past performance of the “Offeror” is requested per 1.6.1 Section 1(a) iii of the solicitation. Please confirm whether the term “Offeror” encompasses strategic teaming partners (subcontractors) of the qualifying ISBEE.

A6: See Q1.

Q7: The government references - Recommended Security Controls for Federal Information Systems and Organizations http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updatederrata_05-01-2010.pdf · The provided URL is not found. (Section H.2)

· Does BIA follow 800-53 rev3 controls for all systems?

· Is the contractor required to have experience and abide by NIST 800-53 rev3 or can the contractor have experience with other (e.g. 800-53 Rev 4) controls?

A7: The BIA uses the current revision which is rev4. The updated link is https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/final.

Q8: Has BIA fully implemented and configured the respective TRM tools for task area 1?

(SOW, Functional Area 1: Task 1)

A8: BIA does not use any TRM tools when performing software waiver reviews. They perform research on the manufacturer and product from the manufacturer’s web site and reputation checks from other reputable web sites.

Q9: Is the contractor required to manage (system configuration and maintenance) all related TRM tools leveraged in task area 1? If not, will the contractor be allowed to make system configuration / recommendations to TRM tools? (SOW, Functional Area 1: Task 1)

A9: Not applicable, Indian Affairs (IA) does not use TRM tools at this time.

Q10: Does IA leverage CVSS or Mandiant Risk Rating for managing and prioritizing each of their security incidents? (SOW, Functional Area 1: Task 1)

A10: IA leverages CVSS, but not Mandiant Risk Rating.

Q11: Is the contractor required to support the Sioux Falls secondary data center if so, what is that frequency of travel? (SOW, Functional Area 2)

A11: Likely never. We leverage existing data center staff for any touch maintenance or installation.

Q12: We understand the support for Monday through Friday from 6:00AM – 5:00PM (MT);

however, does government expect the contractor to provide any after-hours assistance (i.e. On call, weekend) for any of the contractor’s duties? (SOW, Functional Area 2)

A12: There is flexibility. These after-hours scenarios are coordinated in advance with the Contracting Officer’s Representative (COR).

https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/final

Q13: Is the contractor required to be Agile / SAFe Certified Scrum Master (CSM) for development engineering and system integration efforts? Is the contractor team required to work at a specific velocity? (SOW, Functional Area 2: Task 3)

A13: Neither are required, but it is recommended any such certifications or past experience be listed.

Q14: Is the contractor required to be experienced with the DOI ASOC tools? If yes, can the government define tool types and how many years of experience are required at a minimum for the respective positions? (SOW, Functional Area 2: Task 4).

A14: Good question. The ASOC tools are primarily ForeScout CounterACT, HCL BigFix, and Tenable Nessus. The experience in these tools are already worked into the appropriate positions in the “Expected Qualifications” section of the SOW (Attachment 2).

Q15: Can DIS give a background of what work is performed in each of these locations by location? (SOW, Attachment 2)

A15: The two work locations are Albuquerque, NM, and Reston, VA. Each site has all three team functions: Incident Response (IR), Cybersecurity Engineering, & System Administration.

Q16: Security Information Event Management Systems (SIEM), such as Splunk, can the Government supply us with the Version of Splunk Enterprise Security (ES), Splunk User Behavior Analytics (UBA) and Splunk Phantom and what capability modules are utilized or turned on within ES? (SOW, Task 7)

A16: Splunk Enterprise Security is version 7.3.3 and BIA does not currently use UBA or Phantom.

Q17: Can the government describe tools or technology in the development and reporting within their dashboards? (SOW, Task 7)

A17: The SIEM dashboard used by Indian Affairs (IA) is Splunk. All development and reporting for SIEM is within Splunk.

Q18: Where should we include the summary statement within our response and what the page limit is? (Formatting Table pg 83)

A18: The solicitation has been updated to include a page limit for the Summary Statement under Factor 4.

Q19: Will the Government allow for graphics and tables to TNR 10 font? (Section L)

A19: See Q3.

Q20: The solicitation states: “As stated in FAR 52.212-1 (f)(2)(i)(A), if the proposal is emailed, then the proposal must be received at the initial point of entry to the Government Infrastructure not later than 5:00pm (local time) one working day prior to the date specified for receipt of offers.” Please clarify whether our emailed proposal must be received by the government on May 26 or May 27.

A20: This provision is specific to late proposals. The proposals are due May 27, 2020, at 5:00pm EST. Since they are to be received via email, I would suggest you follow up that we receive it. If we do not receive it by the specified time, then we would be reliant on FAR 52.212-1 to determine if it is late or not. Basically, it is a risk each vendor takes should they wait until the last minute to send. The Contract Specialist will be diligent to respond to each proposal as they come in to confirm receipt.

Q21: The table provides a page limit of 15 pages for the Factor 1 – Technical Capabilities and Management Approach section of our proposal. As this section is to contain information regarding two Functional Areas covering a total of nine tasks, in addition to management approach, respectfully request an increase to the page limit.

A21: The page limitation has been increased to 20 pages. The solicitation has been updated to reflect this change.

Q22: May we use a smaller font for tables and graphics, such as 10-point Arial?

A22: See Q3.

Q23: Please clarify in which electronic file we are to submit the Summary Statement for pricing.

Should we include it as Section 2 of our proposal response (which includes the Technical narrative), in the pricing spreadsheet, or a separate volume (i.e., separate electronic file)?

A23: See Q18.

Q24: The Anticipated Level of Effort table within this section lists the following labor categories: Lead/Senior Cyber Security Engineer, Senior Cyber Security Engineer, Cyber Security Engineer, Cyber Security Analyst, Senior Security Administrator, Security Administrator. Qualification requirements listed on SOW pages 20 through 26 are provided for the following labor categories: Cyber Security Analyst, Senior Cyber Security Engineer, Senior Network Security Engineer, Cyber Security Engineer, Senior Cyber Security Analyst, Senior Cyber Security Administrator, and Cyber Security Administrator. As these lists do not match (for example Senior Cyber Security Analyst is on one list but not the other), please provide a listing of the specific labor categories for which we are to show our qualifications. (SOW, section 9.0)

A24: Great catch. Focus on the “Anticipated Level of Effort Table”; this is correct. For the expected qualifications below that table:

• Please ignore the “Network Security Engineer-Senior” qualifications

• Please ignore the “Security Analyst-Senior” qualifications

Q25: At what percent complete is BIA's Splunk implementation? (SOW, Functional Area 2.

Task 7)

A25: The original Splunk deployment was completed years ago, but is subject to possible restructuring, upgrades, and other changes as may be determined by Indian Affairs (IA).

Q26: Does the scope for Functional Area 2 include cloud technology (e.g., Microsoft 365, Microsoft Azure, Microsoft Dynamics)? (SOW, Functional Area 2, Task 1)

A26: No

Q27: Please confirm that BIA will continue using COTS Splunk for IA-CMS and that the licensing costs, user costs, support costs, and maintenance costs for that software/service are covered under a separate contract not related to this solicitation. (SOW, Functional Area 2, Task 7)

A27: Licensing costs, user costs, support costs, and maintenance costs for Splunk software/service are covered under a separate contract and are not related to this solicitation.

Q28: Please confirm that BIA currently has the Splunk SIEM deployed enterprise-wide. (SOW, Functional Area 2, Task 8)

A28: BIA has completed its deployment of Splunk enterprise-wide.

Q29: Please estimate the frequency/number of times per year that it expects to host tabletop exercises so offerors may estimate travel and resources requirements. (SOW, Functional Area 2, Task 9)

A29: The minimum number of table top exercises per year will be one (1) with a desired goal of four (4) per year, or quarterly. The table top exercises will be conducted using teleconferences; no travel is required. The maximum amount of time for the table top exercises is four (4) hours per exercise.

Q30: Solicitation states that Government will provide contractor with GFE (Government Furnished Equipment). With specific needs for “non-domain” joined computer devices for penetration testing, intrusion testing/monitoring, please confirm government will provide those devices as well (also known as BlackHat/Black Box testing). (SOW, section 3.0)

A30: IA will provide all required hardware for the “non-domain” penetration testing, intrusion testing/monitoring work outlined.

Q31: Solicitation states that “The contractor shall, at their cost, send contractors to technical conference, as directed by the ACISO." Please define or provide an example of which conference(s), the frequency, and expected costs for contractor. For example, the BlackHat Conference. (SOW, Section 5.1)

A31: Great question, but it misses the intent.

SOW 5.1 is stating that the contract company is responsible for training its staff. The government is not required to fund travel for this reason. As a historical example from 2018- 2019, only one contractor attended a conference (2019 VM World).

Example 1: If the contract company desires to send an employee to a conference (like RSA) to maintain his/her CISSP or GCIH certification, then the company needs to pay for the travel and the ACISO needs to authorize it.

Example 2: If the contract company wants to provide a SANS course at Albuquerque and Reston (2 work sites), then the contractor would need to fund it & obtain ACISO approval.

Example 3: If the contract company decides to provide training via online options, the contract company should fund it. This of course requires no travel.

Q32: The solicitation clearly defines the requirements of developing a Transition-Out Plan.

Please confirm that the incumbent contractor has a similar Transition-Out Plan in place and that the timeline for onboarding of a new contractor is in fact 60 days. (SOW, section 6.0)

A32: A Transition-Out Plan does not currently exist on the incumbent contract. However, this is being addressed with the incumbent and it is highly likely one will be in place prior to new award.

Q33: Please advise in which section / volume the offeror is to include the completed Representations and Certifications. (Section K.2)

A33: The solicitation is amended to add Reps and Certs to Section 1.

Q34: Please confirm that we may identify relevant past performance for our teammate provided the teammate was the prime contractor on that cited contract. Given that a 15-page limit is provided for past performance, please clarify the construct of this section (i.e., is an introduction allowable or is the government seeking up to 15 1-page past performance references). (Section 1.6.1.a.iii)

A34: There is a 15 page limit. Should the contractor want to use any of these pages for an introduction, it is allowable.

Q35: Are there key personnel?

A35: Cannot answer authoritatively as “key personnel” is not clearly defined. The federal government, DOI, and IA have “essential personnel”, but the contract in question will not have any contractors designated as “essential personnel”.

Q36: Should resumes be submitted for all recommended positions? If so, are letter of commitments required?

A36: Yes, resumes must be submitted to the COR prior to IA’s acceptance of a candidate.

The contract does not require a letter of commitment. Ref Task 15 Personnel Performance/Replacement.

Q37: How many active endpoints does BIA have (servers, workstations, desktops)?

A37: BIA has 6K total devices, and BIE has 5.5K. Servers for BIA and BIE are 435 and 361, respectively.

Q38: How many firewalls and servers (DNS, AD, DHCP, LDAP, MS) does BIA have?

A38: Firewalls for BIA and BIE are 9 and 6, respectively. Servers for BIA and BIE are 435 and 361, respectively.

Q39: Is there currently an incumbent firm providing these services or work similar in scope to the tasks specified within this offering?

A39: Yes, services by an incumbent firm is currently being provided to Indian Affairs (IA).

Q40: Will classified and unclassified data be ingested?

A40: Only unclassified. Personally Identifiable Information (PII) and For Official Use Only (FOUO) are the protected data types that are processed by Indian Affairs.

Q41: Is there an attachment 1 with the LCAT description?

A41: “LCAT” is not in the contract.

Q42: Does the government intend to interview and provide approval for every resource staffed to this contract prior to the contractor beginning to provide services? (H.3)

A42: Review and approval of a candidate’s resume is a requirement prior to being accepted, but IA does not interview candidates.

Q43: What Host- and Network-based Intrusion Detection/Prevention Systems are currently in use at the BIA? (Attachment 2)

A43: The existing NIDS/NIPS deployed by IA are Cisco NG-IPS, Snort, Proofpoint Emerging Threat Pro rulesets for Snort, & FireEye Endpoint Protection (HX).

Q44: Where will the manned incident response analyst support be carried out? Reston, VA or Albuquerque, NM? (Attachment 2)

A44: The manned incident response analyst support is split between Reston and Albuquerque and must remain so in order to provide maximal coverage each day.

Q45: Can the government provide the approved hardware/software list from the Technical Reference Model (TRM) prior to the submission deadline? (Attachment 2)

A45: No, but what can be stated is that greater than 98% of computers (servers, workstations, and laptops) are Dell brand.

Q46: What government furnished security tools are currently deployed, including but not limited to: ASOC, Vulnerability Scanner, SEIM, IDS/IPS etc? (Section 2.0, Functional Area 1)

A46: Security tools currently deployed are as follows:

• Department (DOI) level tools: HCL BigFix, CounterACT, Splunk, FireEye, Tenable Enterprise Nessus, FortiNet FortiAnalyzer.

• Bureau (Indian Affairs) level tools: Splunk, Cisco IPS, Proofpoint ET Pro Snort signatures, Graylog, Zabbix, Endace, Cisco FirePOWER NG-IPS, Cuckoo, Bloodhound, Sysmon, Centrify

Q47: Are work shifts allowed for the manned incident response analyst support and other roles?

(Section 2.0, Functional Area 1)

A47: The manning coverage is covered in SOW 2.0 Task, Functional Area 1, Objectives:

“Manned incident response (IR) analyst support is required on Federal business days (Monday through Friday, excluding Federal holidays) from 5:00AM – 6:00PM (MT).”

For example, the Reston team could take the early shift starting at 7:00am local time (which is 5:00am MT). And Albuquerque could take the late shift, departing at 5:00pm local time.

This example would provide the requisite coverage.

Q48: For Task 5, are personnel supporting IA under this contract designated as “mission essential”? (Section 2.0, Functional Area 2, Task 5)

A48: No, the contractors supporting this contract are not designated “essential personnel”.

Q49: For Task 7, is IA-CMS utilizing services provided through the DHS CDM program for provision of CM Dashboard? And if so, should any concerns around OCI for potential bidders be explicitly addressed in responses? (Section 2.0, Functional Area 2, Task 7)

A49: No. The Indian Affairs (IA) SIEM solution (Splunk) is managed at the bureau level.

DHS mandates an approved set of tools, Splunk being one of them. However, IA is responsible for its own SIEM program, including provisioning.

Q50: For Task 9, will there be any expectation to facilitate annual table top assessments/exercises outside of participation? (Section 2.0, Functional Area 2)

A50: No, there is no expectation to facilitate an annual table top exercise outside of participation. However, CIRT participation is required.

Q51: In the Attachment 2-SOW, it states “The contractor shall, at their cost, send contractors to technical conference, as directed by the ACISO.” Can the Government please identify historically what conferences it has directed contractors to attend at its own expense so that potential bidders can consider what level of unbillable overhead it will be expected to absorb at no cost to the government? (Attachment 2)

A51: See Q31.

Q52: Tasks of the SOW (SOW pp. 7-13) lists functional areas and associated tasks, while Section 9.0 Work Products/Deliverables of the SOW (Figure 3, SOW p. 20) lists the level of effort anticipated to perform these tasks. Can BIA describe how tasks were mapped to level of effort, and can that mapping be shared with potential bidders? (SOW, Section 2.0)

A52: Functional area 1 (SOW pg 7) primarily maps to Analysts. Functional area 2 (SOW pg

9) primarily maps to engineers and administrators.

File details come from the government source that posted it. Updated .