QandA_R190021_AMD_4.pdf

PDF 217 KB Posted

Attached to
Solicitation IT Infrastructure Operations Support Services (ITIOSS) Federal contract opportunity
Solicitation number
16PBGC19R0021
Issued by
Pension Benefit Guaranty Corporation

About this file

This is a request for information (RFI) issued by the Pension Benefit Guaranty Corporation (PBGC) regarding IT infrastructure operations support services (ITIOSS). PBGC seeks vendor feedback on draft performance work statements to help shape an ITIOSS requirement. The requirement includes a wide range of IT professional services supporting PBGC's diverse technological environment, such as business process support, transition planning, and infrastructure operations and maintenance. A task order will provide development, modernization, and enhancement work. Another task order will include SharePoint solutions development and support services, such as developing and maintaining governance, collecting requirements, and delivering new and enhanced solutions on the SharePoint platform. Vendors must submit one electronic copy of feedback by 12:00pm EST on May 10, 2019. This RFI is issued for information and planning purposes only and does not constitute a solicitation.

Questions and Answers 19R0021 AMD 004

View the file

Other files for this federal contract opportunity

Other files attached to Solicitation IT Infrastructure Operations Support Services (ITIOSS), newest first.
File Type Posted
16PBGC19R0021-004__IT_O&M.pdf PDF
B_-_ITIOSS_O&M_and_DM&E_Task_Order_PWS_Amd_004.pdf PDF
D_-_ITIOSS__TO1_QASP_SLAs.pdf PDF
C_-_ITIOSS _SharePoint_Solutions_Development_Task_Order_PWS_Amd_004.pdf PDF
G_-_LA~1.XLS XLS spreadsheet
16PBGC19R0021_IT_O&M_Final.pdf PDF
C - ITIOSS SharePoint Solutions Development Task Order PWS.docx DOCX document
A - ITIOSS2019_IDIQ w Sharepoint PWS.docx DOCX document
G - Labor Categories Pricing Workbook IT Infrastructure SharePoint Solutions Development TO.xlsx XLSX spreadsheet
M - Reading Room.docx DOCX document
F - Labor Categories Pricing Workbook IT Infrastructure Technical Services —
H - ITIOSS_TO1_Award Fee Plan_SLAs.docx DOCX document
N - Network Overview.vsd VSD drawing
I - ITIOSS_TO2_Award Fee Plan_SLAs.doc DOC document
B - ITIOSS O&M and DM&E Task Order PWS.docx DOCX document
L - TO-2 Supporting and Sample Documentation.zip ZIP file
E - ITIOSS _TO2_QASP_SLAs.docx DOCX document
D - ITIOSS _TO1_QASP_SLAs.docx DOCX document
K- TO-1 Supporting and Sample Documentation.zip ZIP file
16PBGC19R0021_ITIOSS__IT_O&M_-_Sharepoint.pdf PDF
C - ITIOSS SharePoint Solutions Development Task Order PWS.docx DOCX document
L - TO-2 Supporting and Sample Documentation.zip ZIP file
D - ITIOSS _TO1_QASP_SLAs.docx DOCX document
K- TO-1 Supporting and Sample Documentation.zip ZIP file
F - Labor Categories Pricing Workbook IT Infrastructure Technical Services —
B - ITIOSS O&M and DM&E Task Order PWS.docx DOCX document
N - Network Overview.vsd VSD drawing
M - Reading Room.docx DOCX document
E - ITIOSS _TO2_QASP_SLAs.docx DOCX document
I - ITIOSS_TO2_Award Fee Plan_SLAs.doc DOC document
A - ITIOSS2019_IDIQ w Sharepoint PWS.docx DOCX document
G - Labor Categories Pricing Workbook IT Infrastructure SharePoint Solutions Development TO.xlsx XLSX spreadsheet
H - ITIOSS_TO1_Award Fee Plan_SLAs.docx DOCX document
SharePoint_Solutions_Development_(SSD)_PWS_-_Task_Order.pdf PDF
Indefinite_Delivery_Indefinite_Quantity_(IDIQ)_-_PWS.pdf PDF
OM_and_DME_PWS_-_Task_Order.pdf PDF
Supplies_or_Services_and_Prices-Costs.pdf PDF
Attachment_1_-_SSD_TO_Pricing_Workbook.xlsx XLSX spreadsheet
Attachment_2_-_Ops_and_DME_TO_Pricing_Workbook.xlsx XLSX spreadsheet
Show all 39

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Question No. Offeror Question PBGC Response Solicitation Reference

Is there an incumbent contractor currently providing these services? If yes, please provide us with the contract details?

Yes. SAIC is the incumbent contractor. None Referenced by Offeror

2 What will be the contract value for this opportunity? The Independent Government Estimate is sensitive information not available for release None Referenced by Offeror

Given the complexity of the required multi-volume proposal, and the number of Pages, combined with the late question and answer period with little time to make substantive changes prior to review and submission, we request the government extend the due date for the proposal submission to August 30th.

The proposal submission date is changed to 21 August 2019. Standard From 33, Block 9, 16PBGC19R0021_IT_OM_Final.pdf.pdf, Proposal Due date

Would the government consider making the ITIL V3 Foundation and CompTIA certifications "desired" rather than "required"? Alternatively would the government consider requiring them to be completed by contract start?

All certifications listed in the PWS as required for key personnel will now be evaluated as desired, not required. Additional certifications are welcomed and desired.

To clarify/correct all educational requirements for key personnel; they will be evaluated as follows:

• A four-year college degree, typically referred to as a bachelor’s degree, is required (with no substitutions) for the following key personnel:

oProgram Manager
oOperation Manager
oSecurity Manager
oEngineering Manager
•A four-year college degree, typically referred to as a bachelor’s degree, is highly desirable,

however, eight (8) additional years of industry experience beyond what is already required may be substituted for the following key personnel:

oService Desk Manager
oNetworking Operation Manager
oITSM & IT Infrastructure Monitoring & Report Manager
oSharePoint Solutions Development and Support Manager

As long as the bachelor’s degree is from an accredited institution, it may be a BA, BBA, BFA or

BS.

16PBGC19R0021_IT_O&M, H.8; Key Personnel Qualifications, Appendix I, Key Personnel;

Program Manager

Would the government consider allowing ITIL v3 Foundation and CAP to be considered "desired" rather than "required" certifications? Alternatively would the government consider requiring them to be completed by contract start?

Please see response to question number 4 16PBGC19R0021_IT_O&M, H.8; Key Personnel Qualifications, Key Personnel; Security Manager

Would the government consider accepting DevOps Foundation Certification as "desired" rather than "required"? Alternatively would the government consider requiring it to be completed by contract start?

Please see response to question number 4 16PBGC19R0021_IT_O&M, H.8; Key Personnel Qualifications, Appendix I, Key Personnel; ITSM & IT Infrastructure Monitoring & Report Manager

Will the government consider a Bachelor of Business Administration (BBA) in Computer Information Systems as meeting or exceeding the requirement for a Bachelor of Science (BS) degree?

Please see response to question number 4 16PBGC19R0021_IT_O&M, H.8; Key Personnel Qualifications, Appendix I, Key Personnel;

Networking Operation Manager

ITIOSS Solicitation 16PBGC19R0021 - Questions and Answers

There are formula reference errors in cells AD13 and AD14. Will the government consider updating this document with the correct formulas.

Section J, Attachment G - Labor Categories Pricing Workbook IT Infrastructure SharePoint Solutions Development has been updated.

G - Labor Categories Pricing Workbook IT Infrastructure SharePoint Solutions Development TO.xlsx, CPAF SSD Task Order tab; Formula Error

Sections B.3 and B.5 references an IDIQ period of performance of 1 base year and 9 option year periods.

Other proposal documents reference 1 12 month base year and 4 12 month option periods. Please confirm the IDIQ contract's period of performance

Section B.4 is amended to reflect the correct period of performance of one (1) 12-month base period and four (4) 12-month option periods. See Amendment 001.

Supplies_or_Services_and_Prices-Costs.pdf, B.3.

Minimum and Maximum Amounts/B.5.

DESCRIPTION OF SERVICES (AT PBGC

SITE), Period of Performance

Since this is a best value procurement, cost can dilute the true evaluation of technical solution. In order to ensure that the Government receives cost proposals which are executable with highly-qualified and properly-compensated personnel, a proposal can be well written but may not be executable with the proposed price due to the factors unknown to the offerors. Establishing a competitive range will allow offerors to focus on the right technical solution for PBGC instead of focusing on the cost.

Will government consider establishing a competitive range prior to the submission of proposal instead of during discussions?

A competive range of for the proposals will be established during Phase II if necessary. See Section M, M.7 Competetive Range Determination

Per Section, M.7 COMPETITIVE RANGE

DETERMINATION

Please clarify the Period of Performance, as there are (2) sets of periods provided: 5 years [Base Year + 4 OY] and 10 years [Base year + 9 OY]

Please see response to question number 9 Section B.4 - Period of Performance

Since CISSP is considered a higher level certification compared to Security+ and CAP, can CISSP be substituted instead?

Please see response to question number 4 Section H.8 - Security Manager Certifications:

CompTIA Security+ is required Certified Assessment Professional (CAP) is required Certified Information Systems Security Professional (CISSP) a plus

Regarding H.8 Appendix I Key Personnel Qualifications,

4. Engineering Manager, PBGC states that a B.S. degree is required. However in the 2018 solicitation #16PBGC18R0009 SEALED BID (IFB), Attachment J.1.B Key Personnel Qualifications, PBGC stated that the (DM&E) Engineering Manager required “Bachelor of Science (B.S.) degree in Information Technology or additional 8 years of IT experience can be substituted.” Is this substitution still permissible?

Please see response to question number 4 Section H.8 - Key Personnel

Regarding H.8 Appendix I Key Personnel Qualifications,

6. Networking Operation Manager, PBGC states that a B.S. degree is required. However in the 2018 solicitation #16PBGC18R0009 SEALED BID (IFB), Attachment J.1.B Key Personnel Qualifications, PBGC stated that for the Networking Operation Manager that “Bachelor of Science (B.S.) degree in Information Technology would be a plus.” Will the government clarify whether the B.S.

degree is now a requirement rather than a plus, and if it is a requirement, can it be satisfied by a substitution of relevant years of experience?

Please see response to question number 4 Section H.8 - Key Personnel

FAR 52.222-41 is provided in Section I, however, there are no wage determinations included in the solicitation documents. Can the government please confirm that FAR 52.222-41 is not applicable and will be removed?

Clause removed Section I - FAR 52.222-41

FAR 52.222-41 is provided in Section I, however, there are no wage determinations included in the solicitation documents. Can the government please confirm that FAR 52.222-41 is not applicable and will be removed?

Clause removed Section I.66 - 52.222-41 SERVICE CONTRACT

LABOR STANDARDS

Offeror recommends that an acronym list be included at start of each Volume and that the acronym list is not Page-constrained and not included in this volume’s Page restrictions. Will the Government please consider this?

Yes. The offeor may include an acronym list at the start of each volume. The acronym list will not be included in the page count.

Sections L.7.2, L.8.1 - Format and Instructions for Preparation of Phase I & II Submission

18 Can tables be able to be submitted in 10 Point font, as Graphics are currently allowed to be submitted?

Yes. Sections L.7.2, L.8.1 - Format and Instructions for Preparation of Phase I & II Submission

19 Please confirm the Business Proposal Volume should include the Pricing Workbooks, Attachments F and G.

Yes. The Pricing Workbooks, Attachments F and G shall be included in the Business Proposal Volume.

L.8.2.4 - Pricing and Price Proposal Workbook

Does the PMP count towards total Page count of technical volume? If yes, will government consider increasing the Page count?

The Progam Management Plan (PMP) will not be required as part of the original proposal. Nor will any associated sub-plans, such as Change or Risk Management. The PMP will still be a contract requirement, however. PM-PMP-03 has been revised accordingly. It should be noted that it will be difficult to provide comprehensive management and technical approaches without addressing many of the concepts listed in PM-PMP-03.

OM & DME PWS Section 5.1.1.4 - PM-PM-03:

The PMP must be presented as part of the original proposal

Can government please provide # of applications and database scans that are planned to be conducted and on what frequency?

Number of web-based applications and the hosting model utilized at PBGC varies from year to year. Each web-based application, with permission from the business unit, should be scanned at least once quarterly. Currently, 63 web-based applications, 3 of which are cloud-based, have been identified for scanning. PBGC is currently using Acunetix to conduct these scans. PBGC is not currently conducting database scans.

Can government please provide # of cloud-hosted systems scans that are planned to be conducted and on what frequency? What tools are being utilized to perform cloud system scans?

Number of web-based applications and the hosting model utilized at PBGC varies from year to year. Each web-based application, with permission from the business unit, should be scanned at least once quarterly. Currently, 63 web-based applications, 3 of which are cloud-based, have been identified for scanning. PBGC is currently using Acunetix to conduct these scans. PBGC is not currently conducting database scans.

Please provide number of projects by complexity (Urgent, high, medium, low) does government expects offeror to work on simultaneously? Please provide a defintion of Urgent, High, Medium, and Low project definitions to characterize size, scope, and complexity.

Number of projects and associated work and complexity varies from year to year, but there are always several projects, many with high level of effort and/or complexity and many run concurrently. For the purpose of this response, size or Level of Effort will categorized as follows w/ typical quantities noted in parenthesis:

-Very Large: More than 7500 person hours (0-2) -Large: More than 5000 person hours (1-2) -Medium: More than 2500 person hours (2-5)

- Small: More than 1000 person hours (5-10)

- Very Small: Between 40 and 1000 person hours (5-10)

For the purpose of this response, complexity will categorized as follows w/ typical quantities noted in parenthesis:

-Very Complex: Requiring design and deployment and integration of mulitple new technologies (0-2) -Complex: Requiring design and deployment of 1 or 2 new technologies (1-3) -Moderate: Requiring modernization or enhancements to 1 or 2 existing technologies (2-9)

- Simple: Requiring modernization or enhancements to 1 existing technology (10-15)

See FY19 Projects Summary in Appendix N of TO1 PWS for details from FY19 which was an especially busy year

24 Does the Government intend to utilize similar LOE every year for the DME projects?

Please see response to question number 23

Please provide number of sharepoint service requests by complexity (high, medium, low) that the government expects offeror to work on simultaneously?

The team moves solutions from conception to delivery using the Agile methodology and 3-week sprints: 11.5 days of development with 3.5 days of planning.

The current team is comprised of a blended workforce with varying skill levels, from junior to senior level, a business analyst for administrative tasks, and a team lead for leadership and coordination with the Federal Team.

Team members are expected to work on 1-5 solutions within a sprint, depending on level of effort and/or complexity, as well as manage customer expectations, resolve work stoppages in a timely manner, and conduct regular tasks to maintain the health of the SharePoint Online infrastructure.

Number of solutions and associated work and complexity varies from year to year, but there are always several solution requests, many with a high Level of Effort and/or complexity. Solutions to be completed in any given calendar year are estimated in parentheses.

For the purpose of this response, solution request complexity or Level of Effort is categorized as follows:

• X-Large = more than 500 work hours or 8 3-week sprints (0-2)

• Large = 300-500 work hours or 4-7 3-week sprints (8-10)

• Medium = 150-300 work hours or 2-4 3-week sprints (24-26)

• Small = 45-150 work hours or 1-2 3-week sprints (20-22)

• X-Small = less than 45 work hours or less than 1 sprint = (25-30)

The team spends time each sprint in team meetings for management and educational purposes, as well as daily stand-ups to report status and challenges.

The Business Analyst and Team Lead attend various customer meetings within a sprint, in addition to their regular responsibilities.

26 Please advise if Labor Category descriptions and qualifications will be provided.

No. None will be provided. Labor Category

Please provide details on remediation plan that is expected from the offeror?

The offeror’s Remediation Plan shall provide the following details (not necessarily in the order listed):

1.Date of First Discovery
2.Description of the vulnerability
3.Vulnerability Severity
4.Plugin ID
5.Plugin Name
6.Hostname
7.IP Address
8.Port Number
9.Planned Mitigation Strategy (Patch, Accept Risk, Admin Action, Other Mitigation)

10. Planned Closure Activity (free form text descirption of mitigation plan)

11. Expected Resolution Date

12. Resolution (free form text detailing results of mitigation plan execution) Please note that the expected resolution date must not be exceeded without written approval from the government. The contractor shall provide a written justification for any deviations from the expected resolution due date. Examples of planned closure activities are as follows:

CHG0012560; Fixlet needed to be created to apply fix CHG0011907; Q3 Maintenance RFC May Workstation RFC CHG0011919 Accept Risk

Based on the vulnerability totals image on Page 156, approxinately 9000 high vulnerabilities are found on a given month. Also, based on SLA for High vulnerabilities SLA TQL of 90%, approxinately 900 vulnerabilities would be remaining after the initial remediation period.

Based on industry, it is understood that an organization should document plans for critical vulnerabilities but documenting detailed remediation plans for 900 high vulnerabilities every month could require significant level of effort. Please confirm that Offeror must document detailed remediation plan for all High vulnerabilities that are remaining open after the initial remediation timeline?

The government understands that documenting detailed remediation plans for 900 high vulnerabilities every month could require significant level of effort.

The contractor is expected to be protect the security posture of PBGC by being proactive in identifying and remediating the Critical and High vulnerabilities in a timely manner.

The government understands that circumstances may sometimes prevent the remediation of High vulnerabilities by the remediation due date, such as patch not yet available, or patch implementation causing functionality not to work properly. If any such circumstances should occur, then yes, the offeror must document a detailed remediation plan for any High vulnerabilities that remain open after the initial remediation timeline. Although the ITIOSS contractor could successfully achieve the TQL for remediation of high vulnerabilities detected and still have a significant volume of high vulnerabilities remaining to establish a plan for; this won't always be the case because the contractor may far exceed the TQL by standard patching during some months. Furthermore, vulnerability instances can be grouped together to formulate a consolidated remediation plan, so it is highly unlikely that the contractor would ever be required to prepare and execute 900 individual remediation plans to address outstanding high vulnerabilities.

The RFP does not specify the NAICS code or Small Business size standard for this solicitation. What is the NAICS code and size standard for this solicitation?

FAR clause 52.204-8 has been updated with NAICS code 541519. Section K.5 (a), Annual Representations and Certifications; NAICS Code and Small Business Size Standard; Page number 86 - NAICS code and Small Business Size Standard is missing from RFP

The RFP states that "PBGC anticipates a contractual period of performance will be one (1) 12-month base period and nine (4) 12-month option period" spelling out "nine" and showing (4) in the following parentheses.

Additionally the table below this text shows estimated dates for the Base Period and 4 Option periods, for a total of 5 years. Please confirm the planned period of performance for this contract.

Please see response to question number 9 Section B.4, Period of Performance; Page number

7. - The planned contract duration is unclear as written; will the period of performance be 5 years or 10 years, or some other period.

Would the government consider a Master's degree acceptable in lieu of the requirement for a Bachelor of Science (BS) degree?

Yes H.8; Key Personnel Qualifications, Pages 53-57 - MS vs BS

CISSP is generally is accepted as containing all elements of CompTIA and more. Would the government consider as acceptable a CISSP certification in lieu of CompTIA?

Yes H.8; Key Personnel Qualifications, Pages 53-57 - CISSP certification vs. CompTIA

CISA is widely considered a more stringent certification than CAP. Would the government consider a Certified Information Systems Auditor certification as acceptable in lieu of Certified Assessment Professional (CAP) certification?

Yes H.8; Key Personnel Qualifications, Page 54 - CISA

vs. CAP certification

Would the government consider allowing Bachelors of Arts (BA) in Science, Technology, Engineering, and Math (STEM) fields to be acceptable in lieu of a Bachelor of Science (BS) degree?

Please see response to question number 4 H.8; Key Personnel Qualifications - BA in STEM subject vs. BS degree

35 Would the government consider allowing 20+ years of experience in lieu of a BS?

Please see response to question number 4 H.8; Key Personnel Qualifications - Key Personnel; Security Manager

Subparagraph 4 reads "Discuss the Offeror's financial capability." Will the government allow inclusion of the most recent corporate annual report to satisfy the majority of this requirement, with a brief statement of highlights in the proposal submission? We believe this will readily allow PBGC to verify strong financial capability. If yes, please verify that the annual report may be an attachment or appendix and will not be included in Page count.

Yes, submissions may be provided as an attachment and will not be included in the page count.

Offerors are cautioned, however, to provide only normally developed annual reports and not to introduce any new content vis a vis this proposal. Provision of additional context will be considered negatively.

L.7.2.5, Page 97 - Section 1, Factor I: Corporate Capability and Experience

This section notes "Recent past performance is defined as that work completed within the past three (3) years." For absolute clarity, please indicate if the three-year timeline is related to the date of final RFP release or the date of Phase I submission.

The three year recency timeline relates to the date of final RFP release. M.2.1.2, Page 112 - Factor 2: Past Performance

This section includes the statement "For the purposes of this evaluation, similar size and scope is defined as: a past/present performance example addressing at a minimum the service categories required in the PWS." For references provided by the teammate directly responsible for future SharePoint work, please verify there is no government expectation that these references will cover the full ITIOSS PWS, but that they are expected to include only elements of the SharePoint PWS.

The past performance references are related solely to the SharePoint tasking. The Government does not expect that same past performance reference also cover TO1 services.

M.2.1.2, Page 112 - Factor 2: Past Performance

Subparagraph 2 notes past performance references will be evaluated by "The work performed and how it specifically relates to this ITIOSS procurement in size and the scope of services provided, including the number of users and the technical architecture supported for both Task Orders."

Given that the PWS for the SharePoint support TO is completely separate from that of the other TO, will the government verify there is no expectation for past performance references from the SharePoint teammate to be evaluated against the separate TO's PWS?

The evaluation will take into account subcontractors that will perform major or critical aspects of the requirement when such information is relevant to the instant acquisition.

M.2.1.2, Page 112 - Factor 2: Past Performance

Understanding that BigFix will be used as the golden source for inspection and reporting, what are the acceptable AV tools that BigFix would be searching for to ensure the 99% SLA requirement is met?

BigFix is the reporting tool used to compute the Endpoint Compliance (Antivirus) SLA. BigFix is configured to mark an endpoint as compliant if the Symantec EndPoint client is installed and running (on Windows and RHEL computers with a BigFix agent) and has antivirus definitions that are no more than 10 days old. Scoring can and is currently done daily and then averaged over the period of performance for the award fee.

Page 5 - row 6.6.2 - Acceptable AV

Monitor endpoint management software, e.g. Symantec End Point Protection, BigFix to ensure it is current and activated and repair/reinstall as required and ensures all application devices are having their security logs ingested into the SIEM - Does this mean the contractor is to maintain BigFix and other endpoint tools so they can be used as a source of truth to compare what endpoints are being ingested in Splunk (the SIEM)?

The contractor is to ensure all endpoint management software is operating properly. Yes, the contractor is also expected to compare endpoints from multiple tools to identify issues with missing or malfunctioning endpoint software. Yes, the contractor is also expected to ensure all logs are successfuly being ingested into the SIEM.

Page 150 - section 6.6.2.1 - bullet points - Clarification request

The solicitation addresses tier 2 support, would the government clarify who provides first tier security support?

TO1 refers to multiple tiers of support. Tier 1 refers to the IT Service Desk to be operrated by the TO1 contractor. Tier 2 refers to incididents and RFIs that cannot be resolved by the IT Service Desk (Tier 1). Tier 3, although not properly defined in the TO1 PWS, refers to external product vendors, e.g. Microsoft, Cisco, etc. that would be escalated to by a Tier 2 team if the issue was beyond their ability to resolve.

The Appendix J - IT Service and Support 2018 Statistical Summary subheading Incident, RFI, Service Requests, and Change Management Requests details the breakdown of incidents and RFIs router to Tier 2 groups covered under TO1 (first table) and those not covered by TO1 (second table)

Page 150 - section 6.6.2 - Tier 1 security support

43 Would the government clarify that the correct Attachment reference is Attachment D?

Yes, for TO1 the correct attachment reference based on fbo.gov posting is Attachment D. Page 25 - section 5.4 - SLAs

44 Is there an expectation of any advanced forensic data analysis?

Only basic forensic analysis is expected and only on an occasional basis. Contractor is expected to coordinate forensic analysis using DHS shared services when necessary.

Page 50 - section L - Forensics

The network diagram shows that the Coraopolis site is slated for decommissioning this month (7/2019), but Appendix F shows it is going to be decommissioned by end of the year (12/2019). If the network diagram is outdated, are there any other changes to the diagram or network infrastructure that may need to be updated?

The Coraopolis site was recently decommissioned. The Wilmington (WIL) site is currently slated for decomission in April-May 2020. Regarding Euclid (EUC), this may grow to approximately 400 users (more than previously anticipated) by the end of 2021 to include the Call Center and Document Management Center. Build-out of the second floor will be ongoing thru January 2020 so the ITIOSS contractor will be required to support a portion of this build-out. Site Support staff may ultimately be required for on-site, day-to-day support, but this is unlikely. In that case, coordination with on-site technical support staff will most definitely be required. The HQ relocation dates are still in flux, but may be earlier than what is noted.

Pages 193/197 - Appendix D and F - Network Diagram and PGBC Locations discrepancy

Do these bullets relate to the IT security infrastructure or to all the PBGC computing environments? For example, the IT Security Tools and Incident Response support services are responsible for "performing preventative and remedial maintenance of components" on only the components within the enterprise IT Security infrastructure, correct?

These particular bullets refer only to the IT Securiy infrastructure. Page 152 - CS-IR-02 - clarification of scope

Do we follow the standard 1 hour notification requirement to send to US-CERT? If so, which PBGC team is responsible for notifying US-CERT (usually SOC, CSIRT or IT)?

Yes, PBGC does follow the 1 hour notification requirement. The IT Security Tools Support and Cybersecurity Incident Response team is responsible for these notifications.

Page 25 - row 24 - US-CERT reporting requirement

There are several requirements around authenticated scans (when technically feasible), but no mentions of unauthenticated scans. When an unauthenticated scan is feasible, but a credentialed scan is not, would all requirements for scanning still apply?

All PBGC managed subnets and hosts must be scanned for vulnerabilities as outlined in 6.6.3 IT Vulnerability Scanning and Reactive Vulnerability Management coordination. Credentials shall be utilized to authenticate to devices that support credential scans, i.e. when technically feasible.

Where not feasible, the result is an uncredentialled scan. The scanning and vulnerability remediation requirements are the same for all hosts on PBGC's network, regardless of whether it supports a credentialed scan or not.

Page 155 - section 6.6.3.1 - Unauthenticated scans

With the security teams managing their own infrastructure, would they be subject to the same maintenance scheduling, meeting and messaging requirements as regular IT infrastructure?

Yes. As noted, additional outages may be negotiated with impacted business units. If there is no business unit impact, additional maintenance windows would be easy to obtain and messaging requirements would be none or minimal.

Page 202 - Appendix H - IT Maintenance Schedule

Will PGBC please share other Service Desk related statistics such as Average Handle Time (call time + wrap up time), Average Wait Time, Average Call Time ?

What are the defined Hours of Operation for the Tier 1 Service Desk?

Requirement # EU-SD05 States : “Contractor shall work to reduce customer interactions by promoting self-service through creation of new and refinement of existing on-line self-help/self-service content and publicizing its availability via email, job-aids, offered training sessions, integrated voice response (IVR) system (to be established in FY18/FY19), and open houses events, etc.”

Was the self-serve IVR system established on schedule?

Q1: IT Service Desk stats:

-Average Call Time 2018: 8:09 (minutes:seconds)

- Average Handle Time 2018 (call time + wrap up time): 8:53

- Average Wait Time 2018: 37 seconds.

Q2: Support hours Primary support hours for this entire contract are 7:00AM – 7:00PM EST M-F excluding holidays and this includes the IT Service Desk, however, the following are noteworth exceptions:

-walkup window support hours are 7:00AM – 6:00PM M-F EST excluding holidays -Network Operations Center support hours are 7x24x365 and these includes basic Tier 1 Service Desk services required outside of primary support hours -- Tier 2 on-call support of critical production infrastructure is 7x24x365 -- Change implementations are normally during non-business hours and are supported by tier-2 (see Appendix H - IT Infrastructure Maintenance Schedule)

Q3: Self-serve IVR implementation status The new telephony system was successfully implemented which will allow for self-serve IVR capabilities, but no of those capabilities have been established. The offeror is expected to make recommendations for this capability.

Page 205, Appendix J - Service Desk Interactions

Requirement “PBGC is in the process of implementing the service request module of Service Now which will be used as a front-end request platform for automated fulfillment of access requests using SailPoint LifeCycle Manager.

This is expected to be in place by September 2019.”

Is this implementation still on track for completion in Sept 2019?

Yes, PBGC is still on track for this. Section 6.3.3.1 Page 48 - Implementation Schedule

“Synchronize and reconcile PBGC’s application list/CIs across disparate systems, e.g. DOJ Cyber Security Assessment and Management (CSAM); used for storing information about PBGC’s FISMA systems, ServiceNow CMDB; used to discover and manage PBGC’s Cis, and mAppIT; PBGC’s centralized application list”

Is the Configuration Item (CI) synchronization between mAppIT, ServiceNow and CSAM integrated/automated or is it done manually?

Only Application configuration items are synchronized between these systems and this synchronization is done manually.

Configuration Management 6.5.10, Page 145 - CI synchronization status

Deliverable PM-PM-03 states that the Program Management Plan (PMP) shall be presented as part of the original proposal.” Would the Government confirm that this requirement is not included in the overall 70-Page limit for Phase II, Volume II?

Offerors must receive an adjectival rating of “Good” or higher for Factors 1 and 3 during Phase 1 in order to be evaluated in Phase II. Offerors without a record of relevant Past Performance (Factor 3) or for whom information on past performance is not av

PWS (B) ITIOSS OM and DME Task Order - Page 15-16

Deliverable PM-PM-03 states that the Program Management Plan (PMP) shall be presented as part of the original proposal.” Would the Government confirm that this requirement is not included in the overall 30-Page limit for Phase II, Volume III?

The Progam Management Plan (PMP) will not be required as part of the original proposal. Nor will any associated sub-plans, such as Change or Risk Management. The PMP will still be a contract requirement, however. PM-PMP-03 has been revised accordingly. It should be noted that it will be difficult to provide comprehensive management and technical approaches without addressing many of the concepts listed in PM-PMP-03.

PWS (C) SharePoint Solutions Development Task Order - Page 10

Please confirm the period is one base plus 9 option years.

The table only shows 4 option years. The Excel Pricing Template (Attachment F) requests Base Year Pricing plus 4 Option Years.

Please see response to question number 9 RFP/B.4/Period of Performance / Attachment F -

Please clarify whether the Draft Transition Plan update is due 5 calendar days after award OR 3 business days after the post-award conference.

Draft Transition Plan update is due 3 business days after the post-award conference. Offerors should note that a high-level transition approach is required as part of the proposal. In this approach, offerors should account for the fact that the communications services listed in DME- ME-19, 20 and 21 and the Security SPMO services outlined in Section 6.6.1.1 are being performed by a different incumbent than the one who is currently providing the rest of the O&M and DME services. Offerors, therefore, will need to account for transition from two separate incumbents. It should be noted that both the high-level transition approach required in the proposal and the Draft Transition Plan required after award must account for transition from two separate contracts held by two separate incumbents

RFP/F.1 Deliverables Table/Ref 1 - Page 20

Can the Government provide the number of FTEs (or number of hours) currently performing the work for both the O&M/DM&E as well as the SharePoint Solutions Development task orders? And, if so, can it be provided by PWS Task Area?

Service Domain/Team FTE Count End-User Services

(11) IT Service Desk (12) Site Support Data Center Services

(5) Windows Server Administration and Support

(4) Windows Desktop Administration and Support, Software Packaging, and Software Deployment

(2) Enterprise Identity Management and Continuous Automated Compliance Monitoring Administration and Support

(2) Office 365 and Messaging Administration and Support

(4) UNIX/LINUX Administration and Support

(2) Virtualization Platforms Administration and Support

(3) Storage and Backup Administration and Support

(7) Database Administration and Support

(3) Web and App Middleware Administration and Support

(8) Voice, Video, and Network Infrastructure Operations Network Infrastructure support

(2) Telephony Infrastructure Support (8) Network Operations Center

(2) IT Service Management (ITSM) and Infrastructure Monitoring and Reporting ITSM Tool Support

(1) IT Service Catalog Support (2) IT Infrastructure and Application Availability, Capacity, and Performance Monitoring

(1) ITIOD Reporting and Dashboarding (1) Change Management support (2 Asset Management and Inventory (2) Configuration Management

(5) IT Security Services Security Program Management Office (S-PMO)

(5) IT Security Tools Support and Cyber Incident Response

(5) IT Vulnerability Scanning and Reactive Vulnerability Management coordination

(6) IT Security Controls Support (2) Test Center Operations

RFP/General - Page n/a

In light of the number of task and sub-task areas in the PWS, and the very large magnitude of the proposal submission requirements, and given the stated sequenced evaluation approach to be employed by PBGC, would the Government consider staggering the dates for the Phase I and Phase II proposal submissions? This proposal is a large commitment (i.e., nearly 200 written Pages plus business proposal), which comes with a high investment.

Given that the Government will not review Phase II documents until the Phase I evaluation has been completed, it would be highly beneficial for all if the due date for Phase II was set at 2-3 weeks subsequent to the Phase I submission. Presumably, this would not result in any delay in the Government’s overall evaluation process.

Another option would be a down-select notification, followed by a short (e.g. 2-week) window for vendors to submit Phase II.

No. The Proposal submission requirements remain unchanged. RFP/General - L.71/L.8 - Page n/a

Please provide information on the current incumbent vendors and contract numbers for both the O&M/DM&E as well as the SharePoint Solutions Development task orders.

Please see response to question number 1 RFP/General

The sentence beginning with “offerors must receive an adjectival rating of Good or higher for Factors 1 and 3 during Phase 1…..” implies that the Factor 2 Past Performance submissions will not be scored and used as part of the Phase 1 evaluation. This is contradicted elsewhere in the RFP document (see L.8 Phase II Submission, Page 99 and Section M, top of Page 110).

Can the Government please clarify?

Offerors must receive an adjectival rating of “Good” or higher for Factors 1 and 3 during Phase 1 in order to be evaluated in Phase II. Offerors without a record of relevant Past Performance (Factor 3) or for whom information on past performance is not available will not be excluded in Phase I unless they receive a rating lower than Good for Factor 1 and 3. Section M updated

RFP/L.7.1 Phase 1 Submission/ Page 94

Please list the Adjectival Ratings (e.g. “Good”) that will be used in the Phase 1 Evaluation process, and clearly define each Rating in terms of what is required to attain.

Please see response to question number 60 RFP/L.7.1 Phase 1 Submission/ Page 94

Can additional experience substitute for either no college degree or a lower level degree (e.g. an Associates vice a Bachelors, or a Bachelors vice a Masters)?

Please see response to question number 4 RFP/L7.2.7/Section 3, Factor 3: Qualifications of Key Personnel, #4, Page 99

Will it be acceptable to bid a key personnel resume where it is noted that the individual is currently in process of gaining one of the required certifications, assuming that they will have the necessary cert by time of award?

Please see response to question number 4 RFP/L7.2.7/Section 3, Factor 3: Qualifications of Key Personnel, #4

If a vendor is responding to both Task Orders, can the vendor’s plan to meet the 23% small business subcontracting goal be met by an approach that combines both task orders, such that one task order may reach a higher small business subcontracting target while the other is lower, but in the aggregate, they reach 23%?

The Offeror must meet the 23% small business requirement on aggregate on both TOs. L.8.2.2.2.2 and L.8.2.3.1.2.2/Small Business Subcontracting Plan Goals; Page 103 and 105

The security manager is stated to require a Security+ and CAP with a CISSP preferred. Most dually certified PMP/CISSPs do not maintain a Security+ since the CISSP is a much higher level certification. If the Security Manager has both a CISSP and PMP, is the Security+ and ITIL still required?

Please see response to question number 4 Appendix I - Page 53

What vulnerability assessment tools are in use? For Device Scanning , the vulnerability assessment tools in use are Tenable.SC, and Nessus. For

Web Application Scanning, the vulnerability assessment tool in use is the Acunetix Web Scanning Tool.

PWS 6.6.1 - Page 148

Are CDM tools in use, if so what? PBGC has deployed and is utilizing CyberArk for priviedged account management and session brokering. PBGC has deployed SailPoint Idientity IQ for identity and entitlement discovery.

PBGC had deployed the CDM firewall for connectivity to CMaaS. PBGC is in the process of deploying a ServiceNow MID server for HWAM and this will be in place before contract award.

PBGC is in discussions with DHS on use of it's instance of Tenable Security Center to report to CMaaS and also about deployment of Carbon Black.

PWS 6.6.1 - Page 148

68 How many POAMs are currently open and for how many systems?

The ITISGSS currently has approximately 30 open POAMs PWS 6.6.1.2 - Page 149

69 What SIEM tool(s) are currently in use? Is it only Splunk per the appendix?

Splunk is PBGCs SIEM tool. PWS 6.6.2 - Page 150

70 What DLP solution is currently in use? PBGC has deployed Symantec DLP. PWS 6.6.2 - Page 150

Are any tools being used to track incident reports besides ServiceNow? Is there any coordination with US CERT?

Splunk is used to track the critical security events and their associated investigation status.

Details for the analysis of such events are stored in a SharePoint list. Should a security event be classified as a security incident, this is recorded in Service Now and reported to US Cert.

PWS 6.6.2 - Page 150

What are the vulnerability mitigation resolution benchmarks for critical and high findings

Critical vulnerabilities must be remediated within the 30 days following their discovery and High vulnerabilities must be remediated 90 days following their discovery.

PWS 6.6.3.2 - Page 156

Being credentialed/authenticated scans, are host agents used in correlation with the vulnerability scanning tool in use? What are they (e.g. Tenable, Qualys)

No, PBGC has considered, but has not yet and has no immediate plans to acquire host-based scanning agents

PWS 6.6.3.2 - Page 156

Has PBGC adopted NIST 800-53R5 yet or NIST 800- 37R2? The PWS states 800-53R4 is in use but is there an anticipation to update to the latest revisions?

PBGC has adopted NIST 800-37R2. NIST 800-53R5 is, of course, still in draft form and therefore not truly available for adoption. Once it is finalized, PBGC plans to adopt NIST 800-53R5 expeditiously.

PWS 6.6.4.2 - Page 158

75 How many separate systems are in place and what are their designated FIPS 199 impact levels?

The ITISGSS is comprised of one (1) system and four (4) subsystems, all of which are FIPS 199 Moderate.

PWS 6.6.4.2 - Page 158

How many ServiceNow mid servers are deployed? Is there just 1?

PBGC has a total of 6 mid server deployed, 3 for its production instance of ServiceNow and 3 for its dev and test instances. PBGC is in the midst of deploying an additional mid server to relay HWAM information to the DHS CDM CmaaS.

General

Can you provide details on how PBGC is utilizing ServiceNow for access management?

PBGC plans to migrate from its existing HP Service Manager/Catalog 9 workflow engine utilized for access request, approval, and fulfillment tracking to the ServiceNow request module on the night of 9/30/2019.

General

For each of the subsections (services) of 6.5, there is a requirement to appoint a leader for that specific service capability. Many of the functions could be consolidated under one leader. Is there any requirement that the leader for each of the services be a different individual?

No, the offeror may propose/name an individual to serve as the lead for multiple teams. Only key personnel must be separate individuals.

PWS 6.5/General

We feel that in some instances we could greatly improve the quality of services offered and at the same time lower overall costs through the purchase and deployment of new technology/automation solutions. Would this be something the PBGC would entertain?

In a general sense, yes, with some critical caveats. First, there are a number of risk-weighted events occuring in the base year so PBGC's appetite for innovation will be diminished initially.

Second, any proposed technology/automation solutions must have proven track records with other clients whose tasking is strongly comparable to that of ITIOSS. Those track records should be measureable through a combination of quantitative and qualitative metrics and verifiable through contact with the applicable clients.

General

80 What is the specific tool used for account management? CyberArk is the privileged account management tool being referenced. 6.5.1.2 SM-SN-09 - Page 100

Is the monthly reporting requirement on service request generated through the catalog that are missing info, or is this in reference to the catalog items themselves?

Each service catalog item is expected to have a minimum set of data elements, e.g. approver(s), description, fulfillment team, etc. Missing elements can result in "orphaned" requests, e.g. no approver, or poor customer experience. The contractor is expected to, at least monthly, validate that all required metadata for each service catalog item is in place or to fix or escalate to the federal face off when it isn't.

6.5.2.2 SM-SC-02 - Page 103

82 How many applications are currently being monitored with RUM and BPM?

RUM – 4;

BPM – 15

6.5.3.1 - Page 104

83 How many BPM probes are deployed in production? Six (6) - HQ, DMZ, Kingstowne, Euclid, Miami, Wilmington 6.5.3.1 - Page 104

84 How many RUM probes/engines are deployed in production?

Two (2) 6.5.3.1 - Page 104

85 What is the total number of BPM transactions being utilized and the amount owned by PBGC?

38 transactions flows have been configured in PBGC's implementation of BPM 6.5.3.1 - Page 104

86 What is the current version of APM deployed in production?

9.26 6.5.3.1 - Page 104

Does PBGC want to monitor every new application that is deployed to production with RUM and/or BPM or just those deemed as mission critical or of high importance? If every application, does PBGC own enough APM capacity to support this?

PBGC makes an effort to monitor every critical and high importance system, but not every system.

What does and does not get monitored is also a function of input from the owning business unit and sometimes their supporting contract SLAs.

6.5.3.2 SM-AA-05 - Page 105

What are the criteria for an incident(s) to be considered or escalated to a problem?

This is outlined in the incident and problem management SOPs, but to sumarize, the general criteria most commonly used for escalating an incident to a problem are as follows:

• A significant interruption or reduction in quality of service has been temporarily restored but further analysis is required to get to the underlying root cause

• Resolution of the incident requires a vendor to be contacted (example Cisco TAC, Microsoft or Oracle)

• Multiple occurrences of a similar incident have occurred

6.5.6 - Page 116

Are there any other sources a risk could come from (such as internal audit), or are the risks solely identified by the contractor?

There are other sources of risk including an audit. 6.5.7 - Page 138

Do all proposed changes need to be reviewed by the CAB, or just changes with higher risk/impact ratings?

PBGC has several change types and only normal-major and emregency go to a CAB and eCAB respectively for review and recommendation to the change manager. Normal-minor changes are typically (alost always) reviewed and approved by an IT change manager. Standard changes are approved once by the CAB and then can be executed repeatedly without further approval.

6.5.8 - SM-CM-03 - Page 142

Will the contractor have admin level access to Splunk and/or be permitted to build searches and dashboards in Splunk to provide an enhanced level of service to PBGC?

Yes Appendix – K

Can you expand upon what the contractor’s responsibility would be around “managing consumables”?

See SM-AM-11 6.5.9.2 - Page 142

93 What tool is used to determine if an end user device has not logged into the network in the last 30 days?

BigFix is utilized to calculate the most recent network connectivity by PBGC GFE computers (laptops and desktops). InTune is utilized to determine this for PBGC issued mobile phones.

6.5.9.2 - Page 143

94 How are software assets on end user devices discovered and tracked?

A combination of Microsoft SCCM and ServiceNow CMDB discovery and repoorting are utilized currently.

6.5.9.2 - Page 143

95 Does this requirement include end user devices? Yes. 6.5.9.2 SM-AM-04 - Page 143

Is PBGC utilizing the service mapping discovery capability (top down discovery, not to be confused with standard device level discovery) for any applications? If yes, how many applications are discovered/mapped in this fashion?

This is not currently licensed or used by PBGC 6.5.10 - No Page Referenced

97 Are all PBGC applications currently mapped/modeled in the ServiceNow CMDB?

PBGC's major applications rae modeled in the CMDB. Not every tools of COTS product is. 6.5.10.2 - SM-CF-03 - Page 147

Is application information stored in the CMDB currently used to support other IT processes such as change and incident? For example, automatically setting an incident priority or a change risk rating based upon application information stored in the CMDB?

Configuration items (including applications) are associated to ITSM modules like change and incident, but these do not currently effect priority or risk settings in an automated fashion.

6.5.10 - Page 147

How is unauthorized hardware and software detected? Is this done solely through the ServiceNow discovery capability?

This is not being done consistently at present, but, PBGC envisions the following tools be utilized to control, prevent, and detect unauthorized hardware and software:

1) Cisco ISE is configured to evelauate and prevent unauthorized hardware from being connected to PBGC's network

2) USGCB and limited administrative access to PBGC workstations greatly reduces risk of unauthorized software installation. AppLocker may be further used to restrict stand-alone malware execution.

3) Use of CyberArk priviledged management software further monitors and tracks use of priviledged access.

4) ServiceNow discovery detects deployed software and can reconcile this with authorized software and authorized changes

5) Splunk can and does collect event logs pertaining to all of these events

6.5.10 - SM-CF-06 - Page 147

100 Are there any other discovery sources or systems of record that populate the ServiceNow CMDB?

Vmware vCenter 6.5.10 - SM-CF-06 - Page 147

How are IMAC requests currently being captured? Is this just a standard help desk request within ServiceNow?

IMAC requests are made through the service request catalog and service request modules of the HP Service Manager 9 tool, referred to as “GetITAccess”, but is planning to migrate, prior to the start of this contract, this capability to the request module of Service Now.

6.2.2.2 - EU-SS-04 - Page 31

Can you explain in more detail the role of the contractor for both the DR and datacenter moves to the new Co-Lo?

Is there an expectation that the contractor will physically move all the equipment between sites?

The new O&M contractor will be responsible for implementation of a new network core router/switch for connectivity as well as relocation of DR equipment and services from WIL to the DR Co-Lo. As noted, the New O&M contractor will be responsible for implementation of a new network core router/switch for connectivity as well as relocation of primary data center equipment and services from HQW to the primary data center Co-Lo.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .