CBP SOC RFI QA responses V7_040825.pdf

PDF 192 KB Posted

Attached to
Security Operations Support Services Federal contract opportunity
Solicitation number
20146850
Issued by
Department of Homeland Security Customs and Border Protection

About this file

This document is a Request for Information (RFI) for Security Operations Center (SOC) Support Services issued by the Customs and Border Protection (CBP) Cybersecurity Directorate. The RFI covers a follow-on effort to the current task order held by Leidos, Inc., with an anticipated total contract value of $250 million and a period of performance from 9/24/2025 to 6/23/2030, consisting of a 6-month base period plus four 12-month option periods and one additional 6-month period.

Key details include the requirement for comprehensive cybersecurity support services across CBP's network, including monitoring approximately 150 ATO-authorized systems, handling classified data, and supporting various cybersecurity functions such as incident response, threat intelligence, and risk management. The current staffing ranges from 75-125 full-time employees, with work to be performed primarily in Ashburn, VA. Cloud infrastructure involves AWS, Google, and Azure platforms, and the SOC will utilize tools like CrowdStrike, Splunk, and Swimlane. The acquisition strategy is not yet finalized, including potential small business set-aside considerations, and the government is seeking industry input on the scope, complexity, and approach to delivering these critical security operations services.

View the file

Other files for this federal contract opportunity

Other files attached to Security Operations Support Services, newest first.
File Type Posted
RFI_Draft PWS SOC 040125 v2.pdf PDF
RFI Instructions for Security Operations Support Services .pdf PDF
SOC PWS Draft Rev1_022525.pdf PDF
CBP CSD SOC Support Services RFI 032025.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Security Operations Center (SOC) Support Services

Request for Information (RFI)

Customs & Border Protection (CBP) Cybersecurity Directorate (CSD)

SOC Support Services RFI Questions/Answers 1 Who is the Incumbent Contractor for the SOC The current Incumbent is Leidos, Inc.

2 Period of Performance The anticipated Period of Performance for this effort is 9/24/2025 to 6/23/2030

3 Is this a follow-on to task order # 70B04C23F00001108 Yes.

4 General Inquiry Acquisition Strategy has not been determined yet.

5 Identify the correct incumbent details for references Leidos, Inc.

6 What is the anticipated period of performance Base (6 Months) + 4 (12-month periods) + one 6-month period.

Is a continuing requirement for Cybersecurity Support Services (task order# 70B04C23F00001163)

No. This is under a different task order.

See response 9.

8 Is this requirement open to any new companies Reviewing responses from industry to determine the strategy.

9 Is this is an entirely new effort or is there an incumbent currently providing these services This is a follow-on effort.

10 What are the incumbent contract details Task order # 70B04C23F00001108- Leidos, Inc.

11 What is the anticipated contract value for this opportunity TEPV $250 Million

12 Where is the place of performance Current worksite is Ashburn, VA.

13 Are there any set aside opportunities Reviewing responses and capabilities from the RFI response.

14 Are IT Asset Disposition (ITAD) services are explicitly required under this PWS Yes. Asset Disposition is within scope

In the event that asset disposal is required, would disposition options such as exchange/sale per FMR 102-39 be considered to potentially offset costs?

Asset disposition will be handled on a case-by-case manner in order to abide by Government standards and provide best value.

Can the Government confirm the name of the incumbent contractor currently performing these services, or is this a new requirement and scope of work?

The current incumbent vendor is Leidos, Inc.

Will this opportunity be solicited as a small business set-aside or competed under full and open competition?

This decision has not been finalized

18 The RFI response is currently limited to four (4) pages. Please confirm whether the cover letter and

The cover letter is separate from the page count. Total of 6 pages with cover sheet.

company information are included within this page count.

What is the current cloud infrastructure supporting CBP’s cybersecurity operations (e.g., AWS, Azure, etc.)?

AWS/Google/AZURE

20 What Security Information and Event Management (SIEM) platform is currently in use? Splunk Enterprise Security, Swimlane

What are the Government’s expectations regarding the integration of Zero Trust Architecture (ZTA) into existing CBP systems and infrastructure?

• Incremental Implementation: CBP experienced a phased approach to ZTA integration, starting with critical areas and progressively expanding to encompass all aspects of our IT environment.

• Compliance with Standards:

Integration efforts adhered to NIST SP 800-207 guidelines and other applicable federal cybersecurity standards and mandates.

• Enhanced Security Posture: The shift to ZTA has significantly mitigate risks associated with cyber threats and enhance the resilience of CBP’s digital assets.

• Continuous Monitoring and Evaluation: Ongoing assessment of the ZTA framework's effectiveness in real-world applications, adjusting strategies as needed based on evolving cybersecurity landscapes.

Can the Government provide further detail on the current stage of ZTA implementation and any defined milestones or roadmap objectives?

CBP in alignment with DHS ZT Framework has an existing notional roadmap/timeline for continued maturity

What are the expected minimum staffing levels (FTEs) for this requirement, by task or labor category, if available?

The current FTE count ranges from 75 to

125. LOE is based off of current Op Tempo. It will be up to vendor to provide in their technical proposal response an FTE solution that is creative and cost effective for this SOC requirement.

24 What the acquisition strategy will be and what vehicle will be used to compete this opportunity?

No acquisition strategy has been determined at this time.

Will the Government consider increasing the limit to 1 page per section, or an overall page limit of 8 pages?

The page number will remain the same with the cover letter being 1 page and 5 pages for responses. Total of 6 with a cover sheet.

Can the government please consider additional page allotments so that we are allowed up to 1/4 a page per bullet in the scope so we can provide a thorough and thoughtful response?

The page number will remain the same with the cover letter being 1 page and 5 pages for responses. Total of 6 with a cover sheet.

Can the Government please provide respondents the flexibility to answer all 33 questions across the 10 sections within a 6-page limit as opposed to the specified fractions of a page for each section?

The fractions are structured to assist in evaluation of the complexity of the task.

The page number will remain the same with the cover letter being 1 page and 5 pages for responses. Total of 6 with a cover sheet.

To better understand the size, scope, and complexity of this requirement, can the government please provide sizing metrics for 1) event ingest per day/week/month, and 2) total number of end points monitored?

The current FTE count ranges from 75 to

125. LOE is based off of current Op Tempo. Endpoints is a varying number and is sensitive information.

Can the government please provide a list of tools (software, hardware) that comprise CSD's Technology Stack and that would be expected to be used in Security Operations Center Support Services?

CrowdStrike Digital Guardian Tanium Tenable Security Center Tenable Nessus DBProtect WebInspect AppDetective Axonius Silo EnCase Swimlane Analyst1 Windows Workstation Windows Server Linux (Various Kernels) Kubernetes RedHat Directory Services Ansible Various AWS Services Zimperium

Is it the government’s intention to consolidate ISSOs/AISSOs from other parts of CBP OIT into the scope of this requirement? For example, systems like BEAGLE, TPVS, MAGE, and others have ISSOs/AISSOs that support their systems today. Would that ISSO/AISSO support be transitioned to Security Operations Center Support Services?

Organizational changes are not considered in this effort.

Can the government please provide the expected annual level of effort that comprises the scope of the Security Operations Center Support Services requirement (# of staff in FTEs, number of hours per year)?

FTE hours (?)Hours may range between 40-50 depending on mission and incident level

Can the government please clarify if this scope of work is inclusive of both professional services and the procurement of supporting tools/licenses to support this requirement or if the supporting tools/licenses are procured separately?

The extent of this effort is professional services. The acquisition of certain tools will be on a case-by-case basis and will be considered individual events to be determined at that time.

Are the CBP owned and operated IOT/OT (i.e., Border Technology, Non-Intrusive Inspection, Tethered Aerostat Radar System, etc.) devices within the purview of the Security Operations Center Support Services requirement?

CBP SOC provides security services for all systems attached to the CBP network to include systems from OFO, USBP, OIT, etc.

34 Does the government intend to have an Industry Day for this requirement?

An Industry Day is not scheduled or anticipated at this time.

Will CBP be expecting the contractor to leverage existing CBP tools in the delivery of this service, or will the contractor be responsible for implementing all security tools under the SOC’s responsibility?

The vendor shall use existing tools and be able to adapt to new tools that are utilized during the period of performance

36 If the contractor will be expected to leverage existing tools, please provide a list of those tools.

Tools being used by CBP SOC is sensitive information and will not be released as an inventory.

Will CBP be expecting the contractor to purchase the licenses for the tools within the SOC, or will the CBP be purchasing the licenses?

CBP Acquisition will purchase requisite tools.

Will CBP be responsible for any agents which are required to be installed on CBP endpoints and mobile devices, or will those agents be the responsibility of the contractor?

The CBP SOC will responsible for assessment of all software and endpoints connected to the CBP network.

Please provide additional information on the shared responsibility model for incident response. Will the SOC contractor be completely responsible for incident response, or will CBP be a part of the response?

SOC contractor will be responsible for CBP incident response and coordination activities

Will CBP be providing government sourced intelligence feeds to the SOC, or should the contractor assume that intelligence feeds will be limited to commercially available intelligence feeds?

Government sourced, ONSINT Research

41 Is there a specific cybersecurity framework which CBP will require the contractor to conform with? MITRE, DHS 4300 directives

What will be the CBP process to authorize the contractor operated SOC to connect to CBP systems? What are the contractors’ responsibilities to support this process such that CBP can issue the appropriate ATO?

To connect to CBP systems the vendor will follow the CBP Background Investigation process. The Government will complete the process. The contractor is responsible for applying qualified personnel.

43 What clearances will the SOC personnel will be required to have?

All Contract staff at a minimum will require a full CBP Background Investigation. Others will require up to

TS/SCI

44 Will the contractor be expected to handle classified information within the SOC Yes

Given the variables, and the potential dependency on actions taken by CBP for incident resolution, how does CBP anticipate determining compliance to the incident resolution SLA?

The contractor shall be capable to surge personnel to respond to events and then scale back to standard operations.

What is the scale of the environment (cloud, on-premises, endpoints, mobile devices) that CBP anticipates that the SOC will be responsible for monitoring?

Specifics about CBP Cyber architecture is sensitive information and cannot be released.

Does the CBP have an existing SOC providing these services, and if so, what transition activities are anticipated to be necessary? Will the new SOC have to store any existing log files? If so, what is the anticipated size of the existing log files, and what format are they in? If the existing logs will not be moved to the new SOC, will the new SOC be expected to have remote access to the existing logs to support incident investigation?

There is currently a SOC in operation.

Log files will need to be stored.

Given the nature of CBP’s mission, multiple CBP devices are likely to not have internet access, and many are likely to have intermittent access. Will monitoring these systems only when they have stable internet connections be sufficient, or will the SOC have to implement methods to support the monitoring of disconnected or limited connected devices?

The SOC will be responsible for monitoring all connections to the CBP Network.

Where is the work location for this opportunity? Will remote and/or hybrid contractors be acceptable or will contractors need to be located at the physical location for the SOC operations?

The current worksite is Ashburn Va.

Remote and hybrid determination is yet to be determined and may change throughout the POP.

Has CBP determined the contract vehicle and acquisition strategy for this procurement, and is this anticipated to be a full and open competition or set-aside?

Acquisition Strategy is yet to be determined

Beyond the SOC management mentioned in the RFI, who are the key executive stakeholders for this initiative, and what are their primary concerns or priorities that should be addressed in our response?

It is incumbent on the vendor to assess these issues in the Management and Technical approach of the proposal

What is the anticipated value range and period of performance for this contract, including base and option periods? Estimates currently are believed to be approximately $64 M.

The estimated value = $250 Million POP- Base (6 Months) + 4 (12-month periods) + one 6-month period.

What are CBP's specific goals and requirements for small business utilization on this contract, including targets for various socioeconomic categories?

The acquisition strategy has yet to be determined.

Based on the incumbent contractor currently providing these services; what aspects of the current SOC operations are working well, and which areas need improvement?

This information is available in the Government Contract performance site.

Besides EO 13800, are there other specific regulatory or compliance requirements (such as DHS policies or CBP-specific directives) that will impact SOC operations?

NIST 800-53, DHS4300A, CBP 1400-05

Will CBP’s international locations require SOC coverage, and are there specific considerations for monitoring these OCONUS locations?

Coverage for assets and connections OCONUS maybe required

What are CBP's requirements for SOC continuity of operations (COOP) in the event of a disaster or major incident affecting primary SOC facilities?

SOC personnel will be required to be onsite with a 24/7 coverage availability.

And the ability to surge support in cases of events

What is the expected timeline for transitioning from the current security operations state to the improved state aligned with EO 13800, and are there specific milestone requirements during this transition?

The Expected Transition period is 3 months

What are CBP's requirements or limitations regarding remote work for SOC personnel, particularly for after-hours monitoring and response?

SOC personnel will be required to be onsite with a 24/7 coverage availability

Can CBP please identify what percentage or numbers of the SOC staff will require security clearances and what levels; and are there specific requirements for cleared facility operations?

All Contract staff at a minimum will require a full CBP Background Investigation. Others will require up to

TS/SCI

61 Can CBP please share the breakdown and numbers of current FTEs supporting the program?

The current FTE count ranges from 75 to

125. LOE is based off current Op Tempo.

It will be up to vendor to provide in their technical proposal response an FTE solution that is creative and cost effective for this SOC requirement.

Can CBP please provide details on the current security operations environment, including existing SIEM, EDR, and SOAR technologies that would

SIEM, EDR, SOAR's currently exist and may require updates, integration with Microsoft tools need to be integrated or migrated as part of this effort?

The RFI mentions cloud-based security technologies. Could you specify which cloud platforms (AWS, Azure, GCP) are currently in use or planned, and whether FedRAMP High compliance is required for all cloud components?

AWS/Google/AZURE

Beyond the standard MTTD and MTTR metrics referenced in the RFI, what specific metrics will CBP use to evaluate successful performance, and what reporting cadence is expected?

Performance will be measured by SLA's and monthly evaluations.

Is CBP seeking standardization of security tools across the enterprise as part of this effort, or is the expectation that the contractor will integrate with existing diverse toolsets?

The expectation is to integrate tools currently used and seek new technology over the course of the POP, as directed by the CBP Task Manger

Can CBP please share statistics on the current monthly volume of security incidents by severity level, and the most common types of threats CBP is experiencing?

This information is sensitive and can't be released

What is CBP's current level of security automation, and what specific automation targets or objectives should bidders focus upon?

SOAR, Dashboard capability, informational interface (collaborative data solution)

How does CBP expect the SOC to interface with other federal security operations centers, such as CISA's or other DHS components, to include ICE, HSI, and ERO?

Thru coordination and communications via phone, collaboration, official meetings (email etc.)

What is CBP's philosophy on technology refresh cycles for security tools, and how should bidders account for technology evolution over the contract period?

The contractor should be prepared to work with various technologies and be able to adapt to new solutions on the fly

Beyond SLAs, how will CBP measure the overall success of this contract, and what would constitute exceptional performance?

Performance will be measured by SLA's and monthly evaluations.

What is the current state of CBP's asset inventory, and will the contractor be responsible for establishing or maintaining the inventory?

Contractor will be responsible for inventory management and tracking of any CBP assets managed thru signature or job responsibilities

Are there specific data sovereignty or data residency requirements that will affect where security data can be stored or processed?

This information will be addressed during Transition

How does CBP's insider threat program interface with SOC operations, and what are the expectations for supporting insider threat detection?

This information will be addressed during Transition

What is the current state of Security Orchestration, Automation and Response (SOAR) implementation, and what are CBP's plans for expanding SOAR capabilities?

This information will be addressed during Transition

75 What government-furnished equipment or facilities will be provided to support SOC operations?

GFE in the order of Laptops and work location will be provided by CBP

76 Can you please tell me how many FTE you envisage being on this recompete contract

The current FTE count ranges from 75 to

125. LOE is based off current Op Tempo.

It will be up to vendor to provide in their technical proposal response an FTE solution that is creative and cost effective for this SOC requirement.

77 1. Will the SOC be required to also provide support for classified data and systems? Yes

1. Are there any space/facility constraints or location concerns associated with the current CBP

SOC?

No

1. How many ATO ’ed systems, applications, networks, are currently supported by the CBP SOC today?

Roughly 150

1. Is there adequate logging currently established for the ATO 'ed systems, applications, and networks, based on OMB’s M-21-31 Minimum Logging Data as defined?

CBP currently operates the most robust enterprise logging solution within DHS.

In order to provide similar, size, scope, and complexity can the Government provide estimates on current size of the environment, # of incidents, and an estimate of historical FTE counts for the work?

The FTE Support should be determined from the details of the PWS and will be considered in the Management Approach.

See response #76.

82 Is this a new requirement? No

83 If this is not a new requirement then what is the existing contract #? The Incumbent is Leidos, Inc.

84 Could you please let me know who the current incumbent is? The Incumbent is Leidos, Inc.

Could you kindly confirm whether this initiative represents a new undertaking, or is there an incumbent currently delivering these services? If an incumbent exists, may we request the relevant details of their contract, including the contract number?

The Incumbent is Leidos, Inc.

86 Are there any set-aside considerations for this opportunity?

The acquisition strategy has yet to be determined.

87 Could you share the anticipated contract value associated with this opportunity?

The estimated contract value is $250 Million

Could you please inform me if this is a new requirement or if there is currently an incumbent performing these services for CBP? If there is an incumbent, can you please indicate who that is?

The Incumbent is Leidos, Inc.

Do you intend on awarding an 8A set-aside.

The acquisition strategy has not been finalized yet and depending results of the

RFI.

File details come from the government source that posted it. Updated .