RFI_Draft PWS SOC 040125 v2.pdf
PDF 1 MB Posted
- Attached to
- Security Operations Support Services Federal contract opportunity
- Solicitation number
- 20146850
About this file
This document is a Performance Work Statement (PWS) for Customs and Border Protection (CBP) Enterprise Services Office of Information and Technology Cyber Security Directorate Security Operations Center (SOC) Support Services. The PWS outlines comprehensive cybersecurity support services across 16 primary task areas, including Program Management, Cyber Defense Forensics, Attack Sensing & Warning, Cyber Incident Response, Threat Intelligence, Risk Management, Security Modernization, Vulnerability Assessment, and Security Engineering.
The contract requires a contractor to provide 24x7x365 cybersecurity support for CBP's information systems infrastructure, with specific requirements for each task area ranging from threat hunting and incident response to security engineering and logging solutions. Key requirements include maintaining robust security operations, conducting vulnerability assessments, providing threat intelligence, supporting zero trust architecture implementation, and ensuring compliance with federal cybersecurity standards. The period of performance is 60 months, consisting of a six-month base period and four one-year options with an additional six-month option. Contractor personnel must have extensive cybersecurity experience, with specific qualification requirements for different analyst tiers and key personnel positions, and must maintain various professional certifications.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CBP SOC RFI QA responses V7_040825.pdf | ||
| RFI Instructions for Security Operations Support Services .pdf | ||
| SOC PWS Draft Rev1_022525.pdf | ||
| CBP CSD SOC Support Services RFI 032025.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Customs and Border Protection (CBP) Enterprise Services (ES) Office of Information and Technology (OIT) Cyber Security
Directorate (CSD)
Performance Work Statement (PWS)
Task Order Attachment 2
For
Security Operations Support Services
DATE April 1, 2025
Table of Contents
1 PERFORMANCE WORK STATEMENT ........... Error! Bookmark not defined.
1.1 Title of Requirement ............................................. Error! Bookmark not defined.
1.2 Requiring Organization
1.3 Introduction
1.4 Scope
1.5 Background
1.6 Applicable Documents
1.7 Performance Requirements
1.7.1 Task 1 – Program / Project Management
1.7.2 Task 2 – Cyber Defense Forensics (CDF) Support
1.7.3 Task 3 – Attack Sensing and Warning (AS&W) Support
1.7.4 Task 4 – Cyber Incident Response Team (CIRT) Support
1.7.5 Task 5 – Cyber Threat Intelligence (CTI) Support
1.7.6 Task 6 – Cyber Risk Management (CRM) Support
1.7.7 Task 7 – Security Modernization (SecMod) Support
1.7.8 Task 8 – Vulnerability Assessment (VA) Support
1.7.9 Task 9 – Security Engineering and Sustainment (SES) Support
1.7.10 Task 10 - Enterprise Logging Solution (ELS) Support
1.7.11 Task 11 - Development Security Operations (DevSecOps) Support (Optional)
1.7.12 Task 12 - Information Systems Security Officer (ISSO) Support
1.7.13 Task 13 – Cyber Threat Hunting (CTH) Support
1.7.14 Task 14 – Operations Enhancement Support
1.7.15 Task 15 – Office of Professional Responsibility (OPR) Cyber Investigations
(CI) Support
1.7.16 Task 16 – Security Technology & Policy (STP) Support
1.8 Deliverables and Work Products
1.8.1 Deliverables .................................................. Error! Bookmark not defined.
1.8.2 Work Products
1.9 Classification
1.10 Contractor CBP BI Pre-Screening
1.11 Security Requirements
1.11.1 CBP Background Investigation
1.11.2 Additional Clearance Requirements
1.11.3 Identification Badge
1.11.4 Physical and IT Security Requirements
1.11.5 Handling Personally Identifiable Information (PII)
1.12 Organizational Conflict of Interest (OCI)
1.13 Special Considerations
1.13.1 Key Personnel
https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543177 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543178 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543179 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543180 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543181 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543182 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543183 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543184 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543185 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543186 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543187 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543188 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543189 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543190 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543191 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543192 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543193 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543194 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543195 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543195 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543196 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543197 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543198 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543199 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543199 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543200 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543201 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543202 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543203 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543204 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543205 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543206 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543207 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543208 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543209 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543210 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543211 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543212 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543213 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543214
1.13.2 Contractor Personnel Experience, Qualifications, Certifications, Knowledge, and Skills
1.13.3 Government Points of Contact
1.13.4 Technical Direction
1.13.5 Invoice Requirements
1.13.6 Inspection and Acceptance
1.13.7 Contractor Training:
1.14 Unique Standards
1.14.1 CBP Requirements
1.14.2 DHS Enterprise Architecture Compliance
1.14.3 ITP Compliance Language
1.14.4 Section 508 Requirements
1.14.5 ISO Compliance Language for Sensitive but Unclassified Requests
1.14.6 Security Review Terms and Conditions
1.15 Place of Performance, Telework, and Travel
1.16 Period of Performance
Section A : Security Event (Investigation) Categorization Section B : Contractor Qualifications and Certification Requirements Section C: Quality Assurance Surveillance Plan ..... Error! Bookmark not defined.
Section D : Acronyms
2 ATTACHMENT 1 Quality Control Plan ................... Error! Bookmark not defined.
https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543215 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543215 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543216 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543217 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543218 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543219 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543220 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543221 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543222 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543223 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543224 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543225 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543226 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543227 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543228 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543229 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543230 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543231 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543232 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543233 https://cbpgov-my.sharepoint.com/personal/0236084115_cbp_dhs_gov/Documents/Desktop/Working%20Version%20-Task%20Order%20PWS%20.docx#_Toc177543234
1. PERFORMANCE WORK STATEMENT
1.1. Title of Requirement
Cyber Security Operations (SOC) Support Services
1.2. Requiring Organization
Customs and Border Protection (CBP), Enterprise Services (ES), Office of Information and Technology (OIT), and Cyber Security Directorate (CSD)
1.3. Introduction
The cyber landscape is constantly changing. CBP OIT needs an acquisition vehicle that can adapt rapidly to these changes. The purpose of this task order is to provide CBP OIT the capability and flexibility to obtain contractor IT Security Operations Support Services.
1.4 Scope
The scope of this task order includes continuing the Security Operations Support Services work of the contractor in accordance with the Government’s and contractor’s processes, procedures, and schedule to successfully perform the following tasks:
• Program/ Project Management;
• Cyber Defense Forensics (CDF) Support;
• Attack Sensing & Warning (AS&W) Support;
• Cyber Incident Response Team (CIRT) Support;
• Cyber Threat Intelligence (CTI) Support;
• Cyber Risk Management (CRM) Support;
• Security Modernization (SecMod) Support;
• Vulnerability Assessment (VA) Support;
• Security Engineering and Sustainment (SES) Support;
• Enterprise Logging Solution (ELS) Support;
• Development Security Operations (DevSecOps) Support (Optional);
• Information System Security Officer (ISSO) Support;
• Cyber Threat Hunting (CTH) Support;
• Operations Enhancement (OE) Support;
• Office of Professional Responsibility Cyber Investigations (CI) Support; and
• Security Technology & Policy (STP) Support
• Artificial Intelligence (AI) Services
A Project Management Plan is due fifteen (15) business days after the Contractor- Government kickoff meeting. The contractor is fully responsible for all aspects of the work throughout the period of performance.
1.5 Background
The mission of the United States Customs and Border Protection (CBP) is to protect our Nation’s borders from terrorist attacks, to provide law enforcement for over forty (40) Federal agencies, and to protect the revenue of the United States while facilitating trade.
Losing the capability to process, retrieve, and protect electronic data could significantly harm CBP’s ability to accomplish its mission.
The Office of Information and Technology (OIT) is responsible for the design, development, programming, testing, implementation, the IT infrastructure, and maintenance of CBP automated systems and capabilities. These include data centers, cloud, hardware, software, data, video and voice communications, and related financial resources in the support of CBP business processes.
The Cyber Security Directorate (CSD) was established to provide security risk management strategies, consistent with the overall strategic goals and objectives of the Department of Homeland Security (DHS) in carrying out its missions that are applied in a consistent manner across CBP. CSD develops and oversees the strategies designed to preserve the confidentiality, integrity, and availability of the information being processed, stored, or transmitted by CBP systems across the full range of threats.
The CBP Security Operations Center (SOC) was established in accordance with the Federal Information Security Management Act (FISMA) and the Homeland Security Presidential Directive (HSPD) 7 as a single point of management and reporting for information security incidents for CBP. The CBP SOC is chartered to prevent, identify, contain, and eradicate cyber threats to CBP networks through monitoring, intrusion detection, and protective security services to CBP information systems, including local area networks / wide area networks (LAN / WAN), commercial Internet connection, public facing websites, wireless, mobile / cellular, cloud, security devices, servers, and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems and collects, investigates, and reports any suspected and confirmed security violations.
CSD requires a knowledgeable, experienced, and innovative contractor to transition security operations from its current state to an improved state that aligns with the framework of Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, Executive Order (EO) 13800. This includes reducing meantime to detect, incident recovery, and establish applicable metrics. This contractor shall have a strong understanding and be proficient with cloud- based security technologies, architecture, and computing and searching, monitoring, and analyzing machine-generated big data.
1.6 Applicable Documents
• Federal Information Security Modernization Act of 2014, which removed subchapters II and III of Chapter 35, Title 44 USC.
https://www.congress.gov/113/plaws/publ283/PLAW- 113publ283.pdf
• National Institute of Standards and Technology (NIST) Computer Security Resource Center (available at http://csrc.nist.gov/) for the latest editions of NIST computer security publications and the following:
o NIST SP 800-37, Rev 1, “Guide for Applying the Risk Management Framework to Federal Information Systems” o NIST SP 800-53, Rev. 4, “Security and Privacy Controls for Federal Information Systems” http://www.congress.gov/113/plaws/publ283/PLAW-113publ283.pdf http://www.congress.gov/113/plaws/publ283/PLAW-113publ283.pdf http://csrc.nist.gov/
• Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, Executive Order (EO) 13800
• System Reporting Form Standards for Security Categorization of Federal Information and Information Systems (Federal Information Processing Standards (FIPS) 199)
• Continuity of Operations o National Security Presidential Directive-51/Homeland Security Presidential Directive-20 (NSPD-51/HSPD-20) o National Continuity Policy Implementation Plan (NCPIP)
• DHS IT Security Policy documents available at https://www.dhs.gov/dhs-security-and- training-requirements-contractors, which include,:
o DHS Sensitive Systems Policy Directive 4300A and 4300B o DHS 4300A, “Sensitive Systems Handbook” o DHS Management Directive (MD) 11042.1 “Safeguarding
Sensitive But Unclassified (For Official Use Only) Information” o Homeland Security Presidential Directive (HSPD-12), Policies for a Common Identification Standard for Federal Employees and Contractors
• CBP policy documents:
o CBP Information Systems Security Policies and Procedures Handbook, HB 1400- 05D, or current version o CBP Security Policy and Procedures Handbook (HB 1400-02B), August 13, 2009,Volume IV (or current version), Chapter 13, Safeguarding Sensitive but Unclassified (FOUO) Information o CBP Telework Program Directive 51250-020 dated June 18, 2020 o CBP HB 5200-13C, Personal Property and Asset Management Handbook o CBP OIT CSD SOC Standard Operating Procedures (SOPs) o CBP OIT Guidance Memos, Processes and Procedures o NIST Special Publication (SP) 800-37, “Guide for Applying the Risk
Management Framework to Federal Information Systems” o NIST SP 800-53, “Security and Privacy Controls for Federal Information
Systems” o NIST SP 800-53A, “Assessing Security and Privacy Controls in Federal Information
Systems and Organizations: Building Effective Assessment Plans”
Performance Requirements
The contractor shall support CBP in a wide range of Security Operations Support Services to assist CBP in the management, maintenance, and maturing of CBP SOC (24 hours a day, 7 days a week, 365 days a year (24x7x365) to protect the CBP information systems infrastructure. The contractor shall provide skilled and experienced employees to satisfy the tasks identified below. This work will be carried out in the DC Metro area.
https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors
The contractor shall provide coverage / core hours as outlined in the table below. Any alterations to work schedules must be coordinated with the Contracting Officer’s Representative (COR) in writing.
Task Coverage / Core Hours*
On-Call Support 24x7x365
Task 1: Program Management / Project Management 8x5, 8:30am – 5pm (Core Hours) Yes
Task 2: Cyber Defense Forensics (CDF) Support 8x5, 8:30am – 5pm (Core Hours) Yes
Task 3: Attack Sensing & Warning (AS&W) Support 24x7x365 N/A
Task 4: Cyber Incident Response Team (CIRT) Support 24x7x365 N/A
Task 5: Cyber Threat Intelligence (CTI) Support 8x5, 8:30 – 5 pm (Core Hours) Yes
Task 6: Cyber Risk Management (CRM) Support 8x5, 8:30 – 5 pm (Core Hours) No
Task 7: Security Modernization (SecMod) Support 8x5, 8:30 – 5 pm (Core Hours) No
Task 8: Vulnerability Assessment (VA) Support 8x5, 8:30am – 5pm (Core Hours) Yes
Task 9: Security Engineering and Sustainment (SES) Support
8x5, 7am – 7pm (Core Hours) Yes
Task 10: Enterprise Logging Solution (ELS) Support 8x5, 7am – 7pm (Core Hours) Yes
Task 11: Development Security Operations (DevSecOps) Support (Optional)
8x5, 8:30 – 5 pm (Core Hours) No
Task 12: ISSO Support 8x5, 8:30 – 5 pm (Core Hours) No
Task 13: Cyber Threat Hunting (CTH) Support 8x5, 8:30 – 5 pm (Core Hours) Yes
Task 14: Operations Enhancement (OE) Support 8x5, 8:30 – 5 pm (Core Hours) Yes
Task 15: Office of Professional Responsibility Cyber Investigations (CI) Support
8x5, 8:30 – 5 pm (Core Hours) Yes
Task 16: Security Technology & Policy (STP) Support 8x5, 8:30 – 5 pm (Core Hours) No
* Unless otherwise specified by Task Monitor
Security Event Categorization, Prioritization, and Response requirements are outlined and defined within CBP Security Operations Division (SOD) and Security Services Division (SSD) SOPs, DHS 4300A and its Attachments. The DHS ONENET ESOC categorizes events by groups as shown in Attachment A; however, these event groups, categorizations, and examples may change, and the contractor would be expected to adhere to the new naming, priority, and response timelines. Input to all policies and procedures must be developed and maintained in accordance with applicable Federal policies, regulations, directives, and standards including but not limited to the current DHS 4300A Sensitive Systems Policy Directive, DHS 4300A Sensitive Systems Policy Directive, CBP Handbook (HB) 1400-05, Information Systems Security Policies and Procedures Handbook, and National Institute of Standards and Technology (NIST) Special Publications.
Task 1A – 1.7.1.0 Program Management and Project Management (PMO) Support The contractor shall provide Program Management support activities. The contractor shall support objectives to efficiently and effectively manage programs, projects, services, and activities. Support includes, but is not limited to the following:
• Task Order Management
• Compliance with DHS / CBP Mandatory Training Requirements as directed by the
COR. Examples include: CBP Annual Integrity Awareness Training (online), DHS Privacy at DHS – Protecting Personal Information (online), CBP Cyber Security Awareness and Rules of Behavior (online); and CBP Privileged User Training (online).
• Service Delivery Management (e.g., quality assurance)
• Performance and Investment Metric Development o Assist in the development, sustainment, and enhancement of a near-real time CSD PMO agreed upon reporting format
Provide the ability to align all PMO work to the current Cybersecurity Strategy
Track all project milestones, risks & issues, project health, etc.
Leverage existing tools (Jira, Risk Register, MS Power Apps, etc.) to feed near real-time data to CSD PMO agreed upon reporting format o Provide documentation support (e.g., Concept of Operations, metrics, technical writing, etc.) as required.
• Provide meeting minutes for all meeting participants for scheduled meetings, as requested. The meeting minutes shall capture at least the following information: subject, agenda, date, attendees, major decisions, areas of non-agreement, and any action items assigned during the meeting. Minutes must be provided in electronic format in a timely manner, no later than three (3) business days after the conclusion of the meeting, to reflect real time consideration for the actions to be undertaken or issues addressed. A master action item list must be maintained by the Contractor PM.
• Develop STP contractor Federal and Contractor Organizational Chart
• Contractor shall be able to receive and hold at a minimum a T5 investigation or equivalent for the Task 1 PM and/or DPM. CBP CSD may add additional positions at the TS or TS?SCI level on a case by case basis.
Program Management – Task 1B Surge Support (Optional) Throughout the course of performance, it may become necessary to provide additional support to Tasks 1 through 16, depending on severity of cyber security threats impacting the Department.
During such an occurrence, the CO (Contract Officer) or COR may direct the Contractor to provide additional support under the impacted Task. Such support is only allowed with
Government direction and will be billed on a time-and-materials basis. Upon Government request, surge support shall be provided by the contractor within 24 hours with existing staff working longer hours and adjusting schedules contingent on available funding. If additional staff is needed for surge support, the contractor will work to provide additional staff, contingent on the DHS / CBP BI process and available funding. The Contractor will report to the Government daily to determine whether the continued surge support is required. The Contractor will provide time recording during any surge.
1.7.1.1. Task 1C Project Management Office (PMO) Support
The contractor shall support the efficient and effective performance project management of cybersecurity and information technology-based projects (process improvement/automation, technology implementation, execution of proofs of concept/value, new feature requests, and policy/directive development, etc.). This support includes project initiation, planning, execution, monitoring & controlling, and project close out while preforming all roles and responsibilities of project management/project manager.
1.7.1.2. Provide CSD Project Management Office (PMO) support:
• Provide experienced Information Technology Project Managers to facilitate CSD projects.
• Maintain and annually review/update the CSD Project Management Methodology
(CPM2).
• Assist the government in the development and maintenance of a robust CSD PMO SharePoint site that supports the automation of the CPM2 process.
• Make recommendations on the implementation of new tools and technologies that will enhance or generally improve CSD functions and capabilities.
• When requested, support the implementation of these new tools as required.
• Develop and maintain Project Management templates and other project aids, such as checklists, forms, flow charts, etc. that support the CPM2 Process and other project management functions.
• Assist in monitoring and measuring project performance through results driven metrics.
• Provide recommendations on project resourcing.
• Assist the government in the development and maintenance of a formalized CSD PMO training program.
• Assist in the development, sustainment, and enhancement of a near-real time CSD PMO agreed upon reporting format o Provide the ability to align all PMO work to the current Cybersecurity Strategy o Track all project milestones, risks & issues, project health, dependencies, funding, etc.
o Leverage existing tools (Jira, Risk Register, PowerBi, Power Automate, SharePoint, etc.) to feed near real-time data to CSD PMO agreed upon reporting format
• Assist the government in developing CSD strategic planning and roadmap development that aligns with the current cybersecurity strategy.
• Provide documentation support (e.g., Concept of Operations, metrics, technical writing, etc.) as required.
• Assist the Government in developing and maintaining PowerPoint presentations and or SharePoint site content development to support PMO efforts, including graphics development and narrative descriptions of the information being conveyed in the graphics.
• Provide meeting minutes for all meeting participants for scheduled meetings, as requested. The meeting minutes shall capture at least the following information:
subject, agenda, date, attendees, major decisions, areas of non-agreement, and any action items assigned during the meeting. Minutes must be provided in electronic format in a timely manner, no later than three (3) business days after the conclusion of the meeting, to reflect real time consideration for the actions to be undertaken or issues addressed. A master action item list must be maintained by the Contractor PM.
1.7.1.3. Task 1 D Project Management Office (PMO) Support
The contractor shall support the efficient and effective performance project management of cybersecurity and information technology-based projects (process improvement/automation, technology implementation, execution of proofs of concept/value, new feature requests, and policy/directive development, etc.). This support includes project initiation, planning, execution, monitoring & controlling, and project close out while preforming all roles and responsibilities of project management/project manager.
• Provide CSD Project Management Office (PMO) support:
• Provide experienced Information Technology Project Managers to facilitate CSD projects.
• Maintain and annually review/update the CSD Project Management Methodology
(CPM2).
• Assist the government in the development and maintenance of a robust CSD PMO SharePoint site that supports the automation of the CPM2 process.
• Make recommendations on the implementation of new tools and technologies that will enhance or generally improve CSD functions and capabilities.
• When requested, support the implementation of these new tools as required.
• Develop and maintain Project Management templates and other project aids, such as checklists, forms, flow charts, etc. that support the CPM2 Process and other project management functions.
• Assist in monitoring and measuring project performance through results driven metrics.
• Provide recommendations on project resourcing.
• Assist the government in the development and maintenance of a formalized CSD PMO training program.
• Assist in the development, sustainment, and enhancement of a near-real time CSD PMO agreed upon reporting format
• Provide the ability to align all PMO work to the current Cybersecurity Strategy
• Track all project milestones, risks & issues, project health, dependencies, funding, etc.
• Leverage existing tools (Jira, Risk Register, PowerBi, Power Automate, SharePoint, etc.) to feed near real-time data to CSD PMO agreed upon reporting format
• Assist the government in developing CSD strategic planning and roadmap development that aligns with the current cybersecurity strategy.
• Provide documentation support (e.g., Concept of Operations, metrics, technical writing, etc.) as required.
• Assist the Government in developing and maintaining PowerPoint presentations and or SharePoint site content development to support PMO efforts, including graphics development and narrative descriptions of the information being conveyed in the graphics.
• Provide meeting minutes for all meeting participants for scheduled meetings, as requested. The meeting minutes shall capture at least the following information:
subject, agenda, date, attendees, major decisions, areas of non-agreement, and any action items assigned during the meeting. Minutes must be provided in electronic format in a timely manner, no later than three (3) business days after the conclusion of the meeting, to reflect real time consideration for the actions to be undertaken or issues addressed. A master action item list must be maintained by the Contractor PM.
1.7.1.4 Task 1 E Program Control Division (PCD) Mission Support Branch Support The contractor shall manage the tasks listed below in accordance with the attached appendices to support PCD HCM. These tasks shall be reported to the Mission Support Branch Chief and will be monitored by the COR. The HCM Branch Chief will have determination on the acceptance of deliverables that are in keeping with the guidelines set forth.
CSD Staff Box:
The Contractor shall manage the CSD Staff Mailbox by ensuring that the following areas are monitored and supported:
• Weekly Workforce Management Branch (WMB) Report: Referencing the Appendix __ the contractor shall manage the report in keeping with the format as prescribed. The Report is due on the deadline outlined by the HCM Branch Chief and shall be free of any grammatical errors.
• Taskers: The contractor shall manage and monitor the Taskers that come to CSD and ensure compliance from other divisions and ensure the continuity and completeness of the content. The deadline for each tasker will be listed in the task itself. These taskers will be compiled from the various groups and returned to the originating office. These taskers will be managed in the appropriate folder and returned to according the Tasker itself.
• The contractor shall ensure they follow the CSD Tasker standard Operating Procedures (SOP) for guidance on completing the task.
CSD Style Guide The contractor shall create the CSD Style Guide. By utilizing existing guides, the contractor shall utilize what is needed to create the specific guide. Currently, there is an existing 2022 guide and HRM is drafting another guide. This in conjunction with the AMO style guide published in 2023, shall be utilized in the draft process.
Updating CSD SharePoint Sites By referencing the published SharePoint Operations and Maintenance (O&M), the contractor shall perform the following:
• Fix Broken Links: During the course of the period of performance it is common for URLs to need updating if another site CSD links to removes a document or changes content.
• Monitor for grammar and spelling corrections and edits.
• Replace outdated content such as PDF’s, Word docs: The contractor shall refer to the CSD SharePoint O&M Implementation Plan.
• Update ORG charts for CSD as required: The contractor shall maintain all CSD Manager Biographies. To execute this task the contractor shall reference the CSD SharePoint O&M Implementation Plan, and instructions from Mission Support.
Create new and innovative ways to track and manage Mission Support Tasks and Actions. These actions will be requested as required and Ad Hoc.
Task 2 – 1.7.2.1 Cyber Defense Forensics (CDF) Support The contractor shall provide support to the Cyber Defense Forensic team in support of Insider Threat Operations and Security Operations according to established policies, handbooks, and CBP CDF Standard Operating Procedures (SOPs). This support includes monitoring activities, conducting threat analysis, investigating policy violations, identifying mitigation and / or remediation courses of action, and assessing risk posed by trusted insiders.
Support includes, but is not limited to the following:
• Support the Cyber Defense Forensics and Insider Threat investigations through near real- time (when possible, based on tools) monitoring of the Data Loss Prevention (DLP) solutions and other applicable tools.
• Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
• Support Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG) and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
• Conduct enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis in support of Cyber Defense Forensics or Insider Threat investigations.
• Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis.
• Assist with maintaining CBP SOC’s Forensics lab equipment, while also providing recommendations on how to modernize or enhance the lab capability.
• Assist with conducting formal digital forensic investigations and document findings in formal investigation reports.
• Assist with performing email hygiene activities in support of CBP investigations when necessary.
• Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.
• Make recommendation for technical event monitoring policies pertaining to indicators and alerts for Security Information and Event Management (SIEM) System, Network Appliances (e.g., Firewalls, IDS, etc.), Cloud Services, Email, Data Loss Prevention (e.g., CASB, DLP) and Endpoint (e.g., EDR) systems in support of Cyber Defense Forensics.
• Assist with categorizing, prioritizing, and reporting on security events in accordance with CBP CDF SOPs and other relevant policy documents.
• Serve as Subject Matter Experts (SMEs) in the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including, but not limited to, Sensitive but Unclassified (SBU), For Official Use Only (FOUO), Law Enforcement Sensitive (LES), CONFIDENTIAL, SECRET and TOP SECRET information.
• Assist with creating and escalating cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.
• Answer and respond to security events reported via external and /or internal parties via phone calls and group mailboxes.
• Assist with authoring, updating, and modernizing CBP CDF SOPs and Playbooks.
• Manage the lifecycle of CDF investigations from creation to closure in accordance with CBP Policy and Procedures.
• Assist with performing static and dynamic file analysis to identify malware characteristics, intent, and origin.
• Assist with conducting malware analysis and providing Malware Analysis Reports.
• Assist with creating metrics and Key Performance Indicators (KPIs) detailing the operational status and performance of the Cyber Defense Forensics.
• Assist with providing requirements, playbooks, and workflows to support automation of Cyber Defense Forensics tasks.
• Assist with and make recommendations for CBP Zero Trust readiness and architecture for Cyber Defense Forensics (CDF) assigned tasks and pillars.
• Assist with performing antivirus scans on maintenance software files (or other business justified files) prior to use on CBPNet.
• Provide support for the CBP Foreign Travel Service with pre- and post-scans of all CBP laptops and mobile devices before and after a CBP employee’s approved travel. Perform forensics investigation analysis when necessary.
• Provide support for the CBP Separation and File Transfer Scans by identifying any content that may contain FOUO, For Official Use Only, LES, or Law Enforcement Sensitive keywords.
• Provide investigative support for CBP's OPR-Cyber Investigations and Insider Threat Branch for media leak investigations by identifying all users who have received/sent, printed, copied, downloaded/uploaded, or accessed the leaked document.
• Contractor shall be able to receive and hold at a minimum a T5 investigation or equivalent for at a minimum of 1 Ful Time Employee (FTE) for this task.
• CBP may approve additional positions at a TS and / or TS / SCI on a case-by-case basis.
The following work products shall be provided to the government. Future work products may be added to this list upon agreement of the CBP Director of Security Operations, the COR, and the Contractor.
Work Products Due Date Distribution Weekly Report Every Monday, or on the first business day following when Monday is not a business day
CDF Branch Chief, CDF Government Staff
New CDF Monitoring Content
Ad hoc, within 3 business days of Change Request (CR) being approved
TBD
Development of Standard Operating Procedures (SOPs)
Ad hoc, within 15 business days of assignment
CDF Branch Chief, CDF Government Staff
Incident Investigation Notifications / Creation
Ad hoc, in accordance with CBP SOPs
CDF Branch Chief, CDF Government Staff
Event SITREP including Executive Summary and Timeline of Events
Ad hoc, in accordance with CBP SOPs
CDF Branch Chief, CDF Government Staff
Incident Investigation and Case Analysis Report –CDF
Ad hoc, in accordance with CBP SOPs
CDF Branch Chief, CDF Government Staff
Review of CDF Standard Operating Procedures (SOPs)
Biannually, as needed CDF Branch Chief, CDF Government Staff
CDF Security Event Alerts and Information Reporting
Ad hoc, within 1 hour of discovery
CDF Branch Chief, CDF Government Staff
Ad hoc Bridge Calls and Meeting Minutes
Ad hoc, within 1 hour of conclusion of the bridge call
CDF Branch Chief, CDF Government Staff
User Behavior Analysis Report
Ad hoc, in accordance with CBP SOPs
CDF Branch Chief, CDF Government Staff
Malware Reverse Engineering Report
Ad hoc, as needed CDF Branch Chief, CDF Government Staff
Task 3 – 1.7.3.1. Attack Sensing and Warning (AS&W) Support
The contractor shall provide Tier I (monitoring and reporting) and Tier II (analysis) support according to established policies, handbooks, and SOPs. Support includes, but is not limited to the following:
• Support the CBP SOC by providing incident response capabilities per DHS 4300A Sensitive Systems Handbook Attachment F, CBP SOC Incident Response Plan (IRP), and other CBP SOC SOPs.
• Categorize, prioritize, and report on security events in accordance with CBP SOC SOPs and other relevant policies documents.
• Answer and respond to security events reported via external and / or internal parties via phone calls and group mailboxes.
• Support the initial triage of security events to determine the validity of cybersecurity events.
• Draft Commissioner’s Cyber Incident Reports (CCIRs) for government review prior to distribution, meeting all requirements and thresholds defined within the CCIR checklist and playbook documents.
• Support the update of CBP SOC SOPs, ensuring compliance with applicable Federal policies, regulations, directives, and standards including, but not limited to, the current DHS 4300A Sensitive Systems Policy Directive, DHS 4300A Sensitive Systems Policy Directive, CBP HB 1400-05D, Information Systems Security Policies and Procedures Handbook, and NIST Special Publications. CBP SOC SOPs must be reviewed and updated biannually.
• Create and escalate cybersecurity-related investigations to both internal (e.g., CIRT, CDF, etc.) and external entities within CBP, DHS, or other Government Agencies.
• Collaborate with Detection Engineering to configure, implement, update, and maintain alerts in all SOC monitoring tools to identify loss or degradation of monitoring capabilities.
• Support the monitoring of tools and log ingestion to identify any loss or degradation of our monitoring capabilities.
• Support the real-time (when possible, based on tools) monitoring and triaging of security alerts from Security Information and Event Management (SIEM) System, Network Appliances (e.g., Firewalls, IDS, etc.), Cloud Services, Email , Data Loss Prevention (e.g., CASB, DLP) and Endpoint (e.g., EDR) systems in support of SOC operations.
• Compile information required per CBP guidelines for submission and perform risk assessment analysis for Web Access Requests (WARs).
• Triage and support Information / Data Spillage Incident Response efforts and provide recommendations on handling and sanitization methods pursuant to appropriate SOPs.
• Support the development of meaningful metrics and KPIs detailing the operational status and performance of the Security Operations Center.
• Assist with supporting OPR, OI, OIG, and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or criminal intent.
• Assist with the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including, but not limited to, SBU, FOUO, LES, CONFIDENTIAL, SECRET, and TOP SECRET information.
• Provide suggestions and recommendations to improve logging and monitoring of CBP assets.
• Make security content recommendations to include new signatures, signature modifications, signature removals (e.g., SIEM, EDR, IDS).
The following work products shall be provided to the Government. Future work products may be added to this list upon agreement by the CBP SOD Director, the COR, CO, and the contractor.
Work Products
Due Date Distribution
Daily Call w/
DHS HQ
NOSC
0900 EST unless changed to a new time in the future.
CBP SOD
Government Staff, CBP SOD
Government Leads
Daily SOC Report
0600 EST Monday – Friday
CBP SOD
Government Staff, AS&W Government Lead, CBP SOD Director, CBP
CISO
Shift Pass-down Reports
At the end of each shift CBP SOD Government Staff, AS&W Government Lead, CIRT Government Lead, Task 3 and 4 personnel
CBP SOC
Weekly Report
Every Monday, or on the first business day following when Monday is a Federal Holiday
CBP SOD
Government Staff, AS&W Government Lead, and CBP SOD Director
Assist in creating the
CBP SOC
Monthly Report
Within five (5) calendar days following the end of each month
CBP SOD
Government Staff, AS&W Government Lead, and CBP SOD Director
Security Event Alerts and Information Reporting
Ad hoc, within 1 business day of discovery
AS&W Government Lead, CBP SOD Government Staff
Creation of Investigation Reporting or Incidents in Case Management System
Ad hoc, in accordance with CBP SOD SOPs and DHS 4300A Attachment F
AS&W Government Lead and CBP SOD Government Staff
SOP Updates Biannually, as needed AS&W Government Lead, & CBP SOD Government Staff
Ad hoc Bridge Calls and Meeting Minutes
Ad hoc, within 1 hour of conclusion of the bridge call
AS&W Government Lead, CBP SOD Government staff, and SOD Director
Due Date Distribution
Commissioner’ s Cyber Incident Report
Within required time frames defined in CCIR checklist
CBP SOD
Government Staff, AS&W Government Lead, CBP SOD Director, CBP
CISO
Task 4 – 1.7.4.1 Cyber Incident Response Team (CIRT) Support
The contractor shall provide support to CBP SOC in support of computer-related cybersecurity incidents and cybersecurity reporting. Requirements include, but are not limited to the following:
• Support the CBP SOC by providing incident response capabilities per DHS 4300A Sensitive Systems Handbook Attachment F, CBP SOC Incident Response Plan (IRP), CBP SOC AS&W and IR SOP, and other CBP SOC Playbooks and workflows.
• Assist with conducting risk assessment analysis for WARs.
• Provide support to the investigation leads during investigations while also managing the lifecycle of all CBP SOC investigations from creation to closure supporting misuse and information spillage as necessary.
• Make security content (e.g., SIEM, EDR, IDS) recommendations to include new signatures, signature modifications, signature removals, and incorporate Indicators of Compromise (IOCs) from internal and external sources to improve security posture and mitigate cyber threats.
• Assist with advanced analysis of data file system artifacts, memory, and advanced Network and Log analysis during incidents to detect, investigate, scope, and contain compromises on Windows, Linux, Mac, and / or Cloud Environments such as AWS, Azure, and others.
• Collaborate to identify requirements, playbooks, and workflows to support automation of Incident Response tasks.
• Assist with development and updates of CBP SOC SOPs, in accordance with applicable Federal policies, regulations, directives, and standards including, but not limited to, the current DHS 4300A Sensitive Systems Policy Directive, DHS 4300A Sensitive Systems Policy Directive, CBP HB 1400-05D, Information Systems Security Policies and Procedures Handbook, and NIST Special Publications. CBP SOC SOPs must be reviewed and updated biannually.
• Assist with generating formal incident investigation reports per CBP SOC SOPs and at the direction of CBP SOD government staff.
• Collaborate with government analysts to provide post-incident recommendations for improving security posture based upon the results of an investigation.
• Support and manage Information / Data Spillage Incident Response efforts and provide recommendations on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
• Assist with conducting email trace and purge functions.
• The contractor shall be able to receive and hold at a minimum a T5 investigation or equivalent for at least 2 FTEs.
The following work products shall be provided to the Government. Future work products may be added to this list upon agreement between the CBP SOD Director, the COR, CO, and the contractor.
Due Date Distribution
New Security Content
Ad hoc, within 3 business days of request
CBP SOC Leads and CTI Team
SOP Creation Ad hoc, in accordance with CBP SOPs
CBP SOC Leads and CTI Team
Standard Operating Procedures
(SOP)
Updates
Biannually, as needed CBP SOC Leads and CTI Team
Analysis of Threat Data Report
Ad hoc, within 3 business days of request
CBP SOC Leads and CTI Team
Situational, Incident- Related Reports
Ad hoc, within 3 business days of request
CBP SOC Leads and CTI Team
Special Cyber Threat Analysis Report
Ad hoc, within 5 business days of request
CBP SOC Leads and CTI Team
Threat Briefings
Ad hoc, within 1 business day of request
CBP SOC Leads and CTI Team
Task 5 – 1.7.5.1. Cyber Threat Intelligence (CTI) Support
The contractor shall conduct Cyber Threat Intelligence (CTI) support. This support includes monitoring activities, developing cyber threat analysis, identifying mitigation and / or remediation courses of action, sharing actionable cyber threat intelligence used in organizational IT asset protection, trending strategic cyber threats, and situational awareness. Support includes but is not limited to the following:
• Assist the CBP Security Operations Center (SOC) with identifying valid Indicators of Compromise (IOCs) and implementing appropriate monitoring, alerting, or blocking.
• Assist the CBP SOC with cyber investigations by providing threat intelligence, research, and artifacts on IOCs, personas, and Advanced Persistent Threat (APT) attribution.
• Assist with development and contributions to internal and external cyber threat intelligence products for distribution to Federal Partners over classified and unclassified communication networks.
•…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .