SOC PWS Draft Rev1_022525.pdf

PDF 1 MB Posted

Attached to
Security Operations Support Services Federal contract opportunity
Solicitation number
20146850
Issued by
Department of Homeland Security Customs and Border Protection

About this file

This Performance Work Statement (PWS) details a comprehensive cybersecurity support services contract for U.S. Customs and Border Protection (CBP) by the Office of Information and Technology's Cyber Security Directorate. The nine-month base period contract ($24 September 2024 - 23 June 2025) seeks a contractor to provide 16 distinct task areas including Program Management, Cyber Defense Forensics, Attack Sensing & Warning, Incident Response, Threat Intelligence, Risk Management, Security Modernization, Vulnerability Assessment, Security Engineering, Enterprise Logging Solution, DevSecOps, Information Systems Security Officer support, Threat Hunting, Operations Enhancement, Professional Responsibility Cyber Investigations, and Security Technology & Policy support.

Key contractual requirements include providing skilled cybersecurity personnel with specific experience and certification levels, maintaining 24x7x365 security operations capabilities, supporting CBP's transition toward Zero Trust Architecture, and delivering comprehensive security monitoring, threat detection, incident response, and risk management services. The contract mandates strict security clearance requirements, with some positions requiring Top Secret/Sensitive Compartmented Information clearance, and emphasizes supporting CBP's mission of protecting national borders through advanced cybersecurity capabilities. Contractor personnel must have extensive technical expertise in network security, incident response, forensics, threat intelligence, and related cybersecurity disciplines.

View the file

Other files for this federal contract opportunity

Other files attached to Security Operations Support Services, newest first.
File Type Posted
CBP SOC RFI QA responses V7_040825.pdf PDF
RFI_Draft PWS SOC 040125 v2.pdf PDF
RFI Instructions for Security Operations Support Services .pdf PDF
CBP CSD SOC Support Services RFI 032025.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Customs and Border Protection (CBP) Enterprise Services (ES) Office of Information and Technology (OIT) Cyber Security

Directorate (CSD)

Performance Work Statement (PWS) For

Security Operations Support Services

DATE 2/20/2025

Table of Contents

1 PERFORMANCE WORK STATEMENT

1.1 Title of Requirement

1.2 Requiring Organization

1.3 Introduction

1.4 Scope

1.5 Background

1.6 Applicable Documents

1.7 Performance Requirements

1.7.1 Task 1 – Program / Project Management

1.7.2 Task 2 – Cyber Defense Forensics (CDF) Support

1.7.3 Task 3 – Attack Sensing and Warning (AS&W) Support

1.7.4 Task 4 – Cyber Incident Response Team (CIRT) Support

1.7.5 Task 5 – Cyber Threat Intelligence (CTI) Support

1.7.6 Task 6 – Cyber Risk Management (CRM) Support

1.7.7 Task 7 – Security Modernization (SecMod) Support

1.7.8 Task 8 – Vulnerability Assessment (VA) Support

1.7.9 Task 9 – Security Engineering and Sustainment (SES) Support

1.7.10 Task 10 - Enterprise Logging Solution (ELS) Support

1.7.11 Task 11 - Development Security Operations (DevSecOps) Support (Optional) .

1.7.12 Task 12 - Information Systems Security Officer (ISSO) Support

1.7.13 Task 13 – Cyber Threat Hunting (CTH) Support

1.7.14 Task 14 – Operations Enhancement Support

1.7.15 Task 15 – Office of Professional Responsibility (OPR) Cyber Investigations

(CI) Support

1.7.16 Task 16 – Security Technology & Policy (STP) Support

1.8 Deliverables and Work Products

1.8.1 Deliverables

1.8.2 Work Products

1.9 Classification

1.10 Contractor CBP BI Pre-Screening

1.11 Security Requirements

1.11.1 CBP Background Investigation

1.11.2 Additional Clearance Requirements

1.11.3 Identification Badge

1.11.4 Physical and IT Security Requirements

1.11.5 Handling Personally Identifiable Information (PII)

1.12 Organizational Conflict of Interest (OCI)

1.13 Special Considerations

1.13.1 Key Personnel

1.13.2 Contractor Personnel Experience, Qualifications, Certifications, Knowledge, and Skills

1.13.3 Government Points of Contact

1.13.4 Technical Direction

1.13.5 Invoice Requirements

1.13.6 Inspection and Acceptance

1.13.7 Contractor Training

1.14 Unique Standards

1.14.1 CBP Requirements

1.14.2 DHS Enterprise Architecture Compliance

1.14.3 ITP Compliance Language

1.14.4 Section 508 Requirements

1.14.5 ISO Compliance Language for Sensitive but Unclassified Requests

1.14.6 Security Review Terms and Conditions

1.15 Place of Performance, Telework, and Travel

1.16 Period of Performance

Section A : Security Event (Investigation) Categorization Section B : Contractor Qualifications and Certification Requirements Section C: Quality Assurance Surveillance Plan Section D : Acronyms

2 ATTACHMENT 1 Quality Control Plan

1 PERFORMANCE WORK STATEMENT

1.1 Title of Requirement

Cyber Security Operations Support Services

1.2 Requiring Organization

Customs and Border Protection (CBP), Enterprise Services (ES), Office of Information and Technology (OIT), and Cyber Security Directorate (CSD)

1.3 Introduction

The cyber landscape is constantly changing. CBP OIT needs an acquisition vehicle that can adapt rapidly to these changes. The purpose of this task order is to provide CBP OIT the capability and flexibility to obtain contractor IT Security Operations Support Services.

1.4 Scope

The scope of this task order includes continuing the Security Operations Support Services work of the incumbent contractor in accordance with the Government’s and contractor’s processes, procedures, and schedule to successfully perform the following tasks:

• Program Management / Project Management;

• Cyber Defense Forensics (CDF) Support;

• Attack Sensing & Warning (AS&W) Support;

• Cyber Incident Response Team (CIRT) Support;

• Cyber Threat Intelligence (CTI) Support;

• Cyber Risk Management (CRM) Support;

• Security Modernization (SecMod) Support;

• Vulnerability Assessment (VA) Support;

• Security Engineering and Sustainment (SES) Support;

• Enterprise Logging Solution (ELS) Support;

• Development Security Operations (DevSecOps) Support (Optional);

• Information System Security Officer (ISSO) Support;

• Cyber Threat Hunting (CTH) Support;

• Operations Enhancement (OE) Support;

• Office of Professional Responsibility Cyber Investigations (CI) Support; and

• Security Technology & Policy (STP) Support

A Project Management Plan is due fifteen (15) business days after the Contractor- Government kickoff meeting. The contractor is fully responsible for all aspects of the work throughout the period of performance.

1.5 Background

The mission of the United States Customs and Border Protection (CBP) is to protect our Nation’s borders from terrorist attacks, to provide law enforcement for over forty (40) Federal agencies, and to protect the revenue of the United States while facilitating trade.

Losing the capability to process, retrieve, and protect electronic data could significantly harm CBP’s ability to accomplish its mission.

The Office of Information and Technology (OIT) is responsible for the design, development, programming, testing, implementation, the IT infrastructure, and maintenance of CBP automated systems and capabilities. These include data centers, cloud, hardware, software, data, video and voice communications, and related financial resources in the support of CBP business processes.

The Cyber Security Directorate (CSD) was established to provide security risk management strategies, consistent with the overall strategic goals and objectives of the Department of Homeland Security (DHS) in carrying out its missions that are applied in a consistent manner across CBP. CSD develops and oversees the strategies designed to preserve the confidentiality, integrity, and availability of the information being processed, stored, or transmitted by CBP systems across the full range of threats.

The CBP Security Operations Center (SOC) was established in accordance with the Federal Information Security Management Act (FISMA) and the Homeland Security Presidential Directive (HSPD) 7 as a single point of management and reporting for information security incidents for CBP. The CBP SOC is chartered to prevent, identify, contain, and eradicate cyber threats to CBP networks through monitoring, intrusion detection, and protective security services to CBP information systems, including local area networks / wide area networks (LAN / WAN), commercial Internet connection, public facing websites, wireless, mobile / cellular, cloud, security devices, servers, and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems and collects, investigates, and reports any suspected and confirmed security violations.

CSD requires a knowledgeable, experienced, and innovative contractor to transition security operations from its current state to an improved state that aligns with the framework of Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, Executive Order (EO) 13800. This includes reducing meantime to detect, incident recovery, and establish applicable metrics. This contractor shall have a strong understanding and be proficient with cloud- based security technologies, architecture, and computing and searching, monitoring, and analyzing machine-generated big data.

1.6 Applicable Documents

• Federal Information Security Modernization Act of 2014, which removed subchapters II and III of Chapter 35, Title 44 USC.

https://www.congress.gov/113/plaws/publ283/PLAW- 113publ283.pdf

• National Institute of Standards and Technology (NIST) Computer Security Resource Center (available at http://csrc.nist.gov/) for the latest editions of NIST computer security publications and the following:

o NIST SP 800-37, Rev 1, “Guide for Applying the Risk Management Framework to Federal Information Systems” o NIST SP 800-53, Rev. 4, “Security and Privacy Controls for Federal Information Systems”

• Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, Executive Order (EO) 13800

• System Reporting Form Standards for Security Categorization of Federal Information and Information Systems (Federal Information Processing Standards (FIPS) 199)

• Continuity of Operations o National Security Presidential Directive-51/Homeland

Security Presidential Directive-20 (NSPD-51/HSPD-20) o National Continuity Policy Implementation Plan (NCPIP)

• DHS IT Security Policy documents available at https://www.dhs.gov/dhs-security-and- training-requirements-contractors, which include,:

o DHS Sensitive Systems Policy Directive 4300A and 4300B o DHS 4300A, “Sensitive Systems Handbook” o DHS Management Directive (MD) 11042.1

“Safeguarding Sensitive But Unclassified (For Official Use Only) Information” o Homeland Security Presidential Directive (HSPD-12), Policies for a Common Identification Standard for Federal Employees and Contractors

• CBP policy documents:

o CBP Information Systems Security Policies and Procedures

Handbook, HB 1400- 05D, or current version o CBP Security Policy and Procedures Handbook (HB 1400-

02B), August 13, 2009,Volume IV (or current version), Chapter 13, Safeguarding Sensitive but Unclassified (FOUO) Information o CBP Telework Program Directive 51250-020 dated June 18, 2020 http://www.congress.gov/113/plaws/publ283/PLAW-113publ283.pdf http://www.congress.gov/113/plaws/publ283/PLAW-113publ283.pdf http://csrc.nist.gov/ https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors https://www.dhs.gov/dhs-security-and-training-requirements-contractors o CBP HB 5200-13C, Personal Property and Asset Management Handbook o CBP OIT CSD SOC Standard Operating Procedures (SOPs) o CBP OIT Guidance Memos, Processes and Procedures

1.7 Performance Requirements

The contractor shall support CBP in a wide range of Security Operations Support Services to assist CBP in the management, maintenance, and maturing of CBP SOC (24 hours a day, 7 days a week, 365 days a year (24x7x365) to protect the CBP information systems infrastructure. The contractor shall provide skilled and experienced employees to satisfy the tasks identified below.

Specific contractor qualifications and certification requirements are outlined by task in Attachment B – Contractor Qualifications and Certification Requirements.

Performance metrics are outlined in Attachment C – Quality Assurance Surveillance Plan

(QASP).

The contractor shall provide coverage / core hours as outlined in the table below. Any alterations to work schedules must be coordinated with the Contracting Officer’s Representative (COR) in writing.

Task Coverage / Core Hours* On-Call

Support 24x7x365

Task 1: Program Management / Project Management 8x5, 8:30am – 5pm (Core Hours)

Yes

Task 2: Cyber Defense Forensics (CDF) Support 8x5, 8:30am – 5pm (Core Hours)

Yes

Task 3: Attack Sensing & Warning (AS&W) Support

24x7x365 N/A

Task 4: Cyber Incident Response Team (CIRT) Support

24x7x365 N/A

Task 5: Cyber Threat Intelligence (CTI) Support 8x5, 8:30 – 5 pm (Core Hours) Yes

Task 6: Cyber Risk Management (CRM) Support 8x5, 8:30 – 5 pm (Core Hours) No Task 7: Security Modernization (SecMod) Support 8x5, 8:30 – 5 pm (Core Hours) No

Task 8: Vulnerability Assessment (VA) Support 8x5, 8:30am – 5pm (Core Hours)

Yes

Task 9: Security Engineering and Sustainment (SES) Support

8x5, 7am – 7pm (Core Hours) Yes

Task 10: Enterprise Logging Solution (ELS) Support

8x5, 7am – 7pm (Core Hours) Yes

Task 11: Development Security Operations (DevSecOps) Support (Optional)

8x5, 8:30 – 5 pm (Core Hours) No

Task 12: ISSO Support 8x5, 8:30 – 5 pm (Core Hours) No Task 13: Cyber Threat Hunting (CTH) Support 8x5, 8:30 – 5 pm (Core Hours) Yes Task 14: Operations Enhancement (OE) Support 8x5, 8:30 – 5 pm (Core Hours) Yes Task 15: Office of Professional Responsibility Cyber Investigations (CI) Support

8x5, 8:30 – 5 pm (Core Hours) Yes

Task Coverage / Core Hours* On-Call Support 24x7x365

Task 16: Security Technology & Policy (STP) Support

8x5, 8:30 – 5 pm (Core Hours) No

* unless otherwise specified by Task Monitor

Security Event Categorization, Prioritization, and Response requirements are outlined and defined within CBP Security Operations Division (SOD) and Security Services Division (SSD) SOPs, DHS 4300A and its Attachments. The DHS ONENET ESOC categorizes events by groups as shown in Attachment A; however, these event groups, categorizations, and examples may change and the contractor would be expected to adhere to the new naming, priority, and response timelines. Input to all policies and procedures must be developed and maintained in accordance with applicable Federal policies, regulations, directives, and standards including but not limited to the current DHS 4300A Sensitive Systems Policy Directive, DHS 4300A Sensitive Systems Policy Directive, CBP Handbook (HB) 1400-05, Information Systems Security Policies and Procedures Handbook, and National Institute of Standards and Technology (NIST) Special Publications.

1.7.1 Task 1 – Program / Project Management

The contractor shall provide Program Management support activities. The contractor shall support objectives to efficiently and effectively manage programs, projects, services, and activities. Support includes, but is not limited to the following:

• Task Order Management

• Compliance with DHS / CBP Mandatory Training Requirements as directed by the COR. Examples include: CBP Annual Integrity Awareness Training (online), DHS Privacy at DHS – Protecting Personal Information (online), CBP Cyber Security Awareness and Rules of Behavior (online); and CBP Privileged User Training (online).

• Service Delivery Management (e.g., quality assurance)

• Performance and Investment Metric Development

• Provide CSD Project Management Office (PMO) support:

o Provide experienced Project Managers to facilitate CSD projects.

o Maintain the Project Management collaboration sites.

o Maintain and annually review/update the CSD Project Management

Methodology.

o Make recommendations on the implementation of new tools and technologies that will enhance or generally improve CSD functions and capabilities.

o When requested, support the implementation of these new tools as required.

o Develop and maintain Project Management templates and other project aids, such as checklists, forms, flow charts, etc.

o Assist in monitoring and measuring project performance.

o Provide recommendations on project resourcing.

o Maintain the Project Management training plan.

o Assist in the development, sustainment, and enhancement of a near-real time

CSD PMO agreed upon reporting format Provide the ability to align all PMO work to the current

Cybersecurity Strategy Track all project milestones, risks & issues, project health, etc.

Leverage existing tools (Jira, Risk Register, MS Power Apps, etc.)

to feed near real-time data to CSD PMO agreed upon reporting format

• Provide documentation support (e.g., Concept of Operations, metrics, technical writing, etc.) as required.

• Provide meeting minutes for all meeting participants for scheduled meetings, as requested. The meeting minutes shall capture at least the following information: subject, agenda, date, attendees, major decisions, areas of non-agreement, and any action items assigned during the meeting.

Minutes must be provided in electronic format in a timely manner, no later than three (3) business days after the conclusion of the meeting, to reflect real time consideration for the actions to be undertaken or issues addressed.

A master action item list must be maintained by the Contractor PM.

1.7.1.1 Task 1A – Surge Support (Optional)

Throughout the course of performance, it may become necessary to provide additional support to Tasks 1 through 16, depending on severity of cyber security threats impacting the Department.

During such an occurrence, the CO (Contract Officer) or COR may direct the Contractor to provide additional support under the impacted Task. Such support is only allowed with Government direction and will be billed on a time-and-materials basis. Upon Government request, surge support shall be provided by the contractor within 24 hours with existing staff working longer hours and adjusting schedules contingent on available funding. If additional staff is needed for surge support, the contractor will work to provide additional staff, contingent on the DHS / CBP BI process and available funding.

The Contractor will report to the Government daily to determine whether the continued surge support is required. The Contractor will provide time recording during any surge.

1.7.2 Task 2 – Cyber Defense Forensics (CDF) Support

The contractor shall provide support to the Cyber Defense Forensic team in support of Insider Threat Operations and Security Operations according to established policies, handbooks, and CBP CDF Standard Operating Procedures (SOPs). This support includes monitoring activities, conducting threat analysis, investigating policy violations, identifying mitigation and / or remediation courses of action, and assessing risk posed by trusted insiders.

Support includes, but is not limited to the following:

• Support the Cyber Defense Forensics and Insider Threat investigations through near real- time (when possible, based on tools) monitoring of the Data Loss Prevention (DLP) solutions and other applicable tools.

• Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.

• Support Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG) and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.

• Conduct enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis in support of Cyber Defense Forensics or Insider Threat investigations.

• Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis.

• Assist with maintaining CBP SOC’s Forensics lab equipment, while also providing recommendations on how to modernize or enhance the lab capability.

• Assist with conducting formal digital forensic investigations and document findings in formal investigation reports.

• Assist with performing email hygiene activities in support of CBP investigations when necessary.

• Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.

• Make recommendation for technical event monitoring policies pertaining to indicators and alerts for Security Information and Event Management (SIEM) System, Network Appliances (e.g., Firewalls, IDS, etc.), Cloud Services, Email, Data Loss Prevention (e.g., CASB, DLP) and Endpoint (e.g., EDR) systems in support of Cyber Defense Forensics.

• Assist with categorizing, prioritizing, and reporting on security events in accordance with CBP CDF SOPs and other relevant policy documents.

• Serve as Subject Matter Experts (SMEs) in the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including, but not limited to, Sensitive But Unclassified (SBU), For Official Use Only (FOUO), Law Enforcement Sensitive (LES), CONFIDENTIAL, SECRET and TOP SECRET information.

• Assist with creating and escalating cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.

• Answer and respond to security events reported via external and /or internal parties via phone calls and group mailboxes.

• Assist with authoring, updating, and modernizing CBP CDF SOPs and Playbooks.

• Manage the lifecycle of CDF investigations from creation to closure in accordance with CBP Policy and Procedures.

• Assist with performing static and dynamic file analysis to identify malware characteristics, intent, and origin.

• Assist with conducting malware analysis and providing Malware Analysis Reports.

• Assist with creating metrics and Key Performance Indicators (KPIs) detailing the operational status and performance of the Cyber Defense Forensics.

• Assist with providing requirements, playbooks, and workflows to support automation of Cyber Defense Forensics tasks.

• Assist with and make recommendations for CBP Zero Trust readiness and architecture for Cyber Defense Forensics (CDF) assigned tasks and pillars.

• Assist with performing antivirus scans on maintenance software files (or other business justified files) prior to use on CBPNet.

• Provide support for the CBP Foreign Travel Service with pre- and post-scans of all CBP laptops and mobile devices before and after a CBP employee’s approved travel. Perform forensics investigation analysis when necessary.

• Provide support for the CBP Separation and File Transfer Scans by identifying any content that may contain FOUO, For Official Use Only, LES, or Law Enforcement Sensitive keywords.

• Provide investigative support for CBP's OPR-Cyber Investigations and Insider Threat Branch for media leak investigations by identifying all users who have received/sent, printed, copied, downloaded/uploaded, or accessed the leaked document.

The following work products shall be provided to the government. Future work products may be added to this list upon agreement of the CBP Director of Security Operations, the COR, and the Contractor.

Work Products Due Date Distribution Weekly Report Every Monday, or on the first business day following when Monday is not a business day

CDF Branch Chief, CDF Government Staff

New CDF Monitoring Content

Ad hoc, within 3 business days of Change Request (CR) being approved

TBD

Development of Standard Operating Procedures (SOPs)

Ad hoc, within 15 business days of assignment

CDF Branch Chief, CDF Government Staff

Incident Investigation Notifications / Creation

Ad hoc, in accordance with CBP SOPs

CDF Branch Chief, CDF Government Staff

Event SITREP including Executive Summary and Timeline of Events

Ad hoc, in accordance with CBP SOPs

CDF Branch Chief, CDF Government Staff

Incident Investigation and Case Analysis Report –CDF

Ad hoc, in accordance with CBP SOPs

CDF Branch Chief, CDF Government Staff

Review of CDF Standard Operating Procedures (SOPs)

Biannually, as needed CDF Branch Chief, CDF Government Staff

CDF Security Event Alerts and Information Reporting

Ad hoc, within 1 hour of discovery

CDF Branch Chief, CDF Government Staff

Ad hoc Bridge Calls and Meeting Minutes

Ad hoc, within 1 hour of conclusion of the bridge call

CDF Branch Chief, CDF Government Staff

User Behavior Analysis Report

Ad hoc, in accordance with CBP SOPs

CDF Branch Chief, CDF Government Staff

Malware Reverse Engineering Report

Ad hoc, as needed CDF Branch Chief, CDF Government Staff

1.7.3 Task 3 – Attack Sensing and Warning (AS&W) Support

The contractor shall provide Tier I (monitoring and reporting) and Tier II (analysis) support according to established policies, handbooks, and SOPs. Support includes, but is not limited to the following:

• Support the CBP SOC by providing incident response capabilities per DHS 4300A Sensitive Systems Handbook Attachment F, CBP SOC Incident Response Plan (IRP), and other CBP SOC SOPs.

• Categorize, prioritize, and report on security events in accordance with CBP SOC SOPs and other relevant policies documents.

• Answer and respond to security events reported via external and / or internal parties via phone calls and group mailboxes.

• Support the initial triage of security events to determine the validity of cybersecurity events.

• Draft Commissioner’s Cyber Incident Reports (CCIRs) for government review prior to distribution, meeting all requirements and thresholds defined within the CCIR checklist and playbook documents.

• Support the update of CBP SOC SOPs, ensuring compliance with applicable Federal policies, regulations, directives, and standards including, but not limited to, the current DHS 4300A Sensitive Systems Policy Directive, DHS 4300A Sensitive Systems Policy Directive, CBP HB 1400-05D, Information Systems Security Policies and Procedures Handbook, and NIST Special Publications. CBP SOC SOPs must be reviewed and updated biannually.

• Create and escalate cybersecurity-related investigations to both internal (e.g., CIRT, CDF, etc.) and external entities within CBP, DHS, or other Government Agencies.

• Collaborate with Detection Engineering to configure, implement, update, and maintain alerts in all SOC monitoring tools to identify loss or degradation of monitoring capabilities.

• Support the monitoring of tools and log ingestion to identify any loss or degradation of our monitoring capabilities.

• Support the real-time (when possible, based on tools) monitoring and triaging of security alerts from Security Information and Event Management (SIEM) System, Network Appliances (e.g., Firewalls, IDS, etc.), Cloud Services , Email , Data Loss Prevention (e.g., CASB, DLP) and Endpoint (e.g., EDR) systems in support of SOC operations.

• Compile information required per CBP guidelines for submission and perform risk assessment analysis for Web Access Requests (WARs).

• Triage and support Information / Data Spillage Incident Response efforts and provide recommendations on handling and sanitization methods pursuant to appropriate SOPs.

• Support the development of meaningful metrics and KPIs detailing the operational status and performance of the Security Operations Center.

• Assist with supporting OPR, OI, OIG, and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or criminal intent.

• Assist with the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including, but not limited to, SBU, FOUO, LES, CONFIDENTIAL, SECRET, and TOP SECRET information.

• Provide suggestions and recommendations to improve logging and monitoring of CBP assets.

• Make security content recommendations to include new signatures, signature modifications, signature removals (e.g., SIEM, EDR, IDS).

The following work products shall be provided to the Government. Future work products may be added to this list upon agreement by the CBP SOD Director, the COR, CO, and the contractor.

Daily Call w/ DHS HQ

NOSC

0900 EST unless changed to a new time in the future.

CBP SOD Government Staff, CBP SOD Government Leads

Daily SOC Report 0600 EST Monday – Friday CBP SOD Government Staff, AS&W Government Lead, CBP SOD Director, CBP

CISO

Shift Pass-down Reports At the end of each shift CBP SOD Government Staff, AS&W Government Lead, CIRT Government Lead, Task 3 and 4 personnel

CBP SOC Weekly Report Every Monday, or on the first business day following when Monday is a Federal Holiday

CBP SOD Government Staff, AS&W Government Lead, and CBP SOD Director

Assist in creating the CBP SOC Monthly Report

Within five (5) calendar days following the end of each month

CBP SOD Government Staff, AS&W Government Lead, and CBP SOD Director

Security Event Alerts and Information Reporting

Ad hoc, within 1 business day of discovery

AS&W Government Lead, CBP SOD Government Staff

Creation of Investigation Reporting or Incidents in Case Management System

Ad hoc, in accordance with CBP SOD SOPs and DHS 4300A Attachment F

AS&W Government Lead and CBP SOD Government Staff

SOP Updates Biannually, as needed AS&W Government Lead, & CBP SOD Government Staff

Ad hoc Bridge Calls and Meeting Minutes

Ad hoc, within 1 hour of conclusion of the bridge call

AS&W Government Lead, CBP SOD Government staff, and SOD Director

Commissioner’s Cyber Incident Report

Within required time frames defined in CCIR checklist

CBP SOD Government Staff, AS&W Government Lead, CBP SOD Director, CBP

CISO

1.7.4 Task 4 – Cyber Incident Response Team (CIRT) Support

The contractor shall provide support to CBP SOC in support of computer-related cybersecurity incidents and cybersecurity reporting. Requirements include, but are not limited to the following:

• Support the CBP SOC by providing incident response capabilities per DHS 4300A Sensitive Systems Handbook Attachment F, CBP SOC Incident Response Plan (IRP), CBP SOC AS&W and IR SOP, and other CBP SOC Playbooks and workflows.

• Assist with conducting risk assessment analysis for WARs.

• Provide support to the investigation leads during investigations while also managing the lifecycle of all CBP SOC investigations from creation to closure supporting misuse and information spillage as necessary.

• Make security content (e.g., SIEM, EDR, IDS) recommendations to include new signatures, signature modifications, signature removals, and incorporate Indicators of Compromise (IOCs) from internal and external sources to improve security posture and mitigate cyber threats.

• Assist with advanced analysis of data file system artifacts, memory, and advanced Network and Log analysis during incidents to detect, investigate, scope, and contain compromises on Windows, Linux, Mac, and / or Cloud Environments such as AWS, Azure, and others.

• Collaborate to identify requirements, playbooks, and workflows to support automation of Incident Response tasks.

• Assist with development and updates of CBP SOC SOPs, in accordance with applicable Federal policies, regulations, directives, and standards including, but not limited to, the current DHS 4300A Sensitive Systems Policy Directive, DHS 4300A Sensitive Systems Policy Directive, CBP HB 1400-05D, Information Systems Security Policies and Procedures Handbook, and NIST Special Publications. CBP SOC SOPs must be reviewed and updated biannually.

• Assist with generating formal incident investigation reports per CBP SOC SOPs and at the direction of CBP SOD government staff.

• Collaborate with government analysts to provide post-incident recommendations for improving security posture based upon the results of an investigation.

• Support and manage Information / Data Spillage Incident Response efforts and provide recommendations on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.

• Assist with conducting email trace and purge functions.

The following work products shall be provided to the Government. Future work products may be added to this list upon agreement between the CBP SOD Director, the COR, CO, and the contractor.

Incident Investigation and Case Analysis Report w/ Comprehensive Findings and Recommendations

Ad hoc, in accordance with CBP SOC SOPs

CBP SOD Government Staff, CIRT Government Lead, CBP SOD Director

SOP Creation / Written Instruction

Ad hoc, in accordance with CBP SOD SOPs

CBP SOD Government Staff, CIRT Government Lead

Executive Summary of Security Events and Incidents

Ad hoc, in accordance with CBP SOD SOPs

DHS, CBP OPR, CBP OIT,

CBP CSD personnel in accordance with CBP SOC SOPs

Timeline of Events (Relative to Security Events and Incidents)

Ad hoc, in accordance with CBP SOD SOPs

DHS, CBP OPR, CBP OIT,

CBP CSD personnel in accordance with CBP SOC SOPs

Final Investigative Summary Ad hoc, in accordance with CBP SOD SOPs

DHS, CBP OPR, CBP OIT,

CBP CSD personnel in accordance with CBP SOC SOPs

SOP Updates Biannually, as needed CIRT Government Lead and CBP SOD Government Staff

Lessons Learned Reports and Post Incident Analysis Report

Ad hoc, within 3 business days of request

CIRT Government Lead, CBP SOD Government Staff

1.7.5 Task 5 – Cyber Threat Intelligence (CTI) Support

The contractor shall conduct Cyber Threat Intelligence (CTI) support. This support includes monitoring activities, developing cyber threat analysis, identifying mitigation and / or remediation courses of action, sharing actionable cyber threat intelligence used in organizational IT asset protection, trending strategic cyber threats, and situational awareness. Support includes but is not limited to the following:

• Assist the CBP Security Operations Center (SOC) with identifying valid Indicators of Compromise (IOCs) and implementing appropriate monitoring, alerting, or blocking.

• Assist the CBP SOC with cyber investigations by providing threat intelligence, research, and artifacts on IOCs, personas, and Advanced Persistent Threat (APT) attribution.

• Assist with development and contributions to internal and external cyber threat intelligence products for distribution to Federal Partners over classified and unclassified communication networks.

• Compile cyber threat data gathered including, but not limited to present and emerging adversarial tactics, techniques, and procedures through independent research and analysis of identified activity combined with current SOC operations.

• Analyze unclassified and classified sources of information and cyber threat intelligence on foreign and / or domestic cyber threats, including recommended mitigation and / or remediation actions, as well as IOCs that could affect CBP information systems and / or networks.

• Perform cyber and technical threat analyses of hostile nation state actors, cybercriminals, terrorist organizations, and other malicious actors that could harm CBP information systems and / or networks and report on any suspected or verified findings.

• Assist with conducting link analysis of technical data using software tools to identify trends in attacks, targeting, and timing of suspicious / malicious activity.

• Assist with creating reports on key trends in cyber threat-related technology development or cybersecurity concerns associated with CBP information systems and / or networks.

• Assist with producing situational, incident-related reports on cyber threats that could affect CBP networks.

• Assist the Government in historical tracking and reporting current trends on cybersecurity events and incidents, including (but not limited to) phishing, malware, and scanning / probing activity.

• Assist the Government with information requests, perform specialized cyber threat analyses, and produce reports for the Government and external organizations.

• Assist the CBP SOC with advanced intrusion detection capability by providing the adversarial tactics, techniques, and procedures along with IOCs and recommended detection rules.

• Assist the Government with recommendations for countermeasures to malware and other malicious activity that could exploit CBP information systems and / or networks.

• Assist the Government with the dissemination of cyber threat information to senior management, security personnel, and key stakeholder communities, including the U.S. Intelligence Community, the U.S. Department of Defense, U.S.

Federal Law Enforcement entities, and others as required.

• Assist the Government with the creation of foreign travel briefings with cyber threat information for traveling CBP personnel as needed / requested.

• Assist Cyber Threat Hunt (CTH) with prioritizing cyber threat actor tactics, techniques, and procedures (TTPs), based on recent and relevant threat intelligence reporting.

• Assist the CBP SOC with development of cybersecurity content, such as rules, signatures, and other methods to detect cyber threat activity.

• Assist with formatting reports from various outputs targeting diverse audiences (e.g., other analysts, management).

• Assist with creating metrics and KPIs detailing the operational status and performance of the CTI branch.

• Proactively utilize CBP cybersecurity capabilities to search through CBP information systems to detect and work with the CBP SOC to isolate advanced threats that may evade existing security solutions.

• Conduct research and provide threat analysis assessments on third-party partners, vendors, and products with ties to CBP and our information systems.

The following work products shall be provided to the Government. Future work products may be added to this list upon agreement between the CBP SOD Director, the COR, CO, and the contractor.

New Security Content Ad hoc, within 3 business days of request CBP SOC Leads and CTI Team

SOP Creation Ad hoc, in accordance with CBP SOPs

CBP SOC Leads and CTI Team

Standard Operating Procedures (SOP) Updates

Biannually, as needed CBP SOC Leads and CTI Team

Analysis of Threat Data Report

Ad hoc, within 3 business days of request

CBP SOC Leads and CTI Team

Situational, Incident- Related Reports

Ad hoc, within 3 business days of request

CBP SOC Leads and CTI Team

Special Cyber Threat Analysis Report

Ad hoc, within 5 business days of request

CBP SOC Leads and CTI Team

Threat Briefings Ad hoc, within 1 business day of request

CBP SOC Leads and CTI Team

1.7.6 Task 6 – Cyber Risk Management (CRM) Support

The contractor shall conduct Cyber Risk Management (CRM) support. This support includes the identification, communication, and distribution of cybersecurity risks and actionable mitigations or remediations at the tactical and strategic levels within the CBP information technology environment. Support includes:

• Assist the Government in identifying tactical risks through working with the operational teams such as the VAT, SOC, CTI, along with other applicable teams and data to create a full picture of the tactical cyber risks.

• Assist the Government in conducting reviews and recommendations for approvals of tactical level change requests such as OIT Configuration Management changes to identify the probable impact to the CBP environment.

• Assist the Government with the prioritization of vulnerability remediation.

• Support the identification of common gaps in the information system security using methods such as the MITRE ATT&CK framework to focus recommendations to government regarding holistic funding in support of remediating security gaps for multiple systems.

• Support the identification of strategic risks through working with the Security Control Assessors (SCAs), Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), system owners, and other applicable teams to gather data for the creation of a full picture of the strategic cyber risks.

• Support the Component Cyber Acquisition Risk Management (C-CARM) through the development of templates and guidance for CBP program offices on meeting cybersecurity requirements for Acquisition Decision Events (ADE) through the Acquisition Lifecycle Framework (ALF).

• Assist in the development and review of Risk Assessment Reports (RAR) and Cyber Risk Recommendation Memos (CRRMs) to ensure that cybersecurity requirements are being implemented early in the ALF to reduce risk while developing and deploying information systems.

• Support the Risk Assessment (RA) Initiative by conducting Risk Assessments for CBP systems by gathering data on security incidents, vulnerabilities, Plan of Actions & Milestones (POA&Ms), Known Exploited Vulnerabilities (KEVs), Loss Magnitude Metrics, Threat Actors, and TTPs.

• Assist the Government in developing and maintaining a risk tolerance level through working with senior management to formally establish the level of acceptable risk.

• Assist the Government in developing information system risk profiles in alignment with the NIST Cybersecurity Framework.

• Assist the Government in conducting reviews and recommendations to aid the government in approving risk acceptance memoranda, assist with the prioritization of POA&Ms, create risk profiles for all CBP information systems, and identify common gaps in the information system compliance to focus holistic funding in support of remediating security findings for multiple systems.

• Assist the Government in creating a holistic picture of the cyber risks in the CBP environment and provide methods to effectively communicate the risks to the applicable stakeholders and senior management.

• Assist the Government in providing briefings for senior management on the cyber risk posture of CBP.

• Assist the Government in historical tracking and reporting of current trends on cybersecurity events and incidents, including but not limited to phishing, malware, and scanning / probing activity to develop probabilities for future occurrences.

• Assist the Government in generating communications to applicable stakeholders regarding cyber risk management, developing, and managing a holistic risk management dashboard to provide senior management a near real-time visual representation of cyber risks to CBP.

• Assist the Government with developing and maintaining a risk register to document all identified risks within CSD.

The following work products shall be provided to the Government. Future deliverables may be added to this list upon agreement between the CBP CRM Director, the COR, the CO, and the contractor.

Risk Register Updates

Ad hoc, within 2 business days of request

CBP CRM Leads

SOP Creation Ad hoc, in accordance with CBP SOPs

CBP CRM Leads

Standard Operating Procedures (SOP) Updates

Within 5 business days of the end of every quarter

CBP CRM Leads

Risk Briefings Ad hoc, within 1 business days of request

CBP CRM Leads / applicable stakeholders

1.7.7 Task 7 – Security Modernization (SecMod) Support

The contractor shall provide Security Modernization support (to include but not limited to Zero Trust Architecture (ZTA) concepts and principles) to assist Government’s engagement and collaboration with educating the broader CBP community on Security Modernization concepts such as the implementation of ZTA, continuing to refine and improve CBP’s ZTA implementation plan covering CBP’s Information Technology (IT) and Operational Technology (Ops Tech), and development of a security modernization strategy in alignment with Government’s Cybersecurity Strategy. This support includes:

• Provide ZT Subject Matter Expertise (SME) and function as strategic consultants to Government leadership.

• Assist the Government in incorporating ZT concepts and principles in accordance with the tasks identified in M-22-09 Moving the U.S. Government Toward Zero Trust Cybersecurity Principles, CISA’s Zero Trust Maturity Model, NIST’s Zero Trust Architecture (NIST SP 800-207), DoD’s Zero Trust Reference Architecture, Executive Order (EO) 14028, Improving the Nation’s Cybersecurity, GSA’s Zero Trust Technical Reference Architecture, and the Department of Defense Zero Trust Strategy, as well as future U.S. Government authoritative Zero Trust documents.

• Support evaluation of current CBP Enterprise Architecture, relevant tools, configurations, and processes / SOPs from a ZTA perspective, detailing the current security posture and identify opportunities for further adoption / implementation by CBP to ensure adherence to ZT principals.

• Assist Government in identifying technology and capability gaps to improve security posture and processes to enhance operational visibility and analytics, as well as operational orchestration and automation across OIT.

• Support Government in evaluating technologies and products in support of security modernization goals.

• Support the Government in making tool and technology recommendations that will provide, enhance, or improve ZTA capability maturity levels.

• Support the Government in identifying opportunities and provide suggestions that will serve as updates to CBP’s ZTA Implementation Plan to achieve advanced ZT/ZTA maturity levels, while continuing to build out CBP’s ZTA advanced maturity roadmap.

• Assist the Government in drafting and updating an OIT Zero Trust Optimization Roadmap and timelines that encompasses ZT concepts, principles, and requirements for all focus areas (Identity, Devices, Networks, Applications & Workloads, Data, Visibility & Analytics, Automation & Orchestration, and Governance) spanning CBP’s IT and Ops Tech.

• Assist the Government in drafting and creating a Security Modernization Strategy that encompasses ZTA concepts, principles, requirements, and provides an iterative approach to leveraging state-of-the-art technologies and advanced processes to address the challenges of a highly evolving threat landscape.

• Assist Government in collaborating with CBP OIT to maintain, and iteratively improve, the effectiveness of the Zero Trust Architecture Implementation & Optimization Integrated Project Team (IPT), establish associated working groups, clarify issues and generate consensus, and garner agreement on an overall CBP Security Modernization Strategy, roadmap, and resulting implementations.

• Assist the Government in prioritizing security modernization initiatives, including architecture and tool evaluations, configuration reviews, strategy planning, implementations that map back to both OIT’s and CSD’s strategic focus areas. Assist CSD in tracking all Security Modernization risks, issues, and blockers, as well as assisting in the development of mitigation strategies.

• Assist the Government in developing, tracking, and meeting/exceeding Security Modernization metrics.

• Assist the Government in historical tracking and reporting to include communications and briefings to applicable stakeholders as needed.

• Assist the Government in identifying roles and responsibilities in alignment with ZT strategy and roadmap and develop processes and procedures to streamline ZT functions and capabilities.

• Assist Government in policy development surrounding security modernization and ZTA implementation.

• Assist government in annual ZTA readiness assessment/gap analysis updates.

• Assist the Government in creating and maintaining the Security Modernization/ZT Project Management Tool (JIRA Project) board and leveraging available plug-ins to support development and maintenance of an enterprise level Integrated Master Schedule/Gantt chart pulling from multiple project boards across OIT.

• Support the coordination of organizations across OIT to ensure visibility of Security Modernization related efforts within dedicated IMS/Gantt chart(s).

• Assist the government in the development and maintenance of a single pane of glass dashboard(s) leveraging Business Intelligence capabilities to track CBP’s ZTA implementation efforts through to optimal maturity for each pillar.

• Support ad hoc requests for security modernization dashboard creation and maintenance of dashboards.

• Assist the Government in developing non-technical summaries on complex technical subject matters for CBP publication.

• Assist the Government in developing technical documentation to support security modernization requirements for DHS and CBP.

• Assist the Government in developing and maintaining PowerPoint presentations to support security modernization efforts, including graphics development and talking points.

• Support the dissemination of correspondence in support of security modernization efforts.

• Provide meeting minutes for all scheduled meetings, as requested. The meeting minutes shall capture at least the following information: subject, agenda, date, attendees, votes and major decisions, areas of non-agreement, and any action items assigned during the meeting. Minutes must be provided in electronic format in a timely manner, no later than three (3) business days after the conclusion of the meeting, to reflect real time consideration for the actions to be undertaken or issues addressed. A master action item list must be maintained by the Contractor PM on the CBP Network.

• Assist the Government in further development and maintenance of the Zero Trust Architecture Implementation & Optimization Integrated Product Team Teams site, including but not limited to reporting mechanisms, archive folders, resources, and access to Microsoft Team channel.

• Assist the Government in creating content for online resources (including, but not limited to SharePoint, Confluence, etc.) conveying information on Zero Trust Architecture and Security Modernization.

• Provide recommendations per government request to Security Modernization on leveraging technologies to achieve Zero Trust Architecture concepts and principles in both on-premises and cloud environments, to include but not limited to micro- and macro-segmentation, establishing immutable workloads, and cloud native capabilities to support other ZTA ideals.

• Assist the Government in development of technical documentation and strategies to support CBP and CSD’s security modernization efforts, to include graphics such as architecture views, operational views, and network diagrams.

• Assist the Government in complex technical discussions with other CBP groups providing insights, recommendations, and clarifying questions to assist the Security Modernization group in understanding other OIT groups’ architectures; assist in conveying recommendations to other teams on potential ways to leverage technologies to achieve ZTA concepts, principles, and requirements.

The following work products shall be provided to the Government. Future work products can be added to this list upon agreement between the CBP CRM Director, the COR, CO, and the contractor.

Tool / Technology Evaluation Reports Ad hoc, as required CBP Leadership

Zero Trust Readiness Assessment Reports Ad hoc, as required CBP Leadership

Zero Trust Readiness Assessment Questionnaire Ad hoc, as required CBP Leadership

Zero Trust Briefings Ad hoc, as required CBP Leadership

Standard Operational Procedures to support Zero Trust Implementation

Quarterly, as required

CBP Leadership, Task Monitors

Zero Trust Readiness Assessment Update Annual CBP Leadership, Task Monitor

1.7.8 Task 8 – Vulnerability Assessment (VA) Support

The contractor shall provide Vulnerability Assessment (VA) support to CBP information systems, including but not limited to the following:

• Assist the Government in managing CBP Enterprise Information System Vulnerability Management (ISVM) compliance validation.

• Assist the Government in briefing leadership on current and future vulnerabilities, security policies and industry standards.

• Assist the Government in briefing leadership on most impactful vulnerabilities, configurations, and penetration testing efforts.

• Assist the Government in creating and managing all scans in accordance with the CBP VAT scan standardization documentation.

• Assist the Government in performing regularly scheduled (monthly and ad hoc) vulnerability assessments using a master schedule as directed.

• Assist the Government in managing, customizing, and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .