2024-04-19-IDIQ-SOW-Security Audit.docx
DOCX document 66 KB Posted
- Attached to
- Security Audit/Assessment Support Services Federal contract opportunity
- Solicitation number
- PR12457774
About this file
This document is a Statement of Work (SOW) for an Indefinite Delivery, Indefinite Quantity (IDIQ) contract for Security Audit/Assessment Support Services for the Department of State (DOS) Internet Freedom program.
The primary objective is to establish multiple award IDIQ contracts to provide on-demand security auditing and assessment services for technologies that promote and protect Internet freedom. The SOW outlines five functional areas: 1) Security Audit/Assessment, 2) Reporting, 3) Coordinated Remedy Development & Review, 4) Remediation Verification, and 5) Trends and Needs Reports. Key deliverables include meeting participation, quarterly progress reports, and various audit/assessment report types. Contractors must demonstrate capabilities across technical disciplines such as code auditing, architecture analysis, system evaluations, cryptographic reviews, and protocol reviews. The contract will be administered through individual task orders issued by the Contracting Officer, with proposals evaluated on a best value basis.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Security Audit and Assessment.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK - IDIQ
DRL/GP SECURITY AUDIT/ASESMENT SUPPORT SERVICES
BACKGROUND/OBJECTIVE:
The primary goal of this acquisition is to establish a suite of indefinite-delivery indefinite-quantity contracts for security auditing and assessment services that will enable the Department of State (DOS) Internet Freedom program units to accomplish their mission objectives.
This acquisition and resulting multiple award contracts are intended to meet the mission needs of the DOS by:
· Providing demand-driven, flexible Security Audit/Assessment services for technologies which promote and protect Internet freedom; and
· Supporting evidence-based decision-making on how funds can be used to best ensure that such technology is secure and has not been compromised.
SCOPE:
The Contractor shall provide the full range of security auditing and assessment services in one or more of the functional categories to meet the mission needs of the DOS Internet Freedom program. Specific requirements will be identified in individual Task Orders (TOs) to support DOS world-wide. The Contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Support Services as defined in this Statement of Work (SOW), except for those items specified as government furnished property and services.
2.1 Functional Areas
· Functional Area 1: Security Audit/Assessment
· Functional Area 2: Reporting
· Functional Area 3: Coordinated Remedy Development & Review
· Functional Area 4: Remediation Verification
· Functional Area 5: Trends and Needs Reports
CONTRACTOR PERSONNEL DISCIPLINES AND SPECIALTIES:
The Contractor shall accomplish the assigned work by employing and utilizing qualified personnel with appropriate combinations of education, training, and experience. The Contractor shall match personnel skills to the work/task outlined herein. The Contractor shall ensure the labor categories, labor rates, and man-hours utilized will be adequate to accomplish the tasks outlined in this SOW and individual Task Orders. The Contractor shall provide the necessary resources and infrastructure to manage, perform, and administer this task order.
FUNCTIONAL AREAS:
The Contractor shall furnish the full range of services necessary to meet requirements of this contract and individual Task Orders (TO)s as related to the five (5) functional areas described below, with specific tasks to be set forth in each individual TO. Individual TOs may encompass more than one functional area listed below.
4.1 Functional Area 1: Security Audit/Assessment
Provide one or more of the security audits and assessment services outlined below.
Security Audit and Assessment Services
· Code Auditing:
· Review of source code to find security vulnerabilities and ensure proper security controls have been used.
· Architectural Security Analysis:
· Review of the design and architecture of a projects application or system to assess if they meet the explicit or implicit security assertions made by the project, identify possible weaknesses in its design, and identify possible threats to the system based upon the adversaries operating in key identified technology operating contexts.
· System Security Evaluations (including web application testing):
· Review of the implemented technology to identify if it fails to meet the explicit or implicit security assertions made by the project which are caused by its method of deployment, or the systems it is deployed on. This can include white/crystal box testing of live/testing systems, review of a system configuration and other hardening procedures, etc.
· Cryptographic Review:
· Conduct cryptographic review and crypto source code review to identify possible vulnerabilities/weaknesses in cryptosystems used by a project.
· Protocol Review:
· Conduct architectural and source code review to identify possible vulnerabilities/weaknesses in network protocols developed/used within the project. This can be scoped to identify any/all vulnerabilities/weaknesses or based upon a specific set of adversaries or operating contexts.
4.2 Functional Area 2: Reporting
The Contractor shall document the Engagement, its findings, and recommended remediations in a Final Audit/Assessment Report (FAAR). In addition to the overall requirements for the FAAR, as outlined in individual TORP’s, the Contractor shall produce a sanitized version of the FAAR which complies with any/all agreed upon public release requirements defined in a DRL approved Release Plan.
4.3 Functional Area 3: Coordinated Remedy Development & Review:
Work with Auditee to identify appropriate security fixes and software flaw mitigation proposals and provide assessments of their adequacy. This service would be an addition to standard remedy recommendations provided in final reporting and would be done when Auditees have limited in-house security capacity and/or require additional support to address specific recommendations.
4.4 Functional Area 4: Remediation Verification
Review documentation provided by the Auditee to verify its attestations to the implementation of changes necessary to address identified Engagement findings. Conduct targeted follow up audits to confirm identified Engagement findings have been remediated or mitigated.
4.5 Functional Area 5: Trends and Needs Reports
The Contractor shall produce a report summarizing broader trends and needs of Internet freedom technologies which it has identified across security audit and assessment services provided under this award. These reports shall provide evidence and analysis to support Government decision-making on how funds can be used to best ensure that supported Internet freedom technologies are secure and have not been compromised. Illustrative areas of focus include, but are not limited to, trends in technology vulnerabilities or weaknesses, project preparedness for security audit, and/or critical links in software supply chains; best practices; and/or broader recommendations for how projects can better secure their software development and deployment and for areas where donors should encourage/support projects in doing so. The area of focus for each individual report will be defined in the Task Order Request Package.
1. DELIVERABLES:
5.1 Meetings
5.1.1 Meetings, Conference Calls, and Workshops – Domestic
Each Task Order will identify any/all additional Task Order specific meeting requirements.
The Contractor shall participate, document, and submit in writing, meeting notes, as record of meetings, conference calls, and workshops involving decisions that relate to this as required to support efforts identified in the scope. Meeting agendas shall be prepared in advance and coordinated with the Contracting Officer’s Representative (COR) and Contracting Program Officer (CPO) prior to distribution.
5.2 Reports
The Contractor shall prepare the following reports. All report deliverables should be formatted to comply with Section 508 of the Rehabilitation Act of 1973. Each Task Order will identify any/all additional Task Order specific reporting requirements.
5.2.1 Quarterly Progress Report
· The Contractor shall furnish a combined Quarterly technical and financial progress report stating the activities and services furnished during the preceding Quarter.
· The report shall be submitted via electronic mail to the CO and COR on or before the 15th day of each quarter following the first complete calendar quarter of the task order.
· The report shall specify the task order technical and financial status for each of the following data points:
· Task Order funding for the current option period and cumulative from the effective date of the task order.
· Personnel gains and losses.
· Status of invoices for the task order, including outstanding invoices, errors and resolution.
CONTRACTOR PERSONNEL ADMINISTRATION:
The Contractor shall maintain the training of its employees by providing initial and refresher training as required to meet the SOW requirements. The Contractor shall make necessary travel arrangements for employees. The Contractor shall provide administrative support to employees in a timely fashion for time keeping, leave processing, pay, and emergency needs.
TASK ORDER MANAGEMENT:
The Contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned to each task order. The Contractor shall establish processes and assign appropriate resources to effectively administer each task order. The Contractor shall respond to Government requests for contractual actions in a timely fashion. The Contractor shall have a single point of contact between the Government and Contractor personnel assigned to support each task order. The Contractor shall assign work effort and maintaining proper and accurate time keeping records of personnel assigned to work on each task order.
TASK ORDER PROCESS
9.1 Requests for Task Order Proposals
(a) Each Task Order Request Package (TORP) will be issued by the Contracting Officer in writing and will be transmitted to the Contract Holder(s) by any appropriate means (e.g. E-mail, U.S. Mail, commercial carrier) unless there are urgent or exigent circumstances, in which case the Contracting Officer may request Task Order Proposals orally.
(b) Each Task Order Request Package (TORP) will include, at a minimum:
1. A due date for proposal submission;
2. Either a SOO or PWS, that will include a detailed description of the technology being audited and work to be accomplished;
3. The applicable tasking areas;
4. A listing of required deliverables, e.g. reporting, briefings, and/or other items; and
5. The estimated period of performance and date by which performance must be initiated and/or completed.
The TORP will also include specific instructions for the submission of proposals, evaluation technique, selection criteria factors, the factors’ order of importance, and other information deemed appropriate.
(c) For all Engagements which include tasks from “Task Area 1: Security Audit/Assessment,” Contractors will be provided an equal opportunity to meet directly with the SPO and Auditee soon after the Task Order Solicitation.
(d) Contractors will be provided an adequate time to prepare and submit responses based on the Estimated cost and complexity of the proposed TORP. The due date will be set forth in each TORP.
(e) If unable to perform a requirement, Contractors shall submit a “no bid” reply in response to the proposal request. All “no bids” shall include a brief statement as to why the Contractor is unable to perform, i.e. conflict of interest.
9.2 Task Order Proposals
9.2.1 Preliminary Note
Unless the TORP specifies otherwise, the Contractor shall, within ten (10) working days of receipt of a TORP, submit to the Contracting Officer a Task Order Proposal that includes the information indicated below.
Task Order Proposals will be streamlined and succinct, to the extent practical based on the estimated dollar value and complexity of the work, stating compliance or exception to requirements, risks, assumptions, and conflict of interest issues. Proposals shall not merely restate SOO or PWS requirements. Both oral and written technical proposals may address, as an example:
1. Technical/Management Approach to include schedule.
2. Total proposed price to include all proposed subcontracts and Other Direct Costs (materials and supplies, travel, training, etc.). Any potential organizational conflicts of interest between the technology/service being evaluated and the Contractor’s or related companies’ products.
3. Proposed Key Personnel for the Task Order in accordance with the following:
The Contractor shall submit resumes for all Key Personnel. The resumes must clearly demonstrate the degree of significant experience as it relates to the proposed position. The Contractor must indicate if any proposed Key Personnel are not currently employed by the Contractor and, in such case, must provide written assurance that the individual(s) will commence work for the Contractor on the Task Order within ten (10) working days of receipt of the Task Order.
9.2.2 Scope of Work
For all Engagements which include tasks from “Task Area 1: Security Audit/Assessment” the Contractors shall include a project specific “Scope of Work” (SOW).
This SOW shall address:
· Goal(s) or Objective(s) for the Engagement.
· Assets and Targets to be audited during the Engagement and why they are included in the audit.
· Methodology to be used.
· Rules of engagement.
· Auditee responsibilities.
· Names, job titles, and contact information for each team member that will contribute to the work described in the TORP.
· A comprehensive task outline identifying project milestones, meetings, presentations, submissions, and reviews with specific calendar dates.
9.2.3 Evaluation of Task Order Proposals.
The Government will evaluate the proposals received and select a Contractor to receive the task order on a best value evaluation of Task Order Proposals. Each TORP will specify the relative importance of all significant evaluation factors and sub factors. Examples of criteria could include one of more of the following as specified in the applicable TORP.
1. Appropriateness of Proposed audit/assessment methodology and task-outline.
2. Qualifications of Key Personnel assigned to Project. .
3. Responsiveness of delivery schedules.
4. Contactor past performance of any previous orders.
5. Evaluated price (Note: Lowest evaluated price does not guarantee proposal selection).
6. Any other technical or administrative aspects.
9.2.4 Task Order Issuance.
1. The Contracting Officer shall issue a written Task Order to the Contractor providing the necessary funding and authorizing the Contractor to begin work. Oral orders may be issued by the Contracting Officer and will be followed by written confirmation within three (3) business days.
2. The Government shall not be obligated to pay the Contractor in any amount in excess of the stated total Task Order amount, and the Contractor shall not be obligated to continue performance if to do so would exceed the total Task Order amount.
General Requirements
CONTRACT AND TASK ORDER MANAGEMENT
The Contractor shall provide Contract and Task Order management for all task orders placed under this contract. The objective of contract and Task Order management is to provide the program management, project control and contract administration necessary to manage a high volume, multiple contract type Task Order process across a large, diversified Internet Freedom technology portfolio so that the cost, schedule and quality requirements of each order are tracked, communicated to the Government, and ultimately attained.
PLACE OF PERFORMANCE
The performance of this contract shall take place at the contractor’s operational facility or in distributed/remote locations.
SUBCONTRACT MANAGEMENT:
This is an IDIQ Multiple Award Task Order (MATO) contract. Individual TO shall be issued on a performance-based FFP basis.
The contractor shall be responsible for any subcontract management necessary to integrate work performed on this task order and shall be responsible and accountable for subcontractor performance on this requirement. The prime contractor will manage work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations. Contractors may add subcontractors to their team after pre-approval by the Contracting Officer (PCO) and the Contracting Officer Representative (COR).
BUSINESS RELATIONS:
The Contractor shall successfully integrate and coordinate all activity needed to execute the requirement outlined in the SOW. The Contractor shall manage the timeliness, completeness, and quality of problem identification. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.
QUALITY CONTROL:
The Contractor shall develop a QCP for each task order and maintain an effective quality control program to ensure services are performed in accordance with the BPA. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor's QCP is the means by which he assures himself that his work complies with the requirement of the contract.
The finalized QCP will be accepted by the Government at the time of the award of the Task/Delivery Order. The Contracting Officer may notify the Contractor of required modifications to the plan during the period of performance. The Contractor then shall coordinate suggested modifications and obtain acceptance of the plan by the Contracting Officer. Any modifications to the program during the period of performance shall be provided to the Contracting Officer for review no later than 10 working days prior to effective date of the change. The QCP shall be subject to the Government's review and approval. The Government may find the QCP "unacceptable" whenever the Contractor's procedures do not accomplish quality control objective(s). The Contractor shall revise the QCP within 10 working days from receipt of notice that QCP is found "unacceptable."
QUALITY ASSURANCE:
The Government will evaluate the Contractor’s performance under each task order to ensure that the Contractor has performed in accordance with the performance standards.
ACCEPTANCE CRITERIA:
Approval of final documents and other work products shall be in accordance with the Department’s established quality control plan. Work performed will be reviewed for quality, timeliness, and professionalism, by the COR and CPO. If the performance is unacceptable, feedback will be provided in a timely fashion.
DATA RIGHTS:
The Government has unlimited rights to all documents/material produced under this contract and each task order in accordance with (IAW) FAR 52.227-14, Rights In Data-General (May 2014). All documents and materials, to include the source codes of any software, produced under this contract and each task order shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
STANDARDS:
The Contractor shall ensure all work is completed in accordance with U.S. government and Department of State (DOS) standards, policy, procedures and guidelines as provided. All products and services under these tasks, and as part of the agreement, are the sole property of the U.S. Government.
CONFIDENTIALITY:
Contractors shall execute and sign non-disclosure agreements when they work with sensitive and/or proprietary information. Forms to be executed and maintained by the Task Manager.
TRAVEL:
Travel shall be IAW individual TO requirements. All travel shall be pre-approved with a request from the Contractor to the COR for final approval. Funds shall be available and obligated in the task order before travel commences. All travel shall be in accordance with the Federal Travel Regulation.
GOVERNMENT-FURNISHED PROPERTY, EQUIPMENT, AND/OR SERVICES
The Contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to provide security auditing and assessment services as defined in this Statement of Work and individual Task Orders.
DEFINITIONS AND ACRONYMS:
Contractor. A supplier or vendor awarded a contract or task order to provide specific supplies or service to the Government. The term used in this task order refers to the prime, not contractor personnel.
Contracting Officer (CO). A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the government. Note: The only individual who can legally bind the government.
Contracting Officer's Representative (COR). An employee of the U.S. government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.
Defective Service. A service output that does not meet the standard of performance associated with the SOW.
Deliverable. Anything that can be physically delivered, but may include non-manufactured things, such as meeting minutes or reports.
Key Personnel. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a task order. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
Physical Security. Actions that prevent the loss or damage of Government property.
Quality Assurance. The Government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.
Quality Assurance Surveillance Plan (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance to ensure services meet the requirements of the Performance Work Statement.
Quality Control. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract/task order requirements.
Subcontractor. One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.
Auditee: The technology team who maintain the technology being audited.
Contracting Program Officer (CPO): A person primarily responsible for assisting the COR with U.S. coordination with the Auditee and for programmatic and technical review of evaluations of task order proposals, final documents, and work products. THE CPO and COR may be the same individual.
Engagement: A discreet security audit event.
Final Audit/Assessment Report (FAAR): A document containing the Engagement and its findings.
SBU - CONTRACTING AND ACQUISITIONS
File details come from the government source that posted it. Updated .