II_01 Attachment 10 DF PROTECTS Consolidation Combined.pdf
PDF 330 KB Posted
- Attached to
- RFQ PROTECTS Federal contract opportunity
- Solicitation number
- 2032H5-24-Q-00009
About this file
This document is a Determination and Finding (D&F) that consolidation, bundling, and substantial bundling is necessary and justified for the PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) program.
The D&F outlines the benefits of consolidation, including reduced acquisition cycle timelines, standardization of cybersecurity solutions and responses across the Treasury enterprise, and improved incident response capabilities. It states that consolidation is necessary to maintain and expand the Treasury's cybersecurity efforts, and that failure to obtain this contract support could increase risks to sensitive information, delay cloud migrations, and reduce the agency's overall security posture. The acquisition will be competed as a total small business set-aside based on market research demonstrating the capability of small businesses to meet the requirements. The related federal contract opportunity is Solicitation Number 2032H5-24-Q-00009 for the PROTECTS program, which includes a detailed Performance Work Statement and other attachments.
View the file
Other files for this federal contract opportunity
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DETERMINATION THAT CONSOLIDATION, BUNDLING OR SUBSTANTIAL
BUNDLING IS NECESSARY AND JUSTIFIED
PROGRAM NAME: PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS)
RFQ Number: 24-Q-00009
Treasury Standard Form – 1007 (Rev 11/16)
Prescribed by Treasury: DTAP 1007.107(a)
I. BACKGROUND.
A. Treasury and its Bureaus and Departmental Offices (DO) operate Security Operations Centers (SOCs) and perform enterprise Security Operations (SecOps) services on both an individual Bureau and shared services basis. These capabilities provide the means to monitor, detect, and respond to cybersecurity threats to their networks, information processing systems, and sensitive data. Treasury and its Bureaus/DO rely upon contracted personnel and other organic IT resources to staff and operate select SOC functions.
The PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) program serves as a framework and solution set to standardize solutions and operating models in providing cybersecurity services across the enterprise both within individual Bureaus and DO and at an enterprise level. PROTECTS helps furnish the best cybersecurity services possible to Treasury, Treasury Bureaus and those federal government agencies who depend on Treasury for their financial management.
B. Market Research. Market research has been conducted in accordance with FAR 10.001(a)(2)(iv) (e.g., see SF 1010 - Market Research Summary Report or other supporting documentation) and has demonstrated that—
Consolidation is necessary and justified (see FAR 10.001(a)(3)(vi)) Bundling is necessary and justified (see FAR 10.001(a)(3)(vii)) Consolidation and Bundling is necessary and justified (see FAR 7.107-1(a)) Substantial bundling is necessary and justified (see FAR 7.107-4)
There are currently two existing Blanket Purchase Agreements (BPAs) and three standalone contracts that covers the five main SOCs. Out of these five existing requirements, four are held by large business and one is held by small business. The market research conducted reveled that both small and large business have the capabilities to conduct this work. Based on the rule of two, it has been determined that this acquisition be a total small business set-aside.
II. CONSOLIDATION.
A. Benefits. When looking at the types of benefits consolidation brings, for PROTECTS, FAR 7.107-2(c) is the guiding principle. The significant benefits associated with establishing the PROTECTS BPA is that it will provide a reduction in acquisition cycle timelines as well as standardization of cybersecurity solutions and responses across the Treasury.
First, the BPA will allow task orders to be executed in an expedited manner. This is a result of reduced administrative burden while increasing ordering efficiency. While there is cost savings associated with procurement activities across the duration of the BPA, those costs are minimal compared to the overall value of the BPA. The BPA will have an
Treasury Standard Form – 1007 (Rev 11/16)
Prescribed by Treasury: DTAP 1007.107 established ordering guide which will standardize the process of issuing orders to requiring activities. This is critical with the ever-changing cyber security environment.
The PROTECTS program will serve as a tool to provide enterprise-wide cybersecurity services to Treasury, Treasury Bureaus and those federal government agencies who depend on Treasury for their cybersecurity support.
To further demonstrate the expedited benefit, the Government can normally, on average, expect the procurement acquisition lead time (PALT) of similar size and scope requirements be cut in half. This is in part because of contractors already pre-vetted and approved to work on the type of requirement. As stated above, the reduction in PALT is a result of built in ordering efficiency based on a single ordering guide. These streamlined ordering procedures are what contribute to the reduction to PALT.
Secondly, the technical benefit by establishing this BPA, in part, includes support incident response capabilities, ensuring that Treasury agencies are best positioned to deal with both current and emerging threats. To do this in the most efficient manner while having the ability to reduce the number of barriers that would arise from a fragmented individual award solution establishing the BPA is paramount. Consolidation allows for a streamlined procurement process that would reduce response times, improve resource allocation, and potentially develop a comprehensive solution that could benefit from knowledge obtained by one agency and applying it Treasury-wide.
In accordance with FAR 7.107-2(c) additional benefits to consolidation which include:
• Current and evolving cyberthreat environment comprising multiple zero-day threats and associated attacker strategies drives extreme timeliness (real-time and near real-time) requirements for integration of incident and threat information and response coordination across multiple functional areas (e.g., incident detection and management, Cyber Threat Intelligence (CTI), threat hunting, cyber range, etc.). In the absence of consolidation, coordination of this information required between multiple contractors – especially where “Government in the middle” brokering/integration/approval is required for inter-contractor communications – poses extremely high risk of cyber defensive failures with devastating potential enterprise and public (e.g., taxpayer and business) impacts. Industry media is filled with reports of breaches worsened by failure to act sufficiently promptly in response to indicators of compromise and emerging threat information (e.g., 2023-24 Microsoft/M365/Azure/Exchange, 2023 Xfinity and NASCO, 2017 Equifax) exposing millions of records of sensitive customer and business information.
• Meaningful integration across multiple functional areas is necessary for those areas to succeed. For example, CTI must inform threat hunting activities, so the hunters know what to look for in terms of Indicators of Compromise (IOCs), lateral traversal attempts, obfuscation techniques, Treasury Standard Form – 1007 (Rev 11/16)
Prescribed by Treasury: DTAP 1007.107 living-off-the-land attacker strategies, etc. Both must inform the cyber range function so that the range can support appropriate scenarios with sufficient realism necessary both to train staff on what the threats look like in the enterprise environment, verify that candidate solutions can detect and mitigate those threats in the enterprise environment, and so that cyber range functions can assist CTI and threat hunting in identifying essential elements of information about attack vectors and attacker strategies.
• Standardization of cybersecurity solutions and responses across Treasury and its bureaus. This will provide continuity and further strengthen the position of Treasury and respective bureaus for future incidents.
• Quality Improvements: Cybersecurity is a critical mission area that impacts all Treasury organizations. The need to perform this mission in a consistent and standard manner across all of Treasury drives this consolidation. This BPA will ensure access for all organizations to the complete range of SOC related services for both on-premises and managed services at a consist service level and, through the acquisition requirements, a unified approach to the cybersecurity of Treasury through coordinated support, collaborative work, and information sharing on cybersecurity solutions.
B. Alternative approaches.
One possible alternative approach is to continue to procure these services at the respective DO/Bureau level. This is less beneficial due to the outlined anticipated reduction of acquisition timeline and procurement savings for each requirement.
Finally, the Government does not have the capability or resources to develop, generate, or maintain the products and professional services needed, nor is there an intention to do so as they are commercially developed, supported, and offered.
C. Negative impact.
The Treasury needs to maintain and expand its cybersecurity efforts to enable compliance with Federal Information Security Modernization Act (FISMA), Executive Order 14028 “Improving the Nation’s Cybersecurity,” and various Office of Management and Budget (OMB) directives and memorandums. All major Treasury business components will be impacted by a breach of the Treasury boundaries. Failure to obtain this critical contract support may result in Treasury the following:
i. Increased risk to unauthorized disclosure of sensitive or protected information.
ii. Delayed or inadequate security coverage for migration of existing legacy systems to new cloud services
iii. Slowed or inadequate ability of the CSIRC to respond to cyber incidents.
iv. Reduced overall Treasury security posture to respond to evolving threat
Treasury Standard Form – 1007 (Rev 11/16)
Prescribed by Treasury: DTAP 1007.107
Failure to establish the BPA would negatively impact the agency’s ability to respond quickly to real time threats, potentially leading to elevated risks to mission and business critical systems, and significant financial and reputational damages.
D. Inclusion of small business concerns.
This acquisition will be competed as a total small business set-aside in accordance with FAR 8.405-5 as market research has demonstrated that there is a reasonable likelihood that offers will be obtained from at least two responsible small business concerns.
To ensure small business concerns will be addressed to the maximum extent pertaining this requirement extensive market research was performed. Request for Information (RFI) and a draft performance work statement (PWS) was published within the HACS MAS to all 594 contract holders in GSA eBuy as well as on SAM.gov on 04 October 2023 with responses due on 01 November 2023. There were 34 responses. Out of the 34 respondents, 13 were small business. In addition to, 32 of the respondents carry the HACS and IT Professional Services SIN (54151HACS & 54151S). The RFI analysis concluded that there is a reasonable expectation that at least two small businesses not only have the capability of meeting the requirements within the PWS but will also provide quotes in response to the solicitation.
III. DETERMINATION.
Based on the above, I hereby determine that in accordance with FAR 7.107, that consolidation, is necessary and justified.
PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) Professional Cyber Services
D&F Consolidation Signature Page 2032H5-24-Q-00009
Prepared by:
Digitally signed by
J on a t h an w
C ar ne y
Date: 2024.01.19 1 2:58:47 -05 '00'
Jonathan W. Carney Contracting Officer
Reviewed By:
Paula A.
Cheetham
Paula Cheetham, Digitally signed by Paula A. Cheetham
Date: 2024.01.19 14:20:24 -05'00'
Adobe Acrobat version:
2023.006.20320
Branch Chief, Enterprise Systems
Reviewed By:
George L.
Digitally signed by Geor ge L. Bonds Jr.
B d J Date: 2024.05.02 on s r. _ 11 •04•59 _04•00· George L. Bonds, Jr.
Director, Procurement Operations
Approve: (Consolidation JAW O/TAP 1001.107)
Guy A. Torres Deputy Chief Procurement Officer Internal Revenue Service
19 January 2024
Date
Date
Date
Date
| I_06_c DF PROTECTS Consolidation Combined |
| I_06_c DF PROTECTS Consolidation |
| I_06_c DF PROTECTS Consolidation sig |
I_06_c DF PROTECTS Consolidation Signature Page (1) printed
| 2024-05-06T14:39:06-0400 | |
| Guy A. Torres |
File details come from the government source that posted it. Updated .