II_01 Attachment 8 - Mock Scenario.pdf

PDF 82 KB Posted

Attached to
RFQ PROTECTS Federal contract opportunity
Solicitation number
2032H5-24-Q-00009
Issued by
Department of the Treasury Internal Revenue Service

About this file

This document is a mock scenario attachment related to a federal contract opportunity solicitation. The mock scenario represents a plausible cybersecurity incident impacting Treasury bureaus, and requires the contractor to describe their SOC offering's capabilities to respond. Key details include:

Part A outlines an initial response to a critical vulnerability being exploited by nation-state actors, where the contractor must describe coordination, communications, and escalations as the top-level enterprise SOC and bureau-level SOC. The SOC's role in ensuring minimal impact to business systems, prioritized response steps, staff composition, and success metrics are requested.

Part B describes the scenario evolving, where the vulnerability has been exploited and a threat actor has an active web shell. The contractor must describe how the response activities, staff composition, prioritized steps, and success metrics change under these new conditions.

The related federal contract opportunity is the PROTECTS solicitation, RFQ 2032H5-24-Q-00009, issued by the Department of the Treasury's Internal Revenue Service. The solicitation includes a detailed performance work statement, provisions and clauses, and several attachments such as a price template, labor category descriptions, and a draft ordering guide.

View the file

Other files for this federal contract opportunity

Other files attached to RFQ PROTECTS, newest first.
File Type Posted
II_02 2032H5-24-Q-00009-P00004.pdf PDF
II_01 Attachment 1 - Price Template v2.xlsx XLSX spreadsheet
II_01 Attachment 3 - PROTECTS Provisions and Contract Clauses v1.docx DOCX document
II_01 Attachment 4 - Questions and Answers MASTER LIST v1.xlsx XLSX spreadsheet
II_02 2032H5-24-Q-00009-P00003.pdf PDF
II_01 Attachment 4 - Questions and Answers MASTER LIST.xlsx XLSX spreadsheet
II_01 Attachment 1 - Price Template v1.xlsx XLSX spreadsheet
II_02 2032H5-24-Q-00009-P00001.pdf PDF
II_01 Attachment 11 2032H5-24-Q-00009.pdf PDF
II_02 2032H5-24-Q-00009-P00002.pdf PDF
II_01 Attachment 1 - Price Template.xlsx XLSX spreadsheet
II_01 Attachment 4 - Questions and Answers Template.xlsx XLSX spreadsheet
II_01 Attachment 6 - PROTECTS Labor Category Descriptions.xlsx XLSX spreadsheet
II_01 Attachment 10 DF PROTECTS Consolidation Combined.pdf PDF
II_01 Attachment 2 - PROTECTS PWS.pdf PDF
II_01 PROTECTS RFQ 24-Q-00009.pdf PDF
II_01 Attachment 7 - PROTECTS Demonstrated Corporate Experience.xlsx XLSX spreadsheet
II_01 Attachment 5 - PROTECTS Resume Template.docx DOCX document
II_01 Attachment 3 - PROTECTS Provisions and Contract Clauses.docx DOCX document
II_01 Attachment 9 - Ordering Guide.pdf PDF
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) Professional Cyber Services

Attachment 8

MOCK SCENARIO

The Mock Scenarios below represent a plausible cybersecurity situation impacting Treasury bureaus.

Each problem will require the contractor to make assumptions about how their SOC offering will be leveraged to provide the requested service capabilities. The scenarios are not implying any additional requirements that are not documented in the RFP. As a part of describing your response, the contractor is expected to clearly articulate the assumptions they made to prepare a response and identify which services are required to meet the response.

Sample Scenario Part A: Critical vulnerability threatens Treasury infrastructure.

Overview: Treasury has received notification of a major security vulnerability impacting public facing servers that is currently being exploited by nation-state actors. The vulnerability does not have a patch available, but workarounds are surfacing on the internet from trusted sources such as reputable security vendors. For the purposes of the example: there are currently estimated to be 30 known hosts impacted by the vulnerability across 4 Treasury bureaus, but that number is not confirmed.

1. Describe the initial response activities taken.

a. Providing support as the top-level enterprise SOC; include coordination, communications, and escalations both internal to your team and externally to Treasury stake holders.

b. Providing support as a bureau level SOC; include coordination, communications, and escalations both internal to your team and externally to the bureau leadership and the enterprise SOC.

2. What is the SOC’s role in ensuring Treasury remains secure with minimal impact to business systems in this type of situation?

3. Identify prioritized steps the SOC should be taking under these conditions.

4. Propose the staff composition of the work – describe the different teams involved.

5. Describe how you measure success during an event like this.

Sample Scenario Part B: Critical vulnerability exploited.

Overview: The vulnerability from above has been exploited and a threat actor has an active web shell on at least 3 servers.

1. Describe how this evolves response activities.

a. Providing support as the top-level enterprise SOC; include coordination, communications, and escalations both internal to your team and externally to Treasury stake holders.

b. Providing support as a bureau level SOC; include coordination, communications, and escalations both internal to your team and externally to the bureau leadership and the enterprise SOC.

2. How does the staff composition change – what new roles are added?

3. Identify prioritized steps the SOC should be taking under these new conditions.

4. Describe how you measure success during an event like this, include possible metrics.

MOCK SCENARIO
Sample Scenario Part A: Critical vulnerability threatens Treasury infrastructure.
Sample Scenario Part B: Critical vulnerability exploited.

File details come from the government source that posted it. Updated .