II_01 PROTECTS RFQ 24-Q-00009.pdf

PDF 383 KB Posted

Attached to
RFQ PROTECTS Federal contract opportunity
Solicitation number
2032H5-24-Q-00009
Issued by
Department of the Treasury Internal Revenue Service

About this file

This document is a Request for Quote (RFQ) issued by the Department of the Treasury for the PROviding Treasury Enterprise Cybersecurity Technology and Services (PROTECTS) professional cyber services contract. The RFQ is seeking quotations from vendors on the GSA Multiple Award Schedule (MAS) Information Technology (IT) contract under the Highly Adaptive Cybersecurity Services (HACS) and IT Professional Services special item numbers.

The RFQ is for a multiple award Blanket Purchase Agreement (BPA) to provide enterprise-wide cybersecurity services, including proactive and reactive services, Security Operations Center (SOC) monitoring, and other cybersecurity support. The period of performance is eight 12-month ordering periods starting from the date of award. The RFQ has set-aside requirements for small businesses and has defined socioeconomic goals. Quotes are due by June 6, 2024 and will be evaluated on factors such as corporate experience, technical capability, and price. Vendors must hold both HACS and IT Professional Services SINs under their GSA MAS IT contract to be considered.

View the file

Other files for this federal contract opportunity

Other files attached to RFQ PROTECTS, newest first.
File Type Posted
II_02 2032H5-24-Q-00009-P00004.pdf PDF
II_01 Attachment 1 - Price Template v2.xlsx XLSX spreadsheet
II_01 Attachment 3 - PROTECTS Provisions and Contract Clauses v1.docx DOCX document
II_01 Attachment 4 - Questions and Answers MASTER LIST v1.xlsx XLSX spreadsheet
II_02 2032H5-24-Q-00009-P00003.pdf PDF
II_01 Attachment 4 - Questions and Answers MASTER LIST.xlsx XLSX spreadsheet
II_01 Attachment 1 - Price Template v1.xlsx XLSX spreadsheet
II_02 2032H5-24-Q-00009-P00001.pdf PDF
II_01 Attachment 11 2032H5-24-Q-00009.pdf PDF
II_02 2032H5-24-Q-00009-P00002.pdf PDF
II_01 Attachment 1 - Price Template.xlsx XLSX spreadsheet
II_01 Attachment 4 - Questions and Answers Template.xlsx XLSX spreadsheet
II_01 Attachment 6 - PROTECTS Labor Category Descriptions.xlsx XLSX spreadsheet
II_01 Attachment 10 DF PROTECTS Consolidation Combined.pdf PDF
II_01 Attachment 2 - PROTECTS PWS.pdf PDF
II_01 Attachment 7 - PROTECTS Demonstrated Corporate Experience.xlsx XLSX spreadsheet
II_01 Attachment 5 - PROTECTS Resume Template.docx DOCX document
II_01 Attachment 8 - Mock Scenario.pdf PDF
II_01 Attachment 3 - PROTECTS Provisions and Contract Clauses.docx DOCX document
II_01 Attachment 9 - Ordering Guide.pdf PDF
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PROviding Treasury Enterprise Cybersecurity Technology & Services

(PROTECTS)

Professional Cyber Services Solicitation Number: 2032H5-24-Q-00009

2032H5-24-Q-00009 PAGE 1

REQUEST FOR QUOTE (RFQ)

Request for Quotations Number 2032H5-24-Q-00009

Issued to:

Contractors under the General Services Administration (GSA) Multiple Award

Schedule Information Technology (MAS IT), Highly Adaptive Cybersecurity Services (HACS) Special Item Number (SIN) 54151HACS and IT Professional

Services SIN 54151S

The Contractor’s Basic GSA Schedule contract is applicable to the order awarded under this RFQ.

Conducted under Federal Acquisition Regulation (FAR) 8.4

Issued by:

Department of Treasury

16 May 2024

2032H5-24-Q-00009 PAGE 2

NOTICE TO PROSPECTIVE QUOTERS

Agency Contact: Jon Carney, Contracting Officer

RFQ Issue Date: 16 May 2024

Questions Due Date: All questions or requests for clarification, citing the specific solicitation section, shall be posted on GSA eBuy by 28 May 2024 at 10:00 AM eastern via attachment 4.

The contract specialist shall be the sole point of contact (POC) for answering questions regarding the RFQ. Answers to all written questions will be provided to all prospective contractors, giving due regard to the proper protection of proprietary information and without reference to the source of the question. In posing questions, vendors must cite the relevant section, paragraph, and page number. Statements expressing opinions, sentiments, or conjectures are not considered valid inquiries and will not receive a response. Further, vendors are reminded that hypothetical questions aimed at receiving a potential “evaluation decision” will not be addressed.

Quote Due Date: 6 June 2024 at 10:00 AM eastern via eBuy.

The quoter will submit a signed cover letter by an authorized company negotiator to constitute agreement with all terms and conditions of this RFQ.

2032H5-24-Q-00009 PAGE 3

The Department of Treasury intends to establish a multiple-award Blanket Purchase Agreement (BPA) under General Services Administration (GSA). The Request for Quote (RFQ) will be solicitated under Special Item Number (SIN) 54151HACS and 54151S.

At the time of award for this order and prior to the exercise of order option years, the Quoters must have a valid GSA schedule contract in effect that covers the appropriate performance year. Failure to comply will result in the Quoters being ineligible for award or in the case of options the order may not be renewed. The Quoters shall notify the Contracting Officer no later than 12 months before its contract expiration whether they will be establishing a new contract, extend its current contract or establishing a new contract with a different socioeconomic status. The Quoters must have BOTH 54151HACS and 54151S SINS to be considered responsive.

The order established as a result of this RFQ will be based on the Quoters current contract and discounts provided. In the event that the successful Quoter has their current contract canceled or it expires, or is awarded a new contract, the Government reserves the right to transfer the new contract if the current contract is canceled or expired and a new one has been awarded, but prior to doing that the Contracting Officer must ascertain that the new contract does not contain terms and conditions unfavorable to the agency and new price reductions are negotiated.

Requirement details, agency specific, GSA Schedule terms and conditions, and FAR Clauses will be incorporated and applicable to this order.

1.0 Authority

1.1 Pursuant to FAR subpart 8.405-3, Ordering activities may establish Blanket Purchase Agreements (BPAs) under any schedule contract to fill repetitive needs for supplies or services. Ordering activities shall establish the BPA with the schedule contractor(s) that can provide the supply or service that represents the best value.

1.2 SET ASIDE INFORMATION (If applicable)

Pursuant to FAR 8.405-5, this acquisition will be a total set aside for small business.

The Treasury intends to award a minimum of five (5) vendors under the BPA. GSA and/or Treasury reserves the right to add more vendors during the evaluation process.

Task Orders (TO) will be issued in accordance with Attachment 9, Ordering Guide.

The ordering guide will be finalized once award of the BPA is established.

2032H5-24-Q-00009 PAGE 4

1.2.1 Treasury Small Business Goals

Burea u

FY24 Bureau Small Business Goal

Overall Sm all Business

(SB)

Small Disadvantag ed Business

(SDB)

Wome n Owned Small Busine ss

(WOSB

Service- Disabled Veteran Owned Small Busines s

(SDVOS

B)

HUBZONE

Small Business (HUBZone

Veteran Owned Small Business

(VOSB)

(No Goal Must be Tracked)

GOAL 37%

12.75% 5% 5% 3%

1.3 NORTH AMERICAN INDUSTRY CLASSIFICATION SYSTEM (NAICS)

CODE AND SIZE STANDARD

The principal nature of the requirements described in this solicitation is consistent with services performed by industries in the 541519 – Other computer related services (size standard $34M).

1.4 PRODUCT SERVICE CODE (PSC)

The services in this solicitation are best represented by PSC code: DJ01 – IT and Telecom – Security and Compliance Support Services (Labor).

1.5 TYPE OF SERVICES

The type of services under this solicitation are: The PROTECTS Professional Cyber Services, known as ‘PROTECTS’, will serve as a tool to provide enterprise-wide cybersecurity services. PROTECTS will conduct proactive and reactive cybersecurity services and operate Security Operations Centers (SOCs) to monitor, detect, and respond to cybersecurity threats to their networks, information processing systems, and sensitive data as described in the Performance Work Statement (PWS). The contractor shall provide, all management, supervision, hardware, software, and labor to support this BPA contract. This BPA will also include managed services.

The types of orders are expected to be Firm Fixed Price (FFP) and Labor Hour (LH), or a combination of each. Each task order will specify which type of service is requested.

1.6 EXTENT OF COMPETITION

2032H5-24-Q-00009 PAGE 5

This solicitation is issued in accordance with FAR 8.405-5.

1.7 SECURITY CLEARANCES

Security clearance requirements will be detailed in specific TOs. At a minimum, all positions on this BPA require a minimum of a Minimum Background Investigation (MBI).

Additionally, some positions on this BPA may require access to SECRET and TOP SECRET in some TOs. Contractors must ensure that they possess required access levels (SECRET, TOP SECRET, SCI) at time of TO issuance. Failure to meet security clearance requirements may result in being off-ramped from the BPA.

1.8 PERFORMANCE LOCATION(S)

The primary work location will be determined at the task order level. Commuting expenses will not be paid by the Government. HACS may also include performance at other designated locations. The specific place of performance for each activity will be as mutually agreeable to the Government and the contractor.

1.9 PERIOD OF PERFORMANCE

Eight 12-month ordering periods beginning the day of award. Contractors must ensure that their MAS IT covers the full amount of ordering periods.

Actual contract dates will be filled in prior to award.

Ordering Period 1: 2024 – 2025 Ordering Period 2: 2025 – 2026 Ordering Period 3: 2026 – 2027 Ordering Period 4: 2027 – 2028 Ordering Period 5: 2028 – 2029 Ordering Period 6: 2029 – 2030 Ordering Period 7: 2030 – 2031 Ordering Period 8: 2031 – 2032

1.10 OBSERVANCE OF FEDERAL HOLIDAYS

The contractor shall observe Federal holidays and other days identified in this section unless otherwise indicated in individual contracts. The Government observes the following days as holidays:

(1) New Year's Day (January 1)

2032H5-24-Q-00009 PAGE 6

(2) Birthday of Martin Luther King, Jr. (Third Monday in January)

(3) Washington's Birthday (Third Monday in February)

(4) Memorial Day (Last Monday in May)

(5) Juneteenth (June 19)

(6) Independence Day (July 4)

(7) Labor Day (First Monday in September)

(8) Columbus Day (Second Monday in October)

(9) Veterans Day (November 11)

(10) Thanksgiving Day (Fourth Thursday in November)

(11) Christmas Day (December 25)

In addition to the days designated as holidays, the Government may also observe the following days:

(1) Any day designated by Federal Statute; Executive Order; or President’s Proclamation

Notwithstanding holidays and Government closures, the contractor shall perform in accordance with the terms established in the associated contract.

1.11 OVERTIME

Overtime hours can only be approved by the Contracting Officer’s Representative (COR). Overtime will be in accordance with the underlying GSA Schedule contract.

2.0 SERVICES AND PRICES/COSTS

The quoter is required to price each ordering period. The rates must be at or below the rates listed on the contractor’s MAS IT.

The work shall be performed in accordance with all sections of this RFQ and the quoter’s contract awarded under the GSA MAS IT HACS SIN. The contractor must be listed within the HACS SIN. Quotes that are not associated with an active GSA MAS IT contract with the awarded HACS SIN will not be considered. Release of this RFQ does not guarantee issuance of an award.

2.1 CONTRACT LINE-ITEM NUMBER (CLIN) STRUCTURE

Refer to the Performance Work Statement (PWS) under Attachment 2 for a complete description of the requirements. The Government reserves the right to make an award for any or all the contract line items listed below.

2032H5-24-Q-00009 PAGE 7

Ordering Periods - 12 Months each Indicate all applicable MAS IT labor categories, rates, and any discounts offered. When there are several levels of a given labor category in an MAS IT contract, please indicate which level you are referencing in your pricing matrix. Also, this is to be reflected in the ordering period(s).

See Attachment 1 for PROTECTS Price Template.

3.0 Performance Work Statement (PWS)

3.1 See Attachment 2 for PROTECTS Performance Work Statement (PWS)

4.0 DELIVERABLES, INSPECTION, AND ACCEPTANCE

4.1 SCOPE OF INSPECTION

All deliverables will be inspected by the COR for content, completeness, accuracy and conformance under this agreement and the specifics of the project.

4.2 BASIS OF ACCEPTANCE

The basis for acceptance shall follow the requirements set forth in the PWS, the contractor's quote and other terms and conditions of the contract. Deliverable items rejected shall be corrected in accordance with the applicable provisions.

(1) Reports, documents, and narrative type deliverables will be accepted when all discrepancies, errors or other deficiencies identified, in writing, by the Government have been corrected.

(2) If the draft deliverable is adequate, the Government may accept the draft and provide comments for incorporation into the final version.

(3) All the Government's comments to deliverables must either be incorporated in the succeeding version, or the contractor must demonstrate, to the Government's satisfaction, why such comments should not be incorporated.

(4) If the Government finds that a draft or final deliverable contains spelling errors, grammatical errors, improper format, or otherwise does not conform to the requirements stated within this contract, the document may be immediately rejected without further review and returned to the contractor for correction and re-submission. If the contractor requires additional Government guidance to produce an acceptable draft, the contractor shall arrange a meeting with the

COR.

The contractor shall deliver all formal products concurrently to the Bureau/DO Task Lead, Government Technical Monitor (GTM), COR and CO as required. Electronic

2032H5-24-Q-00009 PAGE 8

transmission shall be the primary delivery mechanism; however, hard copies will be provided as appropriate. All products shall be scanned for malware prior to submission.

• Completeness – Initial requirements (as identified) are satisfied in all sections.

• Accuracy – Documents shall be accurate in presentation, technical content, and adherence to accepted elements of style.

• Clarity—Documents shall be clear and concise; project management and terms shall be used, as appropriate. All diagrams shall be easy to understand and be relevant to the supporting narrative.

• Specification Validity—all deliverables must satisfy the requirements of the U.S.

Government as specified herein.

• File Editing—All text and diagrammatic files shall be provided in Microsoft Office Version 2010 or higher (Word, Excel, PowerPoint, Visio, etc.) so that they can be edited by the U.S. Government.

• Format—Documents shall be submitted electronically whenever possible.

Hardcopies shall be provided upon request. The document’s format may change from Subtask to Subtask.

• Timeliness—Deliverables shall be submitted on or before the due date specified in the Schedule of Deliverables Section of this Proposal or submitted in accordance with a later scheduled date determined by mutual agreement between the GTM and the contractor Project Leader.

Generally, all work performed under a TO shall comply with Bureau/DO directives, instructions, and standards. Exceptions may be made on a case-by-case basis.

Additional and unique acceptance criteria to specific deliverables shall be specified at the TO level.

The GTM or COR shall notify the contractor of deliverable acceptance or provide comments in writing within ten (10) Government workdays of receipt of a deliverable.

Within ten (10) Government workdays, the contractor shall resubmit the final deliverable to the GTM, COR and CO, if necessary.

4.3 DRAFT AND FINAL DELIVERABLES

All deliverables shall meet professional standards and meet the requirements set forth in contractual and task order documentation. The contractor shall provide all deliverables in electronic format to the Bureau/DO, and other than software, all documents shall be provided using Microsoft Word, Excel, PowerPoint, Visio, or as otherwise needed (such as in Tableau or Adobe .pdf) formats pursuant to the following schedule. The deliverables are not to be separately priced but shall be included in the monthly price.

2032H5-24-Q-00009 PAGE 9

All electronic artifacts shall be delivered through encryption-protected channels according to the specifications within the FIPS 140 series and other Federal, Treasury, and Bureau/DO guidelines, regulations, and requirements. Specifically, cryptomodules used for encrypting electronic artifacts must be listed by NIST as having been validated under the requirements of FIPS 140-2 (if validated prior to September 22, 2019, and not used after September 22, 2026) or FIPS 140-3 and its approved successor FIPS 140 standards. Electronic artifacts must be protected at rest and in transmission in accordance with appropriate Bureau/DO policies.

The contractor will write documentation in clear, concise language that is verifiable. The contractor shall produce final documents without typographic and grammatical errors.

All documents shall be formatted according to standards provided by the Government.

The contractor shall send all electronic deliverables to the designated Bureau/DO Task Lead/GTM/COR, with copies of monthly, quarterly, and annual formal deliverables also sent to the Contracting Officer (CO).

All written deliverables require at least two iterations – a draft and a final. The final document must be approved and accepted by the Government prior to payment submission. The contractor shall submit draft and final documents, using prescribed formats to the Government electronically. The Government requires ten (10) business days for review and submission of written comments to the contractor on draft documents. The contractor shall revise the deliverables to make any necessary corrections and incorporate the Government’s comments into final deliverables before submission. Upon receipt of the Government’s comments, the contractor shall have ten

(10) business days to incorporate the Government’s comments and/or change requests and to resubmit the deliverable in its final form.

Any issues that cannot be resolved by the contractor in a timely manner shall be identified and referred to the COR.

The following table provides the initial contractor work product delivery schedule and should not be considered all inclusive. Additions and adjustments to deliverables, schedules and frequency will be made within specific TOs.

TASK DELIVERABLE FREQUENCY SCHEDULE

2.2 Meeting Briefings/

Presentations As needed No later than (NLT) three

(3) business days prior to scheduled meeting

2.2.1 SOC Support

Services Program Management Plan

Annually NLT fifteen (15) calendar days after award and annually thereafter

2.2.1 TO Status Updates Weekly Fridays

2.2.1 TO Status Reports Monthly NLT 15th of each month

2.2.1 TO Quarterly Quarterly Quarterly intervals

2032H5-24-Q-00009 PAGE 10

Performance Reports starting NLT sixty (60) business days after award

2.2.2 SOC

Communications Plan

Annually NLT fifteen (15) calendar days after award and annually thereafter

2.2.3.2 SOC Incoming

Transition Plan

As needed NLT fifteen (15) business days after award

2.2.3.3 SOC Outgoing

Transition Plan

As needed NLT ninety (90) days prior to end of TO

2.2.5.1 Contractor SOC

Performance and Investment Metrics Program Summary Briefings

Bi-weekly Bi-weekly intervals starting NLT fifteen (15) business days after award

2.2.5.1 Contractor SOC

Performance and Investment Metrics Report

Quarterly Quarterly intervals starting NLT sixty (60) business days after award

2.3 Daily Summary

Informal Reports

Daily Daily intervals starting three (3) business days after award

2.3 Incident Analysis

Reports

As needed NLT fifteen (15) business days after task assignment

2.3, 2.4.1, 2.4.2, 2.4.4, 2.6

Automated reporting and query interface(s) for status and events: e.g., ticketing; system configuration data;

vulnerability scan data; threats and vulnerability repository; audit logs;

inventory data

Updated at no more than thirty

(30) min intervals

Available 24h x 365 days/yr., starting five (5) business days after award

2.3, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.9

Tactical Configuration Change Documentation

As needed As soon as practical, but not to exceed four (4) hours.

2.3.4 Forensic DMA

Report of Findings

As Needed NLT fifteen (15) business days after task

2032H5-24-Q-00009 PAGE 11

assignment

2.3.6 Fly-Away Kit Annually NLT fifteen (15) calendar

days after award and annually thereafter

2.3.7 Information Systems

Continuity and Disaster Recovery Plans

As needed NLT thirty (30) business days after task assignment

2.4.1 Network Map Quarterly Quarterly intervals

starting NLT sixty (60) business days after award

2.4.2 Vulnerability

Scanning Risk Assessment

Weekly NLT three (3) business days after completion of scan

2.4.3 Vulnerability

Assessment Report of Findings

Per assessment NLT fifteen (15) business days after conclusion of assessment

2.4.3.1 Phishing Assessment

Report

Per assessment NLT fifteen (15) business days after conclusion of assessment

2.4.3.2 Wireless Assessment

Report

Per assessment NLT fifteen (15) business days after conclusion of assessment

2.4.3.3 Web Application

Assessment Report

Per assessment NLT fifteen (15) business days after conclusion of assessment

2.4.3.4 OSSA Report Per assessment NLT fifteen (15) business

days after conclusion of assessment

2.4.3.5 Database

Assessment Report

Per assessment NLT fifteen (15) business days after conclusion of assessment

2.4.4 Bureau/DO

Vulnerability Alerts

As needed Timelines based on severity and Bureau/DO guidance

2.5.1 Adversary Threat Set

Profiles

Weekly Weekly intervals starting NLT ten (10) business days after award

2.5.2 Bureau/DO Specific

Intelligence Tippers

As Needed As soon as practical

2.5.2 Cyber Intelligence Weekly Weekly intervals starting

2032H5-24-Q-00009 PAGE 12

Reports NLT ten (10) business days after award 2.5.2, 2.6.10, 2.7.1, 2.7.2

Training and Exercise support materials

As needed NLT twenty (20) business days after task assignment

2.5.3 Threat Hunting

Analysis Report

Per mission NLT twenty (20) business days after task assignment

2.5.4 Summary Reports Daily Daily intervals starting

three (3) business days after award

2.5.5 Penetration Testing

Report of Findings

Per assessment NLT fifteen (15) business days after conclusion of assessment

2.5.5 Rules of

Engagement

Per assessment NLT thirty (30) days prior to assessment start

2.6.1 Cybersecurity

Architecture and Strategy Recommendations

As needed NLT twenty (20) business days after task assignment

2.6.2 SAR Report As needed NLT thirty (30) business

days after task assignment

2.6.3 Market Research

Reports for New Hardware and Software

As needed NLT twenty (20) business days after task assignment

2.6.3 Automation and

Orchestration Playbooks

As needed NLT thirty (30) business days after task assignment

2.6.3 Change and Release

Design Documentation

As needed NLT twenty (20) business days after task assignment

2.6.3 SOC Tool

Engineering Design Documentation

As needed NLT thirty (30) business days after task assignment

2.6.3 Test Plans for New

and Existing Security Solutions

As needed NLT twenty (20) business days after task assignment

2.6.3 “End-to-End” Configuration Flow Diagrams

As needed NLT twenty (20) business days after task assignment

2032H5-24-Q-00009 PAGE 13

2.6.4 ISSE operations

modifications recommendations

As needed NLT twenty (20) business days after task assignment

2.6.4 ISSE alternative

operations solutions documentation

As needed NLT twenty (20) business days after task assignment

2.6.4 ISSE end-to-end

architecture tradeoff assessment

As needed NLT forty-five (45) business days after task assignment

2.6.4 ISSE strategic plans As needed NLT forty-five (45)

business days after task assignment

2.6.4 ISSE tactical plans As needed NLT fifteen (15) business days after task assignment

2.6.4 ISSE implementation

plans and strategies

As needed NLT thirty (30) business days after task assignment

2.6.4 ISSE standards As needed NLT forty-five (45)

business days after task assignment

2.6.4 ISSE new program

requirements recommendations

As needed NLT twenty (20) business days after task assignment

2.6.4 ISSE operations

technology recommendations and capabilities

As needed NLT thirty (30) business days after task assignment

2.6.5 Ports, Protocols, and

Services Matrix

Monthly NLT 15th of each month

2.6.5, 2.6.6 Filtering Rules / Exceptions Validation Results Report

Quarterly Quarterly intervals starting NLT sixty (60) business days after award

2.6.5, 2.6.6, 2.6.7, 2.6.8

Standard operating procedures (SOPs) and maintenance documentation

Annually NLT thirty (30) business days after award and annually thereafter

2.6.9 Detection Signature

Review Results Report

Quarterly Quarterly intervals starting NLT sixty (60) business days after award

2032H5-24-Q-00009 PAGE 14

2.6.11 SOC Technology

Prototypes As needed Sixty (60) to ninety (90) days after task assignment

2.7.2 Basic Cyber Range

Capability

Daily Daily intervals starting NLT thirty (30) business days after award

2.7.2 Expanded Cyber

Range Capability

Quarterly Quarterly intervals starting NLT sixty (60) business days after award

2.7.3 Routine Knowledge

Capture

Daily Daily intervals starting NLT ten (10) business days after award

2.7.3 Knowledge

management content

As needed NLT ten (10) business days after task assignment

Note: The contractor shall deliver electronically to the email addresses detailed in the specific task order via means required by applicable Bureau/DO policies for secure email transmission.

All deliverables will meet requirements as described under the tasks in clear, concise, well-written language, and in accordance with the applicable PWS. Accordingly, the quality measures (acceptance criteria) as set forth below will be applied to each work product or deliverable received from the contractor under this Proposal.

Services Delivery Summary (SDS)

The Services Delivery Summary (SDS) represents the most important BPA objectives that, when met, shall ensure BPA performance is satisfactory. Although not all PWS requirements are listed in the SDS, the contractor is fully expected to comply with all requirements in the PWS. Additions and adjustments to performance objectives and thresholds may be made within specific TOs.

Task Performance Objective Performance Threshold

2.2 Trip Reports

98% of the time Trip Reports are received within five (5) business days after completion of travel and contains all details related to the trip and information on the traveler.

2.2 Meeting/Conference Minutes

98% of the time minutes are provided within two (2) business days upon request by the Government and

2032H5-24-Q-00009 PAGE 15

contain all results and impacts of the meeting/conference.

2.2.2 Staffing Level and Retention Positions are staffed at >90% of plan measured monthly.

2.2.2 Staff Certifications 100% of contractor staff hold required certifications.

2.2.2 Staff Mix

Staff resource mix is maintained within 20% of originally awarded resource mix.

2.2.5.2, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.7.3

Process and Procedure Documentation Quality

98% of the time, documentation accurately reflects current operational processes and procedures; tool and system references; organizational references and contact information;

and policy references.

2.2.5.2, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.7.3

Process and Procedure Documentation Timeliness

No more than one (1) late document per month and no more than five (5) days late. For final deliverables, no more than two sets of corrections/edits and all corrections must be accomplished within two (2) days, or other such time periods as mutually determined between the government and the tasked contractor.

2.3, 2.4, 2.5, 2.6 Security Operations

100% of the time, no successful intrusions into the networks under the contractor’s control due to negligence or deviation from established procedures in performing actions specified by this task.

2.3, 2.4, 2.5, 2.6

On-the-Job Skills Practical Evaluation

100% of the time, evaluations are completed prior to contractor staff being granted privileged access to SOC systems.

2.3.1 Incident Response

95% of the time, review all incidents flagged by monitors within fifteen (15) minutes of detection.

2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, Incident Tickets Generation, Assignment, Acknowledgement, Notification, Escalation, and Resolution

95% of the time incident ticket generation, assignment, acknowledgement, notification, escalation, and resolution occurs within standard timeframes established by

2032H5-24-Q-00009 PAGE 16

2.3.6 Bureau/DO.

2.3.1, 2.3.2, 2.3.3, 2.5.1, 2.5.2

On-call Support

Ops Center is able to contact the on-call technician nine (9) of every ten (10) attempts made outside of normal duty hours.

2.3.6 Fly-Away Incident Response

98% of the time, team is ready to deploy within twenty-four (24) hours of notification.

2.4, 2.6.2

Accurate and timely security assessments, in prescribed format, in accordance with the engineering principles outlined in NIST SP 800-160

Content: No more than one (1) deviation per month from established principles and directives. 100% of assessments will address all required elements and consider security functionality from existing Bureau/DO Enterprise Architecture.

Format: No more than one (1) late document per month and no more than five (5) days late. For final deliverables, no more than two sets of corrections/edits and all corrections must be accomplished within two (2) days, or other such time periods as mutually determined between the government and the tasked contractor.

2.4.1, 2.4.2, 2.4.3.1, 2.4.3.2, 2.4.3.3, 2.4.3.4, 2.4.3.5

Accurate and timely configuration of vulnerability management and scanning environment resources as required by vulnerability management plan and government requirement

No more than three (3) total days delay per month to all vulnerability management activities attributable to improper or late configuration of environments. All improper configurations identified and corrected within 1 workday

2.6.5, 2.6.6, 2.6.7, 2.6.8

Uptime for Cyber/Information Security Infrastructure Mechanisms

99.9% availability as measured per month must be maintained for all cyber security defense, and intrusion detection monitoring, incident management and change management services (e.g., firewall protection service for a specific area of coverage must be operational 99.9% of the time).

2.6.5, 2.6.6, Unplanned Outage or Operational Anomalies

100% of the time, provide notification to the customer IT Operations Center for

2032H5-24-Q-00009 PAGE 17

2.6.7, 2.6.8

Notifications unplanned outages and / or operational anomalies within fifteen (15) minutes of detection.

2.6.5, 2.6.6, 2.6.7, 2.6.8

Software and Operating System Versions

100% of the time security mechanisms are running supported software versions and are up to date (deployed within ten (10) days from vendor release) on security vulnerability patches with any exceptions approved by government in writing

2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.7.2

Planned Downtime Coordination and Execution

100% of the time, planned downtime must be scheduled at least a week in advance and executed in a manner that remaining online infrastructure can compensate for the offline system.

2.7.2 Cyber Range Environment

95% of the time, the cyber range environment is operational to support training and exercise events.

Cyber range environment supports at least five (5) concurrent users on a daily basis and expands to support fifteen (15) concurrent users quarterly for exercise events.

2032H5-24-Q-00009 PAGE 18

5.0 CONTRACT ADMINISTRATION INFORMATION/DATA

5.1 PROCURING CONTRACTING OFFICER (CO)

The procuring CO has overall responsibility for administering the contract. The procuring CO shall perform all contract administration. The name and contact information of the CO is:

Jon Carney Contracting Officer Phone: 585-262-1134 E-mail: Jonathan.w.carney@irs.gov

5.2 CONTRACTING OFFICER’S AUTHORITY

The CO is the only person authorized to approve changes in any of the requirements of the contract/task order.

5.3 CONTRACTING OFFICER’S REPRESENTATIVE (COR)

COR APPOINTMENT AND AUTHORIZATION. Should the CO appoint a COR, it shall be in writing for any contract/task order issued under this RFQ. The COR provides technical review of deliverables, invoice servicing, and facilitating payment. The name and contact information of the COR is:

Shawn Roskosky Contracting Officer’s Representative (Primary) Phone: 202-603-1776 E-mail: shawn.roskosky@treasury.gov

Ben Porter Contracting Officer’s Representative (Alternate) Phone: 202-436-5840 E-mail: bernard.porter@treasury.gov

Diago Stinson Contracting Officer’s Representative (Alternate) Phone: 202-924-4893 E-mail: diago.stinson2@treasury.gov

(1) The Department of Treasury COR will receive, for the Government, all work called for by the contract/task order and will represent the CO in the technical phases of the work. The COR will provide no supervisory or instructional assistance to contractor personnel.

2032H5-24-Q-00009 PAGE 19

(2) The Department of Treasury COR is not authorized to change any of the terms and conditions of the contract/task order. Changes in the scope of work shall be made only by the CO by properly executed modifications to the contract/task order. Additional responsibilities of the Department of Treasury COR include:

(a) Monitor the contractor’s performance to ensure compliance with the technical requirements of the contract/task order.

(b) Review and approval of progress reports, technical reports, etc. which require Government approval.

(c) Verify and certify that the items have been inspected and meet the requirements of the contract/task order.

(d) Notify the CO immediately if performance is not proceeding satisfactorily.

(e) Ensure that changes in work under the contract/task order are not initiated before written authorization or a modification is issued by the CO.

(f) Provide the CO a written request and justification for changes.

(g) Furnish interpretations relative to the meaning of technical specifications and technical advice relative to CO approvals.

(h) Inspect and accept service and deliverables, including visiting the place(s) of performance to check contractor performance, as authorized by contract/task order inspection clause on a non-interference basis. This may include, but is not limited to, evaluation of the following:

(i) Actual performance versus schedule and reported performance.

(ii) Changes in technical performance which may affect financial status, personnel or labor difficulties, overextension of resources, etc.

(iii) Verification that the number and level of the employees charged to the contract/task order are actually performing work under the contract/task order.

(i) At the completion of the contract/task order, advise the CO concerning the following:

2032H5-24-Q-00009 PAGE 20

(i) All articles and services required to be furnished and/or performed under the contract/task order have been technically accepted.

(ii) Contractor compliance with patent rights and royalties’ clauses of

(iii) Recommend disposition of any Government furnished property in possession of the contractor.

(iv) Verify proper consumption and use of Government furnished property by the contractor.

(v) Prepare a performance report detailing compliance with requirements, quality assurance, timely completion, and any problems associated with the contract/task order.

(3) The contractor is advised that only the CO, acting within the scope of this contract/task order and the CO’s authority, has the authority to make changes which affect contract/task order prices, quality, quantity, or delivery terms.

(4) The Department of Treasury COR will furnish technical advice to the contractor to provide specific details, milestones to be met within the terms of the contract/task order, and any other advice of a technical nature necessary to perform the work specified in the contract/task order. The Department of Treasury COR shall not issue any instructions which would constitute a contractual change.

5.4 INVOICE SUBMISSION AND CONTENT

The contractor shall submit Request for Payments in accordance with IR1052.232-9001 Electronic Invoicing and Payment Requirements for the Invoice Processing Platform (IPP) (Jul 2019)

Invoices shall be sent to the following:

www.ipp.gov

6.0 SPECIAL CONTRACT REQUIREMENTS

6.1 KEY PERSONNEL

This RFQ is not for a personal services contract. Accordingly, the quoter must designate appropriate and sufficient supervisory personnel to meet task outcomes. Quoter’s supervisor shall provide day-to-day supervision of all contract personnel including, but not limited to, work assignments and performance monitoring, coverage, payroll

2032H5-24-Q-00009 PAGE 21

records, leave approval and monitoring, etc. At no time will contract personnel be supervised by Department of Treasury’s managers or other Department Office (DO) personnel. The Department of Treasury and DOs will provide, as needed by the quoter and its employees, limited assistance in the form of technical and policy guidance through the assigned COR.

The contractor shall provide and supervise the skilled personnel required for the effective and efficient performance of this contract. All proposed personnel performing risk and vulnerability testing shall hold a current, active, and favorably adjudicated U.S.

Government background investigation, minimum Office of Personnel Management Tier 2 (Background Investigation)) in which Department of Treasury can accept reciprocity. The descriptions located in Attachment 6, PROTECTS Labor Category Descriptions, represent the minimum requirements for each labor category.

Experience refers to actual directly related and applicable experience.

The contractor shall identify one person as the lead and key personnel who shall provide management, administrative, and technical interface between Government and contractor personnel in the day-to-day performance of the contract. An important element of this requirement is the ability for the contractor to provide expertise as needed.

The CO shall, in coordination with the COR, approve individuals designated as key personnel throughout the course of the contract.

All key personnel are subject to the following:

The key personnel specified in Attachment 6 are essential to work performance. At least 30 days prior to the contractor voluntarily diverting any of the specified individuals to other programs or contracts, the contractor shall notify the CO and shall submit a justification for the diversion or replacement and a request to replace the individual. The request must identify the proposed replacement and provide an explanation of how the replacement's skills, experience, and credentials meet or exceed the requirements of

6.2 QUALIFICATIONS

The vendor shall clearly indicate offered qualifications and experience for all proposed key personnel as outlined in Attachment 5, PROTECTS Resume Template. The key personnel are Chief Cyber Security Engineer, Program Manager, SOC Project Manager as outlined in Attachment 6, PROTECTS Labor Category Descriptions.

6.3 KEY PERSONNEL REPLACEMENT

If an employee of the contractor is terminated for cause or separates from the contractor voluntarily with less than 30 days’ notice, the contractor shall provide the maximum

2032H5-24-Q-00009 PAGE 22

notice practicable under the circumstances. The contractor shall not divert, replace, or announce any such change to key personnel without the written consent of the CO. The contract will be modified to add or delete key personnel as necessary to reflect the agreement of the parties.

Requests for replacement shall include:

● Detailed resume containing a description of position duties and qualifications, information about the qualifications of the individual(s) proposed, and any additional information requested by the CO in sufficient detail to permit the CO to evaluate the impact on the work the contractor is obligated to perform hereunder.

The Government reserves the right to review the qualifications of key personnel selected to work on this contract before assignment, including the contractor's proposed key personnel and any key personnel replacements The Government also reserves the right to reject proposed key personnel whom it determines not suitable for the program.

The Government also reserves this right in certain circumstances when specific key personnel are required for specific tasks.

6.4 KEY PERSONNEL SUBSTITUTION

Replacement of key personnel can be disruptive and interfere with the Government’s ability to accomplish the efforts in a timely manner. The potential impacts of a key personnel replacement can sideline the mission and impact the goals of the affected program office for a substantial amount of time. The contractor shall not remove or replace any personnel designated as key personnel for this contract, without the written concurrence of the CO. Prior to utilizing other than personnel specified in response to this RFQ, the contractor shall notify the appropriate CO and COR. This notification shall be no later than 14 calendar days in advance of any proposed substitution, and shall include justification, including resume(s) and labor category of each proposed substitution(s) in sufficient detail to permit evaluation of the impact on contractor performance (What are the circumstances surrounding the individual’s departure? Give a reason why you believe it is in the Government’s best interest to accept such a change, and how the Government can expect to maintain continuity in the efforts that are ongoing at present, considering the retraining and re-familiarization with our organization and assigned tasks that inevitably has to happen with the introduction of any new individual). The Department of Treasury/DOs CO and COR reserve the right to determine that the proposed substitute personnel are unacceptable, or that the reduction of effort would be so substantial as to impair the successful performance of the work under the contract/task order, the contractor may be subject to default action as prescribed by FAR 52.212-4 Alt I.

6.5 PERSONNEL ASSIGNMENTS

All personnel are subject to the following:

2032H5-24-Q-00009 PAGE 23

(1) The contractor shall provide staff to ensure all work is performed on schedule and by following best commercial practices. The contractor may move around the personnel to different roles/responsibilities, if necessary, upon the CO and COR’s approval.

(2) The list of personnel set forth may be amended from time to time during the contract period of performance in order to either add or delete personnel.

6.6 PERSONNEL REQUIREMENTS

The contractor shall provide staff to ensure all work is performed on schedule in accordance with the deliverables list. All staff interfacing with the Government shall be fluent in the English language, verbal and written.

6.7 SECURITY REQUIREMENTS INFORMATION SECURITY EQUIREMENTS

All work that is associated with Government information, systems, and information security must be in compliance with the Federal Information Security Modernization Act (FISMA) of 2014 as implemented by Federal Information Processing Standards Publication 200 (FIPS 200), “Minimum Security Requirements for Federal Information and Information Systems.” This standard specifies minimum-security requirements Federal agencies must meet. The appropriate security controls and assurance requirements to be selected are described in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev 4, “Security and Privacy Controls for Federal Information Systems and Organizations” and associated documents. Specific impact levels required (per FIPS 200) for government information and information systems may vary and will be specified as requirements are identified.

The U.S. Federal Government will conduct background checks and verify information submitted by the contractor employees, conduct fingerprint checks, and conduct other appropriate investigations. Investigations will include, but are not limited to, criminal record, credit worthiness, and prior work performance history. The contactor shall coordinate with the assigned COR to process background investigations for contractor staff supporting this effort.

The contractor shall comply with all information technology system security policies and procedures that apply to the Bureau/DO. All personnel providing services under the resultant TOs must meet all requirements to successfully complete the screening process. All contractor personnel providing support must achieve the basic screening process to work on-site.

Under Federal Information Security Modernization Act (FISMA), Government employees and contractors are subject to Federal information security laws, regulations, and policies. All contractor employees, providing support under the TO shall complete Bureau/DO mandatory training annually, which covers computer security, disclosure, 2032H5-24-Q-00009 PAGE 24 privacy, and Unauthorized Access (UNAX). In addition, each individual contractor employee shall sign a non-disclosure form. The contractor shall provide written certification to the COR that this training was completed.

National Industrial Security Program (NISP) Requirements The security requirements apply to the prime contractor and any subcontractors, herein “sub,” employed during this BPA; the language is written to the prime contractor, herein “contractor.” The security requirements also apply to tasks, work requests or other identified methods of requesting work that flow from this document. No contractor personnel may perform any work under this BPA until the Government grants specific permission to do so, regardless of existing clearance or investigation.

Contractor Facility Security Officers (FSOs) shall ensure no work performance commences until they have received an approved DD F 254.

The contractor shall ensure it has appropriate permission from the government prior to flowing down any proscribed information or accesses to its subs and shall ensure that DD 254s for subs are appropriately filled out given the accesses allowed the contractor and requirements of the subs contract.

The contractor is responsible for obtaining the approval of the CO or authorized representative prior to release of any information received or generated under the contract, classified or unclassified, per 48 Code of Federal Regulations (CFR) 252.204- 7000. The CO or authorized representative will direct the contractor to the appropriate office that has public release authority. Prime contractors shall serve as focal point for their subs’ public release requests and refer them to the CO or authorized representative.

The contractor shall not safeguard (store, handle, or process) Bureau/DO Classified National Security Information (CNSI) at their (or another contractor’s) facility.

6.8 PERSONNEL ACCESS TO GOVERNMENT INFORMATION AND

FACILITIES

For TOs requiring personnel clearances, contracted employees must have, prior to starting, and maintain favorably adjudicated security clearances at the Top Secret or Secret level, depending on the task, throughout the life of the BPA. Personnel security investigations conducted for access to CNSI shall be initiated by the contractor company through Department of Defense. Secret clearances must be favorably adjudicated at either the interim or final level. Top Secret clearances must be favorably adjudicated at the final level. The contractor shall provide a suitable, qualified, trained, and favorably adjudicated staff with the skills necessary to perform all support functions referenced in this BPA. Security/suitability requirements for personnel are found in Bureau/DO guidance, Treasury Directive Publication (TD P) 15-71, Executive Orders

2032H5-24-Q-00009 PAGE 25

(EOs) 13526 and 12968, and 5 CFR 731. All contractors must be vetted and approved by Personnel Security to have a security clearance commensurate with the level of the contract prior to beginning work on any portion of this contract.

Any employee assigned to support the Bureau/DO shall comply with Personal Identity Verification One and Two (PIV-1, PIV-2) requirements as described in Homeland Security Presidential Directive 12 (HSPD-12), “Policy for a Common Identification Standard for Federal Employees and Contractors,” and “Federal Information Processing Standard 201-2, Personal Identity Verification Standards for Federal Employees and Contractors,” dated August 2013, or replacement document.

6.9 CONTROLLED UNCLASSIFIED INFORMATION (CUI) STORAGE AND

DISCLOSURE

Controlled unclassified information (CUI), data, and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment shall be returned to the Government. The Government will determine the fate of such information, data, and/or equipment. If the Government determines that such information, data, and/or equipment is to be sanitized, it shall be accomplished in accordance with NIST SP 800-88 Rev 1, “Guidelines for Media Sanitization.”

6.10 PROTECTION OF INFORMATION

The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The contractor shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this contract should be considered as CUI. It is anticipated that this information will be gathered, created, and stored within the primary work location. If contractor personnel must remove any information from the primary work area, they shall protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.

6.11 CONFIDENTIALITY AND NONDISCLOSURE

The preliminary and final deliverables, all associated working papers, and any other materials generated by the contractor in the performance of the contract are the property of the U.S. Government and must be submitted to the COR at the conclusion of the contract. All documents produced for this project are the property of the U.S.

Government and cannot be reproduced or retained by the contractor. All appropriate

2032H5-24-Q-00009 PAGE 26

project documentation will be given to Department of Treasury/DOs during and at the end of this contract. The contractor shall not release any information without the written consent of the CO. Any request to the contractor for information relating to the resulting contract must be submitted to the CO for approval prior to release.

Personnel working on any of the described tasks, at the Government’s request, shall be required to sign formal nondisclosure and/or conflict of interest (COI) agreements to guarantee the protection and integrity of Government information and documents.

6.12 INDIVIDUAL NON-DISCLOSURE AGREEMENTS

The contractor’s employees assigned to any contract/task order under this contract/task order shall be required to sign contract specific Nondisclosure Agreements (NDAs) and/or Individual COI forms which become part of the Organizational Conflict of Interest (OCI) Plan.

6.13 GENERAL COMPLIANCE REQUIREMENTS

Department of Treasury/DO’s information systems are the property of the Government.

The contractor shall be responsible for adhering to all aspects of the Privacy Act and is prohibited from removing from the worksite any programs, documentation, or data without the knowledge and written approval of the COR.

6.14 INFORMATION TECHNOLOGY RESOURCES

In accordance with FAR 39.105, this section is included in the contract. This section applies to all users of sensitive data and IT resources, including awardees, contractors, subcontractors, lessors, suppliers, and manufacturers.

The following Department of Treasury/DOs policies must be followed. These policies will be provided at time of award.

The contractor and subcontractors must insert the substance of this section in all subcontracts.

6.15 ORGANIZATIONAL CONFLICT OF INTEREST (OCI)

The purpose of this clause is to protect the integrity of the procurement…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .