273FCC20F0051 - Security Testing and Evaluation - Logical Follow-On_redacted.pdf

PDF 51 KB Posted

Attached to
Security Testing and Evaluation (ST & E) Federal contract opportunity
Solicitation number
273FCC20F0051
Issued by
Federal Communications Commission

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

LIMITED SOURCES JUSTIFICATION (LSJ)

Security Testing & Evaluation (ST & E) Support for the Federal Communications Commission (FCC)

The acquisition that is the subject of this limited-sources justification is conducted under the authority of the Multiple-Award Schedule (MAS) Program article 40 USC § 501.

Limitation of sources is justified on the following facts, rationale, recommendations, and approvals pursuant to FAR 8.405-6(a).

1. Identification of the agency and the contracting activity, and specific identification of the document as a “Limited-Sources Justification” (LSJ).

This Limited-Sources Justification (LSJ) was prepared by the Federal Communications Commission (FCC), Office of the Managing Director (OMD) Enterprise Acquisition Center (EAC) located at FCC Headquarters 445 12th Street SW, Washington DC 20554. (The FCC Headquarters is moving to 45 L Street NE, Washington DC 20002 in June 2020.)

2. Nature and/or description of the action being approved.

It is the intent of the FCC’s OMD-Information Technology Center (ITC) program office to obtain information technology security test and evaluation (ST&E) audit, test, and assessment services in compliance with the Federal Information Security Modernization Act (FISMA) and the National Institute of Standards and Technology (NIST) best practices.

The ST&E services requirement is a logical follow-on order to the incumbent contractor pursuant to FAR 8.405-6(a)(1)(i)(C) for a base period of twelve (12) months, two (2), twelve (12) month option periods, and one six month option period in accordance with FAR 52.217-8, Option to Extend Services . This logical follow-on is necessary to significantly reduce the risk of internal and external compromise and penetration of FCC’s enterprise network by maintaining compliance and obtaining official management decisions for the organizational operation of FCC information systems.

The incumbent contractor is:

Intelipath Services Group, Inc.

5501 Cherokee Ave #202 Alexandria, VA 22312

3. A description of the supplies and/or services required to meet the FCC’s needs (including the estimated maximum potential value).

The work to be performed by the contractor includes travel and entails, at a minimum:

• Independent ST&E Support

• Continuous Monitoring Support

• External Audit Support

• IT Security Advisory in Support of the NIST Assessment and Authorization (A&A) Process

• Internal/External Web Application Penetrating Testing

• Plan of Actions & Milestones (POA&M) Closure Validation

Continuation of these services is vital to ensuring compliance and audit activities necessary for meeting Federal Information Security Modernization Act (FISMA) requirements to perform annual independent evaluations of their information security programs and practices and to report the evaluation results to the Office of Management and Budget (OMB). The objective of these evaluations is to determine the effectiveness of information security policies, procedures, and practices of the FCC's and the Universal Service Administrative Company's (USAC) information systems, including compliance with FISMA and related information security policies, procedures, standards, and guidelines.

As well, the FCC is working to close Government Accountability Office (GAO) audit recommendations on program compliance, efficiency and effectiveness, fiscal management, and specifically, risk management and technology. Federal agencies are being reviewed to see how the cyber risks are coordinated with the agency’s enterprise risk management (ERM) program. GAO’s audit reviewed procedures, relevant regulations, guidance, and assessed the documents against applicable criteria, including federal internal control standards, FCC’s Strategic Plan, and GAO’s fraud risk framework. In August 2019, FCC developed a new Fraud Division to focus on investigating fraud in the Universal Service Fund’s programs. FCC is in the middle of implementing an anti-fraud strategy for high-cost programs. One of the activities in the ST&E program is regular risk assessment to assure that it can prevent or detect the types of risks that have previously occurred. The current ST&E contract team, Intelipath Services Group (Intelipath) helps the FCC effectively manage and respond to risks.

During the coordinated assessments, Intelipath actively works on a risk-based approach to cybersecurity by effectively identifying, prioritizing, and managing cyber risk.

Currently, these services are being rendered under the General Services Administration (GSA) Federal Supply Schedule (FSS) order GS-35F-296DA / FCC17G0022. The current order includes firm-fixed price (FFP) contract line item numbers (CLINs) and ends March 26, 2020.

The estimated amount of the logical follow-on required tasks for the order is $XXXXXX for one (1) twelve (12) month base period, two (2) twelve (12)month option periods, and one(1) six (6)month option period in accordance with FAR 52.217-8, Option to Extend Services.

Base Period 12 months $ XXXXXXXX

Option Period 12 months $ XXXXXXXX

Option Period 12 months $ XXXXXXXX

Option to Extend 6 months $ XXXXXXXX

TOTAL $ XXXXXXXXX

4.The authority and supporting rationale and, if applicable, a demonstration of the proposed contractor’s unique qualifications to provide the required supply or service.

As defined in FAR 8.405-6(a)(l)(i)(C), it is in the interest of economy and efficiency that the order for continued support by the incumbent contractor be placed as a logical follow-on to an original FSS. The original order with Intelipath was competitively awarded in accordance with the applicable FSS ordering procedures. Intelipath can provide the best value to the Government.

Given the Intelipath team’s intimate knowledge of the FCC information system environments and the remaining existing open POAMs, they are best suited to complete progress activity and validate the remediation/closure of their identified security POAMs and assess the remaining FCC systems as part of the ATO process.

In addition, the IT Security Office has brand new contractor teams for network security operations (NSOC), security engineering, and information system security officers (ISSOs). Maintaining continuity and familiarity of information technology security personnel with the FCC System Owners is imperative to the success of the Commission’s ATO and compliance goals.

Aside from the efficiency in completing assessments and starting the ATO process, the ST&E team’s thorough understanding of FCC’s current technological requirements and solutions has benefited the different FCC Offices and Bureaus in identifying solutions that align with the Commission’s IT objectives and utilize current FCC technical capabilities.

Intelipath has completed ST&E assessments and initial security Authorization To Operate (ATO) for FCC System boundaries required to undergo the Federal Information Security Management Act (FISMA) mandated process. To date, the team has identified 13 critical and 86 high risk IT security issue POAMs spanning requirements per FISMA.

The ST&E team has tracked and validated closure of 77% of those identified critical and high risk POAMs. The work of Intelipath has significantly supported the reduction of FCC FISMA audit findings as the work completed in prior fiscal years has reduced the Commission’s overall number of FISMA findings by 70% and they are diligently working to resolve the remaining findings.

The Authority to Operate decision that culminates from the security authorization process of an information technology system in the US Federal Government is a unique industry requiring specialized practices. Although there are capable ISSO and IV&V vendors that can conduct the Assessment and Authorization (A&A) process, it is not feasible for a new contractor to begin the Initial ATO phase in the middle of the six-step Risk Management Framework (RMF) process (already underway at FCC) or begin work transitioned from another contractor in the middle of the process.

A substantial schedule delay would currently be anticipated if the FCC were to change ST&E teams while coordinating implementation of the individual, compensating, system, and common controls for all of the identified FCC inventory of systems in fiscal year

(FY) 2020. Efforts to meet completion dates previously reported to GAO would include increased cost for resources for ongoing work that cannot be compromised and also include appropriate transition. The delays would adversely impact the reported schedule of closure for open GAO recommendations.

An alternate contractor would take considerable time to reach the same required level of competence currently being performed, at cost not included in the budget. It has been determined that transition periods range from 30-90 days from an incumbent contractor to a new contractor, at a minimum. The increased cost for adding transition time and the learning curve could delay the schedule by three or more months while increasing costs to have both contracts performing simultaneously to complete transition. Assuming the costs for transition-out and transition-in are the same as the current contract monthly burn, the increased cost for both contract transition periods is a little over $XXXX; that amount is not currently in the budget, as it was not planned or anticipated to have the volume and level of FISMA remediation activities currently being conducted this fiscal year.

While the Commission is in this period of seeking initial security ATOs for its system boundaries, achieving the current FCC Continuous Monitoring (CM) assessment goal is predicated on having an ST&E team familiar with the FCC IT environment, as the learning curve associated with potentially bringing in a new team will cause significant negative impact to meet the planned timelines provided to GAO for successful audit reporting.

5. A determination by the Contracting Officer that the order represents the best value consistent with FAR 8.404(d).

The Contracting Officer has determined that issuing the proposed Task Order to Intelipath Group Services for the Security Testing and Evaluation (ST & E) Support represents the best value and will result in the lowest overall cost, considering price and administrative costs, to meet the Government’s needs. This task order will be awarded in accordance with FAR 8.404, “Use of Federal Supply Schedules” and the terms and conditions of the original, conformed task order.

The General Services Administration (GSA) has already negotiated fair and reasonable pricing rates and the price for this extension task order will be analyzed based on those rates as negotiated in the current task order. The Contracting Officer will also consider and local guidance regarding the use of FSS pricing. Additionally, prior to issuance of the task order, the ordering activity will consider the level of effort and the mix of labor categories proposed to perform the specific task being ordered in order to determine that the total price is reasonable. The contractors labor mix and level of effort will also be compared to the Independent Government Cost Estimate (IGCE).

6. Determination by the Contracting Officer that the anticipated cost to the

Government will be fair and reasonable.

GSA has already determined the prices of the supplies and services under FSS schedule, including prices for services offered at fixed hourly rates, to be fair and reasonable. By placing an order against a schedule using the procedures in FAR 8.405, the ordering activity CO has concluded that the order represents the best value (see FAR 2.101) and will provide the lowest overall cost alternative to meet the Government’s needs.

The proposed level of effort and labor mix will be evaluated to determine that the final price is fair and reasonable per FAR 8.405-2(d). Proposed order rates will be compared with the basic contract rates and verified as fair and reasonable.

While Intelipath’s efforts have significantly improved the FCC’s information security posture through audit activities, Intelipath’s talents are still also needed to fully implement the information security policies and procedures and resolve the longstanding weaknesses in the FCC information security program and systems. Specifically, Intelipath support is needed to focus on certain security control areas, particularly Risk Management, Identity and Access Management, and Information Security Continuous Monitoring already started/implemented. The FCC IT infrastructure is still comprised of many legacy systems and it has become a priority to modernize these systems to reduce operational costs as well as improve its cybersecurity posture.

The Intelipath team has proven over the last three years that they possess the necessary technical and assessment capabilities needed to perform and deliver ST&E assessments, audits, and compliance services in FCC’s highly demanding and diverse environment.

These are specifications of a functional nature and the solutions designed and performed by Intelipath provide the means to ensure the best value approach at a price considered worth spending for continued work in the immediate future. Intelipath’s support remains the best value to the government in successfully completing the information security technology audits, tests, and assessments, scheduled to date, through March 2021.

7. A description of the market research conducted among GSA schedule contract holders and the results or a statement of the reason market research was not conducted.

Prior to placing the current order, market research revealed several FSS schedule holders capable of fulfilling the requirement under the General Services Administration (GSA) Information Technology Schedule 70, Special Item Number (SIN) 132-51.

The current order was competitively evaluated and placed with Intelipath and a new order will be placed as a logical follow-on to the incumbent vendor for the new effort which is a continuation of work being performed under order GS-35F-296DA. In accordance with FAR Part 8, Required Sources of Supplies and Services, internet searches regarding the incumbent’s GSA Schedule current published price lists and past history were the potential sources reviewed. Once the acquisition approach was determined to focus on a logical follow-on as a continuum of best value, no further market research was conducted among GSA Schedule holders beyond Intelipath Services Group.

8. Any other facts supporting the limited sources justification.

The ST&E team has proven they possess the necessary capabilities required during their performance and delivery of the following:

• Compliance and Audit Support Services

• Continuous Monitoring Support

• External Audit Support

9. A statement of the actions, if any, the agency will take to remove or overcome any barriers that led to restricted consideration before any subsequent acquisition for supplies and services is made.

It is the policy of the EAC to follow the requirements of the FAR when making FSS schedule procurements. In this case, the specific requirements can only be met in this situation by limiting sources in accordance with FAR 8.405-6. Contractors were given a fair opportunity to be considered for the original order and the new effort will be based on continuing work efforts initiated in the final option period based on the GAO information technology audit recommendations. ST&E is a recurring examination and analysis of the safeguards required to protect an information system, as applied in an operational environment, to determine security posture. After this contract expires, FCC OMD ITC anticipates acquiring these ongoing contract services through contract competition.

10. Program Office Requisitioner’s Certification:

I certify that the facts and representations under my cognizance which are included in and form the basis for this justification are complete and accurate.

Signature Date Print Name:

Title:

11. Program Office - Senior Official Concurrence and Recommendation:

I have reviewed this justification and the certification above and concur that supporting data, developed by the program office technical personnel, contained or relied upon in this LSJ are complete and accurate. I recommend approval of this justification based upon the circumstances described herein.

Signature Date Print Name:

Title:

12. Contracting Officer Certification:

This is to certify that the justification for the proposed acquisition is accurate and complete to the best of my knowledge and belief and that it has been reviewed and certified by the appropriate program or technical personnel as to supporting data for which they are responsible

Official Name Signature Date

FCC

Contracting Officer

Joyce Terry-Butler

13. Head of Contracting Activity (HCA) Concurrence/Approval/

FCC Head Contracting Activity

14. Senior Procurement Executive (SPE) Concurrence/Approval

FCC Senior Procurement Executive

File details come from the government source that posted it. Updated .