FAR 6.302 (Open Market) Justification and Approval - Bug Bounty_Redacted.pdf
PDF 3 MB Posted
- Attached to
- Bug Bounty SaaS Federal contract opportunity
- Solicitation number
- 47HAA023C0010
- Issued by
- GSA Office of Administrative Services
About this file
This justification and approval document outlines a sole source award for a bug bounty software-as-a-service platform. The General Services Administration Office of Administrative Services seeks to purchase access to a commercially available bug bounty platform from HackerOne Inc. on a firm fixed-price basis for a one year base period and four one year option periods. The platform will allow GSA to launch and manage a bug bounty program to incentivize security researchers to report vulnerabilities in GSA web applications and implement a vulnerability disclosure policy. HackerOne will provide its bug bounty platform software, a network of security researchers, and services to triage and track reported issues. The contracting officer determined prices to be fair and reasonable. This sole source award is justified as HackerOne is the only platform federally approved under the FedRAMP authorization process, which is required for government use of software-as-a-service.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. General Services Administration Office of Administrative Services
JUSTIFICATION FOR OTHER THAN FULL AND OPEN COMPETITION
IAW FAR 6.302-1
Pursuant to the requirements of the Competition in Contracting Act (CICA) as implemented by the Federal Acquisition Regulation (FAR, the following justification for the use of the statutory authority under FAR Subpart
6.3 is based on the following facts and rationale as required under FAR 6.303-1.
1. Agency and Contracting Activity.
This requirement is in support of GSA Office of the Chief Information Officer (OCIO), located at 1800 F Street, NW Washington, D.C. 20405. The contracting activity is GSA Office of Administrative Services (OAS) Office of Internal Acquisition (OIA), 1800 F Street NW, Washington, DC 20405.
2. Nature and/or description of the action being approved.
a. Brief Description:
With bug bounties becoming an established industry-wide best practice, GSA Security Operations Division (SecOps) desires to establish one of its own. As part of its programmatic focus on security, SecOps needs to purchase access to a pre-existing, commercially available Bug Bounty SaaS Platform that will allow it to launch and manage the Bug Bounty program. In addition, the platform will allow GSA to implement a Vulnerability Disclosure policy to handle and triage reports from researchers for GSA. This acquisition will provide access to a large network of security researchers, people who have an interest - both personally and financially - in helping to find and address bugs and other technical issues within GSAs web applications. Bug bounties serve as a legal and social arrangement with the security community: bounty operators, define what researchers are permitted to do in regards to discovering and reporting security issues of a production system, and in turn, researchers are assured they will not be punished for anything they do within that scope and are awarded for their findings.
A sole source contract will be issued to HackerOne Inc. for Bug Bounty SaaS. The action will be a firm fixed-fixed price contract to HackerOne Inc. for a base period of one (1) year and four (4) one (1) year options.
Estimated Period of Performance is as follows:
12-Month Base Period: September 25, 2023 to September 24, 2024 12-Month Option 1 Period: September 25, 2024 to September 24, 2025 12-Month Option 2 Period: September 25, 2025 to September 24, 2026 12-Month Option 3 Period: September 25, 2026 to September 24, 2027 12-Month Option 4 Period: September 25, 2027 to September 24, 2028
Total Estimated Value for the Base and 4 Option Periods is $ consisting of:
Base Period Value:- Option 1 Period Value: $ Option 2 Period Value: $ Option 3 Period Value: $ Option 4 Period Value: $
b. Place of Publication:
Only one vendor is an authorized reseller with a FEDRAMP Authorization for Bug Bounty SaaS, therefore a sole source stand-alone contract will be issued to HackerOne Inc. A notice of intent to award sole source was posted to SAM.gov Contract Opportunities on August 30, 2023 for the sole source requirement. https://sam.gov/opp/fc5970c23924455e90479118377a97b1/view
3. Description of Supplies/Services required to meet the agency’s needs (including the estimated value).
This is a Sole Source Award to HackerOne to deliver a Bug Bounty program which SecOPs will utilize for SecOps-owned web applications. HackerOne will provide access to their Bug Bounty SaaS Platform for researchers to report vulnerabilities (“Platform/Network Access”) and allow SecOps to manage and track issues across multiple public web applications, triage services for those reported vulnerabilities, disburse rewards for effective vulnerabilities, and explain the reasons behind rejections (“Vulnerability Report Triage Services”). The Vulnerability Report Triage Services, must be provided on a “per web application” basis, allowing SecOps to operate a Bug Bounty for a web application independently of the other web applications that are utilizing the Platform/Network Access for their own tests. As part of these services, HackerOne must provide staff who are specialists in reviewing vulnerability reports and communicating with researchers. HackerOne will provide the following:
A Software-as-a-Service platform, with a publicly available website, for researchers to report security vulnerabilities on publicly available government websites in a manner consistent with the SecOps Vulnerability Security Policy. The platform will:
Communicate the procedures of how to discover and report the security vulnerabilities on publicly available government websites in manner consistent with the SecOps Vulnerability Security Policy.
Provide a secure means for researchers to submit the site vulnerabilities they discover.
Ensure that researchers are aware of SecOps Vulnerability Security Policy and any other relevant discovery or reporting procedures.
Permit SecOps to post up to five concurrent (5) applications on the platform during the initial period of performance.
Permit SecOps to add or remove any of the posted applications at any time during the period of performance.
Provide access to a network of security researchers and bounty hunters.
Provide a platform for SecOps staff to view reported vulnerabilities and update their status as the issues are managed and resolved.
Support both public bounties (open to any researcher on the platform) and private, invite-only bounties (open to only researchers SecOps and HackerOne select).
Triage of severity of reported vulnerabilities. HackerOne will provide services to:
Screen reported vulnerabilities and filter out invalid and duplicate reports.
Classify vulnerabilities according to SecOps guidelines developed for HackerOne and assign them to the proper SecOps staff, while SecOps maintains the rights to update these guidelines at any time.
Communicate with researchers about their reports, escalating to SecOps staff if needed.
Bug bounties serve as a legal and social contract with the security community: bounty operators, like GSA IT, define what researchers are permitted to do with regard to discovery and reporting security issues of a production system, and in turn, researchers are assured they will not be punished for anything they do within that scope and are awarded for their findings.
With bug bounties becoming an established industry-wide best practice, GSA IT desires to continue use of its well established vulnerability disclosure program. The vulnerability disclosure policy released in November 2016 outlines how researchers can report system vulnerabilities, while keeping personal and financial information safe.
GSA IT wishes to continue to incentivize security researchers and other interested users to report security issues directly to the system owner through the use of financial rewards - or, a bug bounty.
While many in the research community are simply seeking to disclose vulnerabilities for recognition and out of goodwill alone, it is understood that there is a financial marketplace for unreported security issues in important systems. Where there are no legitimate means by which disclosure can occur and/or be acknowledged, there is a risk of a black marketplace taking the place of an open one. Bug bounties are a proven method of mitigating security risk in production systems: they incentivise researchers to report issues to the system owner who can fix them before they’re discovered by malicious actors.
By the very nature of a bug bounty program, a contractor that provides a Bug Bounty SaaS Platform that can achieve the goals of GSA IT while providing the best value to the government must be one that is well-established. The more well-known the provider of a Bug Bounty SaaS Platform, the larger and more talented the pool of security researchers they have in their community. The larger the community of security researchers in the Bug Bounty SaaS Platform provider’s network, the better the chance GSA IT has of finding bugs and technical issues within their web applications.
Private companies have operated bug bounties for many years. The first program was created at Netscape in late 1995, and offered cash rewards to anyone who found bugs in Netscape Navigator (the precursor to Mozilla’s Firefox web browser). The basic concept is simple: reward independent researchers for software bugs they discover and report responsibly. Over the fifteen years a few companies offered similar programs, but it remained a niche concept. The idea really took off in 2010 when Google launched their Vulnerability Reward Program (VRP) for the company's web applications. Since its launch, Google has paid researchers over in bounty rewards. That success -- and the similar successes of other early bounties at Barracuda, Microsoft, and Facebook -- led to an explosion of similar programs. Today, hundreds of companies run bounty programs, which tens of thousands of researchers participate in.
Security bug bounties provide many benefits to organizations that offer them: they provide an officially-sanctioned channel for users to report security issues; they incentivise independent researchers to use their expertise to improve the organization's’ security posture; they bring a broader base of expertise into play by opening up research to experts outside the organization; and they complement traditional security reviews and penetration tests by making security review an ongoing, iterative process. Thus, bug bounties have become an important component of a mature cybersecurity practice.
However, operating a bug bounty is difficult. The vast majority of reported issues turn out to be invalid and even valid reports can require significant back-and-forth with researchers to fully understand the issue. Properly tracking and managing reports can be difficult: most off-the-shelf bug-tracking software is ill-suited to bug bounties.
Additionally, managing the multiple small payouts to researchers can be very time-consuming.
Bug bounty platforms such as HackerOne exist to solve these issues: they provide specialized software to receive, track, and manage bug reports. They offer staff who are specialists in reviewing vulnerability reports and communicating with researchers. They automate and manage payouts to researchers. On top of that, they build communities of experienced security researchers and help organizations put their bug bounties in front of that community.
To determine these types of services are not supported by a mandatory source or an existing GSA contract vehicle, the Market Research team interviewed two well known companies within the commercial industry that provide access to their Bug Bounty SaaS Platform and their community of security researchers: HackerOne and BugCrowd.
HackerOne is the only platform on the market that has been authorized for usage from a security perspective under the FedRAMP program, which is required for using SaaS products in the government.
The authority at FAR subpart 6.302-1, “Only One Responsible Source”. HackerOne Inc. owns proprietary rights to the Bug Bounty SaaS. They do have eight (8) vendors that are authorized resellers. Review of the FEDRAMP website was conducted to verify FEDRAMP certification status of all eight (8) resellers and HackerOne. None of the identified resellers are FEDRAMP certified and therefore do not meet GSA IT requirements. Only HackerOne Inc.
is FEDRAMP certified and meets all GSA IT requirements.
Impact on the Mission that if the J&A Is Not Approved
If the J&A is not approved and this SaaS is not provided, GSA IT would no longer be in compliance with BOD 20-01 which requires that federal agencies to:
Implement a Vulnerability Disclosure Policy that requires GSA internet accessible systems to be enrolled
Adhere to a timeline that eventually leads to all GSA internet accessible systems being enrolled.
Since Vulnerability Disclosure Policies invite ethical hackers, researchers, finders (General Public) to hack systems defined in the scope of this policy. GSA IT is going beyond the outlined requirements of BOD 20-01 by using the existing Bug Bounty Program to work in conjunction with the vulnerability disclosure policy and program.
6. Description of efforts made to ensure that offers are solicited from as many potential sources as is practicable.
X GSA has publicized this requirement, prior to award, as required by subpart 5.2 by posting a notice of intent to award sole source to HackerOne on GSA.gov Contract Opportunities on 30 August 2023.
7. Determination by the contracting officer that the anticipated cost to the Government will be fair and reasonable.
The contracting officer has determined that the anticipated price(s) will be fair and reasonable using the techniques as identified in FAR Subpart 15.404-1(b)(2). One or both of the following technique shall be used:
Comparison of the proposed prices to historical prices paid;
Comparison with competitive published price lists, published market prices of commodities, similar indexes, and discount or rebate arrangements;
Combined with the vendor’s technical capabilities as cited in Section 5 of this document and the proposed price, the Government will determine proposed prices offer the best value to the Government prior to award.
File details come from the government source that posted it. Updated .