MAS - United One Communications, LLC - 47QTCA18D00DC

DOCX document 284 KB

Attached to
Federal Supply Schedule 47QTCA18D00DC Federal contract IDV
Contract number
47QTCA18D00DC
Issued by
GSA Federal Acquisition Service

About this file

This federal supply schedule outlines information technology products and services available from a contractor. The schedule was awarded on June 15, 2018 with an expiration date of June 14, 2028. It includes labor categories such as Information Assurance Engineer I-III and Cybersecurity Specialist I-II. Pricing is provided for professional services under SINs 54151S and 54151HACS, with hourly rates ranging from $60.18 to $143.35. The contractor is authorized to provide items under SINs 54151S, 54151HACS, 811212, and OLM.

United One Communications LLC Pricelist and/or Vendor Terms and Conditions for 47QTCA18D00DC, a Federal Supply Schedule awarded to United One Communications LLC, under Information Technology Schedule 70 (IT-70)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

GENERAL SERVICES ADMINISTRATION

FEDERAL ACQUISITION SERVICE

AUTHORIZED FEDERAL SUPPLY SCHEDULE FSS PRICE LIST

Online access to contract ordering information, terms and conditions, pricing, and the option to create an electronic delivery order are available through GSA Advantage!®. The website for GSA Advantage!® is: https://www.GSAAdvantage.gov.

Schedule Title: Multiple Award Schedule (MAS)

FSC Group: D310, D399, J070

Contract Number: 47QTCA18D00DC

Contract Period: June 15, 2018 – June 14, 2028

For more information on ordering go to the following website: https://www.gsa.gov/schedules.

Contractor:

United One Communications LLC

808 N Franklin St Unit 3204 Tampa, FL 33602

Phone number: (813) 278-3020 www.getuoc.com

Contractor’s Administration Source:

Carl C. Chaisson GSAPMO@getuoc.com

Business Size:

Small Business

SBA Certified Small Disadvantaged business SBA Certified 8(a) Firm

Current as of Modification PO-0022, effective June 15, 2023

Prices Shown Herein are Net (discount deducted)

CUSTOMER INFORMATION:

1a. TABLE OF AWARDED SPECIAL ITEM NUMBERS (SINs)

SIN DESCRIPTION

54151S Information Technology Professional Services 54151HACS Highly Adaptive Cybersecurity Services 811212 Maintenance of Equipment, Repair Services, and/or Repair/Spare Parts OLM Order Level Materials

1b. LOWEST PRICED MODEL NUMBER AND PRICE FOR EACH SIN: See pricelist below

1c. HOURLY RATES: See Page 11. Job Descriptions begin on page 7.

2. MAXIMUM ORDER*: $500,000

*Ordering activities may request a price reduction at any time before placing an order, establishing a BPA, or in conjunction with the annual BPA review. However, the ordering activity shall seek a price reduction when the order or BPA exceeds the simplified acquisition threshold. Schedule contractors are not required to pass on to all schedule users a price reduction extended only to an individual ordering activity for a specific order or BPA.

3. MINIMUM ORDER: $100

4. GEOGRAPHIC COVERAGE: 50 States and Washington D.C.

5. POINT(S) OF PRODUCTION: Not Applicable

6. DISCOUNT FROM LIST PRICES: GSA Net Prices are shown on the attached GSA Pricelist.

7. QUANTITY DISCOUNT(S): Not Applicable

8. PROMPT PAYMENT TERMS: Net 30 Days.

Information for Ordering Offices: Prompt Payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions.

9. FOREIGN ITEMS: Not Applicable

10a. TIME OF DELIVERY: Determined on task order level

10b. EXPEDITED DELIVERY: Contact contractor

10c. OVERNIGHT AND 2-DAY DELIVERY: Contact contractor

10d. URGENT REQUIREMENTS: Agencies can contact the Contractor’s representative to affect a faster delivery.

Customers are encouraged to contact the contractor for the purpose of requesting accelerated delivery.

11. FOB POINT: Destination

12a. ORDERING ADDRESS: 808 N Franklin St Ste 3204 Tampa, FL 33602

12b. ORDERING PROCEDURES: See Federal Acquisition Regulation (FAR) 8.405-3

13. PAYMENT ADDRESS: 808 N Franklin St Ste 3204 Tampa, FL 33602

14. WARRANTY PROVISION: Not Applicable

15. EXPORT PACKING CHARGES: N/A

16. TERMS AND CONDITIONS OF RENTAL, MAINTENANCE, AND REPAIR (IF APPLICABLE): N/A

17. TERMS AND CONDITIONS OF INSTALLATION (IF APPLICABLE): N/A

18a. TERMS AND CONDITIONS OF REPAIR PARTS INDICATING DATE OF PARTS PRICE LISTS AND ANY

DISCOUNTS FROM LIST PRICES (IF AVAILABLE): N/A

18b. TERMS AND CONDITIONS FOR ANY OTHER SERVICES (IF APPLICABLE): N/A

19. LIST OF SERVICE AND DISTRIBUTION POINTS (IF APPLICABLE): N/A

20. LIST OF PARTICIPATING DEALERS (IF APPLICABLE): N/A

21. PREVENTIVE MAINTENANCE (IF APPLICABLE): N/A

22a. SPECIAL ATTRIBUTES SUCH AS ENVIRONMENTAL ATTRIBUTES (e.g. recycled content, energy efficiency, and/or reduced pollutants): N/A

22b. Section 508 Compliance

Section 508 compliance information on the supplies and services in this contract are available at the following website address (URL): www.unitedonecommunications.com

The EIT standard can be found at: www.Section508.gov/

23. Unique Entity Identifier (UEI) number: MZ3PA733M1A9

24. Contractor has an active registration in the SAM database.

Information Technology Category Instructions and Regulations

Section III Terms and Conditions for all IT Contractors

NOTE: All non-professional labor categories must be incidental to, and used solely to support professional services, and cannot be purchased separately.

1) Organizational Conflicts Of Interest

a) Definitions.

i) Contractor" means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.

ii) "Contractor and its affiliates" and "Contractor or its affiliates" refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.

iii) An "Organizational conflict of interest" exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor's or its affiliates' objectivity in performing contract work.

b) To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract.

Examples of situations, which may require restrictions, are provided at FAR 9.508

2) Services Performed

a) All services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.

b) The Contractor shall commence performance of services on the date agreed to by the Contractor and the ordering activity.

c) The Contractor agrees to render services only during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.

3) Travel.

a) Any contractor travel required in the performance of services must comply with the Pub. L.99-234 and FAR Part

31.205-46, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel.

4) Warranty

a) Unless otherwise specified in this contract, the Contractor's standard commercial warranty as stated in the contract's commercial pricelist will apply to this contract.

b) The Contractor's commercial guarantee/warranty shall be included in the Commercial Supplier Agreement to include Enterprise User License Agreements or Terms of Service (TOS) agreements, if applicable.

c) Except as otherwise provided by an express or implied warranty, the Contractor will not be liable to the ordering activity for consequential damages resulting from any defect or deficiencies in accepted items.

Terms and Conditions for SIN 54151HACS Highly Adaptive Cybersecurity Services (HACS)

5. Only IT Professional Highly Adaptive Cybersecurity Services (HACS) shall be offered under this special item number. The following are the approved subcategories:

High Value Asset (HVA) Assessments;

Risk and Vulnerability Assessments (RVA), Cyber Hunt, Incident Response, and Penetration Testing

6. Resumes shall be provided to the GSA Contracting Officer or the ordering activity upon request.

7. Services offered SIN 54151HACS shall be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:

o Federal Acquisition Regulation (FAR) Part 52.204-21 o OMB Memorandum M-17-12 - Preparing for and Responding to a Breach of Personally Identifiable

Information (PII) o OMB Memorandum M- 19-03 - Strengthening the Cybersecurity of Federal Agencies by enhancing the High

Value Asset Program o 2017 Report to the President on Federal IT Modernization o The Cybersecurity National Action Plan (CNAP) o NIST SP 800-14 - Generally Accepted Principles and Practices for Securing Information Technology Systems o NIST SP 800-27A - Engineering Principles for Information Technology Security (A Baseline for Achieving

Security) o NIST SP 800-30 - Guide for Conducting Risk Assessments o NIST SP 800-35 - Guide to Information Technology Security Services o NIST SP 800-37 - Risk Management Framework for Information Systems and Organizations: A Systems Life

Cycle Approach for Security and Privacy o NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View o NIST SP 800-44 - Guidelines on Securing Public Web Servers o NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks o NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations o NIST SP 800-61 - Computer Security Incident Handling Guide o NIST SP 800-64 - Security Considerations in the System Development Life Cycle o NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security o NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident Response o NIST SP 800-115 - Technical Guide to Information Security Testing and Assessment o NIST SP 800-128 - Guide for Security-Focused Configuration Management of Information Systems o NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and

Organizations o NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks (WLANs) o NIST SP 800-160 - Systems Security Engineering: Considerations for a Multidisciplinary Approach in the

Engineering of Trustworthy Secure Systems o NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal Information Systems and

Organizations.

UNITED ONE COMMUNICATIONS LLC

LABOR CATEGORY DESCRIPTIONS

Job Title Information Assurance Engineer I

Minimum Years of Experience

2 years

Minimum Education Level

Bachelor’s Degree

Detailed Position Description and Functional Responsibilities

The Information Assurance Engineer I ensures availability, integrity, authentication, confidentiality, and non-repudiation. They incorporate protection, detection, and reaction capabilities to ensure the preservation and restoration of systems; develop and manage IA risk management plans; and certify and accredit systems. They may also provide network intrusion detection and monitoring, HBSS-related monitoring, correlation analysis using security event and incident management (SEIM) analysis tools, and support as required for the fielded CND analysis suite for network subscribers and other supported components. Typical duties include:

• Work with client to identify overall security requirements for the proper handling of data

• Assist architects and system developers in the identification and implementation of appropriate information security

• Enforce the design and implementation of trusted relationships among external systems and architectures

• Provides interface to certification and accreditation organization

• Provide guidance to development and operational efforts on IA functions, particularly those focused on strategic planning, infrastructure protection, and defensive strategy

• Executing, drafting, editing, and maintaining standard operating procedures

• Provide coordination of significant incidents with clients and supported entities to ensure proper analysis is performed and timely and accurate reporting of the incident is affected

• Provide, develop, and maintain a network forensic analysis capability to enhance response to, support of, and investigation into significant incidents to provide a clearer view of the exploits, vulnerabilities, and tactics, techniques, and procedures used

• Provide support for CND analysis, fusion, and monitoring 24x7

• Coordinate with client incident response, cyber threat analyst, IAVM, HBSS support, and CND infrastructure support staff as necessary

• Expected to interact with all areas affected by the project including end users, computer services, and client services

• Develops detailed work plans, schedules, estimates, resource plans, and status reports

• Conducts project meetings and is responsible for tracking and analysis of progress

Qualifications • Industry standard certification such as Security+ CE, CASP, CISSP, CISA, GSEC, MCSA, MCSE, etc.

• Public Key Infrastructure

• Cyber security best practices

• INFOSEC and IA industry policies/standards

• Risk Management Framework

• Certification and Accreditation

• Vulnerability Analyses

• Knowledge of DoD 8570 IAT standards

• Experience conducting analysis at the packet level

• Experience reading and analyzing firewall logs

• Experience administering UNIX-based systems

• Experience with Snort, McAfee, eTrust, and Cisco intrusion detection sensors

• Experience with vulnerability assessment tools (e.g. Retina, Nessus, FoundScan, ArcSight, etc.)

Job Title Information Assurance Engineer II

Experience

5 years

Minimum Education Level

Bachelor’s Degree

Detailed Position Description and Functional Responsibilities

The Information Assurance Engineer II ensures availability, integrity, authentication, confidentiality, and non-repudiation. They incorporate protection, detection, and reaction capabilities to ensure the preservation and restoration of systems; develop and manage IA risk management plans; and certify and accredit systems. They may also provide network intrusion detection and monitoring, HBSS-related monitoring, correlation analysis using security event and incident management (SEIM) analysis tools, and support as

• Assist architects and system developers in the identification and implementation of appropriate information security

• Enforce the design and implementation of trusted relationships among external systems and architectures

• Provides interface to certification and accreditation organization

• Provide guidance to development and operational efforts on IA functions, particularly those focused on strategic planning, infrastructure protection, and defensive strategy

• Executing, drafting, editing, and maintaining standard operating procedures

• Provide coordination of significant incidents with clients and supported entities to ensure proper analysis is performed and timely and accurate reporting of the incident is affected

• Provide, develop, and maintain a network forensic analysis capability to enhance response to, support of, and investigation into significant incidents to provide a clearer view of the exploits, vulnerabilities, and tactics, techniques, and procedures used

• Provide support for CND analysis, fusion, and monitoring 24x7

• Coordinate with client incident response, cyber threat analyst, IAVM, HBSS support, and CND infrastructure support staff as necessary reports

• Conducts project meetings and is responsible for tracking and analysis of progress

Qualifications • Industry standard certification such as Security+ CE, CASP, CISSP, CISA, GSEC, MCSA, MCSE, etc.

• Public Key Infrastructure

• Cyber security best practices

• INFOSEC and IA industry policies/standards

• Risk Management Framework

• Certification and Accreditation

• Vulnerability Analyses

• Knowledge of DoD 8570 IAT standards

• Experience conducting analysis at the packet level

• Experience reading and analyzing firewall logs

• Experience administering UNIX-based systems

• Experience with Snort, McAfee, eTrust, and Cisco intrusion detection sensors

Job Title Information Assurance Engineer III

Experience

7 years

Minimum Education Level

Master’s Degree

Detailed Position Description and Functional Responsibilities

The Information Assurance Engineer III ensures availability, integrity, authentication, confidentiality, and non-repudiation. They incorporate protection, detection, and reaction capabilities to ensure the preservation and restoration of systems; develop and manage IA risk management plans; and certify and accredit systems. They may also provide network intrusion detection and monitoring, HBSS-related monitoring, correlation analysis using security event and incident management (SEIM) analysis tools, and support as

• Assist architects and system developers in the identification and implementation of appropriate information security

• Enforce the design and implementation of trusted relationships among external systems and architectures

• Provides interface to certification and accreditation organization

• Provide guidance to development and operational efforts on IA functions, particularly those focused on strategic planning, infrastructure protection, and defensive strategy

• Executing, drafting, editing, and maintaining standard operating procedures

• Provide coordination of significant incidents with clients and supported entities to ensure proper analysis is performed and timely and accurate reporting of the incident is affected

• Provide, develop, and maintain a network forensic analysis capability to enhance response to, support of, and investigation into significant incidents to provide a clearer view of the exploits, vulnerabilities, and tactics, techniques, and procedures used

• Provide support for CND analysis, fusion, and monitoring 24x7

• Coordinate with client incident response, cyber threat analyst, IAVM, HBSS support, and CND infrastructure support staff as necessary reports

• Conducts project meetings and is responsible for tracking and analysis of progress

Qualifications • Industry standard certification such as Security+ CE, CASP, CISSP, CISA, GSEC, MCSA, MCSE, etc.

• Public Key Infrastructure

• Cyber security best practices

• INFOSEC and IA industry policies/standards

• Risk Management Framework

• Certification and Accreditation

• Vulnerability Analyses

• Knowledge of DoD 8570 IAT standards

• Experience conducting analysis at the packet level

• Experience reading and analyzing firewall logs

• Experience administering UNIX-based systems

• Experience with Snort, McAfee, eTrust, and Cisco intrusion detection sensors

Job Title Cybersecurity Specialist I

Experience

2 years

Minimum Education Level

Bachelor’s Degree

Detailed Position Description and Functional Responsibilities

Specialized in providing the full range of security/cybersecurity incident data collection and correlation, engineering, analysis, testing, and/or support. The scope of responsibility relates to one or more of the following IT areas: information/data, computer hardware or software, networks, mobile computing, cloud, and/or applications. Specialized tasks may include but are not limited to ethical hacking, penetration testing or risk and vulnerability assessment (RVA), whether related to potential or actual threats, attacks, incidents, forensics, intrusions, and/or responses/remediation

Qualifications • Industry standard certification such as Security+ CE, CASP, CISSP, CISA, GSEC, MCSA, MCSE, etc.

• Public Key Infrastructure

• Cyber security best practices

• INFOSEC and IA industry policies/standards

• Risk Management Framework

• Certification and Accreditation

• Vulnerability Analyses

• Knowledge of DoD 8570 IAT standards

• Experience conducting analysis at the packet level

• Experience reading and analyzing firewall logs

• Experience administering UNIX-based systems

• Experience with Snort, McAfee, eTrust, and Cisco intrusion detection sensors

Job Title Cybersecurity Specialist I

Minimum Years of Experience

5 years

Minimum Education Level

Bachelor’s Degree

Detailed Position Description and Functional Responsibilities

Specialized in providing the full range of security/cybersecurity incident data collection and correlation, engineering, analysis, testing, and/or support. The scope of responsibility relates to one or more of the following IT areas: information/data, computer hardware or software, networks, mobile computing, cloud, and/or applications. Specialized tasks may include but are not limited to ethical hacking, penetration testing or risk and vulnerability assessment (RVA), whether related to potential or actual threats, attacks, incidents, forensics, intrusions, and/or responses/remediation.

Qualifications • Industry standard certification such as Security+ CE, CASP, CISSP, CISA, GSEC, MCSA, MCSE, etc.

• Public Key Infrastructure

• Cyber security best practices

• INFOSEC and IA industry policies/standards

• Risk Management Framework

• Certification and Accreditation

• Vulnerability Analyses

• Knowledge of DoD 8570 IAT standards

• Experience conducting analysis at the packet level

• Experience reading and analyzing firewall logs

• Experience administering UNIX-based systems

• Experience with Snort, McAfee, eTrust, and Cisco intrusion detection sensors

SIN(s) Labor Categories Unit of Issue GSA Price

54151S Information Assurance Engineer I Hour $111.10

54151S Information Assurance Engineer II Hour $123.67

54151S Information Assurance Engineer III Hour $143.35

54151HACS Cybersecurity Specialist I Hour $60.18

54151HACS Cybersecurity Specialist II Hour $69.67

File details come from the government source that posted it. Updated .