MAS - Gray Tier Technologies LLC - 47QTCA19D00JS
PDF 665 KB
- Attached to
- Federal Supply Schedule 47QTCA19D00JS Federal contract IDV
- Contract number
- 47QTCA19D00JS
- Issued by
- GSA Federal Acquisition Service
About this file
This is a federal supply schedule for information technology professional services and highly adaptive cybersecurity services. The contractor provides services including risk management, information assurance, security operations center functions, penetration testing, incident response, and cybersecurity consulting. Labor categories cover specialists in penetration testing, cyber forensics, Splunk engineering, and information security at various levels of experience. The schedule was awarded on August 26, 2019 through GSA with a period of performance through August 25, 2024. Pricing is provided for each labor category along with minimum education and experience requirements. The contractor offers services under SINs 54151S, 54151HACS, and related subcategories.
Gray Tier Technologies, LLC Pricelist and/or Vendor Terms and Conditions for 47QTCA19D00JS, a Federal Supply Schedule awarded to Gray Tier Technologies, LLC, under Information Technology Schedule 70 (IT-70)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Page | 1
Gray Tier Technologies GSA Schedule 47QTCA19D00JS
AUTHORIZED
INFORMATION TECHNOLOGY SCHEDULE PRICELIST
GENERAL PURPOSE COMMERCIAL INFORMATION TECHNOLOGY
EQUIPMENT, SOFTWARE AND SERVICES
THREAT SIMULATION
Our operators can conduct a full range of InfoSec operations from network infiltration and intelligence gathering to implementing tailored effects
CONSULTING
Our consulting services are tailored to help our clients solve their toughest security challenges
SOFTWARE R&D
We specialize in developing bespoke offensive and defensive tools to support our client’s training and operations
RED TEAMING
Our most comprehensive security assessment, combining penetration testing, application security testing, and social engineering
PENETRATION TESTING
Comprehensive risk, vulnerability, and penetration testing intelligence with prioritized risk-rated recommendations
APPLICATION TESTING
Our security engineers will test vulnerabilities in your custom or off the shelf applications
WEB APPLICATION TESTING
Our security engineers will test vulnerabilities in your web, mobile, & cloud applications
OPEN SOURCE INTELLIGENCE
OSINT is intelligence collected from publicly available sources
SOCIAL ENGINEERING
Phishing and phone campaigns to pinpoint your vulnerabilities and promote awareness and education
Page | 2
AUTHORIZED INFORMATION TECHNOLOGY SCHEDULE PRICELIST
GENERAL PURPOSE COMMERCIAL INFORMATION TECHNOLOGY
EQUIPMENT, SOFTWARE AND SERVICES
Special Item Nos.:
54151S Information Technology (IT) Professional Services
54151HACS Highly Adaptive Cybersecurity Services (HACS) Subcategories: Penetration Testing;
Incident Response;
Cyber Hunt;
Risk and Vulnerability Assessments;
High Value Asset Assessments
SPECIAL ITEM NUMBER 54151S - Information Technology (IT) Professional Services
FPDS Code D301 IT Facility Operation and Maintenance FPDS Code D302 IT Systems Development Services FPDS Code D306 IT Systems Analysis Services FPDS Code D307 Automated Information Systems Design and Integration Services FPDS Code D308 Programming Services FPDS Code D310 IT Backup and Security Services FPDS Code D311 IT Data Conversion Services FPDS Code D316 IT Network Management Services
FPDS Code D317 Creation/Retrieval of IT Related Automated News Services, Data Services, or Other
Information Services (All other information services belong under Schedule 76) FPDS Code D399 Other Information Technology Services, Not Elsewhere Classified
Note 1: All non-professional labor categories must be incidental to and used solely to support hardware, software and/or professional services, and cannot be purchased separately.
Note 2: Offerors and Agencies are advised that the Group 70 – Information Technology Schedule is not to be used as a means to procure services which properly fall under the Brooks Act. These services include, but are not limited to, architectural, engineering, mapping, cartographic production, remote sensing, geographic information systems, and related services. FAR 36.6 distinguishes between mapping services of an A/E nature and mapping services which are not connected nor incidental to the traditionally accepted A/E Services.
Note 3: This solicitation is not intended to solicit for the reselling of IT Professional Services, except for the provision of implementation, maintenance, integration, or training services in direct support of a product. Under such circumstances the services must be performance by the publisher or manufacturer or one of their authorized agents.
Page | 3
Gray Tier Technologies LLC 2331 Mill Road Ste 100, Alexandria, VA 22314
Phone: 703.224.8952 / Fax: 703.224.8801 www.graytier.com
Contract Number: 47QTCA19D00JS Period Covered by Contract: Aug 26, 2019 through Aug 25, 2024
General Services Administration
Federal Acquisition Service
Pricelist current through Modification # 0002, dated August 16, 2023.
Products and ordering information in this Authorized Information Technology Schedule Pricelist are also available on the GSA Advantage! System (http://www.gsaadvantage.gov).
http://www.graytier.com/
Page | 4
Table of Contents
INFORMATION FOR ORDERING ACTIVITIES APPLICABLE TO ALL SPECIAL ITEM NUMBERS
1. GEOGRAPHIC SCOPE OF CONTRACT:
2. CONTRACTOR’S ORDERING ADDRESS AND PAYMENT INFORMATION:
3. LIABILITY FOR INJURY OR DAMAGE
4. STATISTICAL DATA FOR GOVERNMENT ORDERING OFFICE COMPLETION OF STANDARD
FORM 279:
5. FOB DESTINATION
6. DELIVERY SCHEDULE
7. DISCOUNTS: Prices shown are NET Prices; Basic Discounts have been deducted
8. TRADE AGREEMENTS ACT OF 1979, as amended:
9. STATEMENT CONCERNING AVAILABILITY OF EXPORT PACKING:
10. SMALL REQUIREMENTS
11. MAXIMUM ORDER
12. ORDERING PROCEDURES FOR FEDERAL SUPPLY SCHEDULE CONTRACTS
13. FEDERAL INFORMATION TECHNOLOGY/TELECOMMUNICATION STANDARDS
REQUIREMENTS:
14. CONTRACTOR TASKS / SPECIAL REQUIREMENTS (C-FSS-370) (NOV 2003)
15. CONTRACT ADMINISTRATION FOR ORDERING ACTIVITIES:
16. GSA ADVANTAGE!
17. PURCHASE OF OPEN MARKET ITEMS
18. CONTRACTOR COMMITMENTS, WARRANTIES AND REPRESENTATIONS
19. OVERSEAS ACTIVITIES
20. BLANKET PURCHASE AGREEMENTS (BPAs)
21. CONTRACTOR TEAM ARRANGEMENTS
22. INSTALLATION, DEINSTALLATION, REINSTALLATION
23. SECTION 508 COMPLIANCE
24. PRIME CONTRACTOR ORDERING FROM FEDERAL SUPPLY SCHEDULES
25. INSURANCE—WORK ON A GOVERNMENT INSTALLATION (JAN 1997) (FAR 52.228-5)
26. SOFTWARE INTEROPERABILITY
27. ADVANCE PAYMENTS
1. SCOPE
2. PERFORMANCE INCENTIVES I-FSS-60 Performance Incentives (April 2000)
3. ORDER
4. PERFORMANCE OF SERVICES
5. STOP-WORK ORDER (FAR 52.242-15) (AUG 1989)
6. INSPECTION OF SERVICES
7. RESPONSIBILITIES OF THE CONTRACTOR
8. RESPONSIBILITIES OF THE ORDERING ACTIVITY
9. INDEPENDENT CONTRACTOR
10. ORGANIZATIONAL CONFLICTS OF INTEREST
11. INVOICES
12. PAYMENTS
13. RESUMES
14. INCIDENTAL SUPPORT COSTS
15. APPROVAL OF SUBCONTRACTS
16. DESCRIPTION OF IT/IAM PROFESSIONAL SERVICES AND PRICING
GSA PRICE LIST & LABOR CATEGORIES
Page | 5
INFORMATION FOR ORDERING
ACTIVITIES APPLICABLE TO ALL
SPECIAL ITEM NUMBERS
SPECIAL NOTICE TO AGENCIES: Small Business Participation SBA strongly supports the participation of small business concerns in the Federal Acquisition Service. To enhance Small Business Participation SBA policy allows agencies to include in their procurement base and goals, the dollar value of orders expected to be placed against the Federal Supply Schedules, and to report accomplishments against these goals.
For orders exceeding the micro-purchase threshold, FAR 8.404 requires agencies to consider the catalogs/pricelists of at least three schedule contractors or consider reasonably available information by using the GSA Advantage! on-line shopping service (www.gsaadvantage.gov). The catalogs/pricelists, GSA Advantage! and the Federal Acquisition Service Home Page (www.gsa.gov/fas) contain information on a broad array of products and services offered by small business concerns.
This information should be used as a tool to assist ordering activities in meeting or exceeding established small business goals. It should also be used as a tool to assist in including small, small disadvantaged, and women-owned small businesses among those considered when selecting pricelists for a best value determination.
For orders exceeding the micro-purchase threshold, customers are to give preference to small business concerns when two or more items at the same delivered price will satisfy their requirement.
1. GEOGRAPHIC SCOPE OF CONTRACT:
Domestic delivery is delivery within the 48 contiguous states, Alaska, Hawaii, Puerto Rico, Washington, DC, and U.S. Territories. Domestic delivery also includes a port or consolidation point, within the aforementioned areas, for orders received from overseas activities.
Overseas delivery is delivery to points outside of the 48 contiguous states, Washington, DC, Alaska, Hawaii, Puerto Rico, and U.S. Territories.
Offerors are requested to check one of the following boxes:
[ ] The Geographic Scope of Contract will be domestic and overseas delivery.
[ ] The Geographic Scope of Contract will be overseas delivery only.
[X] The Geographic Scope of Contract will be domestic delivery only.
For Special Item Number 132-53 Wireless Services ONLY, if awarded, list the limited geographic coverage area:
2. CONTRACTOR’S ORDERING ADDRESS AND PAYMENT INFORMATION:
Gray Tier Technologies LLC 2800 Eisenhower Ave Ste 220 Alexandria, VA 22314 http://www.gsa.gov/fas)
Page | 6
Contractor must accept the credit card for payments equal to or less than the micro-purchase for oral or written orders under this contract. The Contractor and the ordering agency may agree to use the credit card for dollar amounts over the micro-purchase threshold (See GSAR 552.232- 79 Payment by Credit Card). In addition, bank account information for wire transfer payments will be shown on the invoice.
The following telephone number(s) can be used by ordering activities to obtain technical and/or ordering assistance:
Phone: 703.224.8952 / Fax: 703.224.8801 When Authorized Dealers are allowed by the Contractor to bill ordering activities and accept payment, the order and/or payment must be in the name of the Contractor, in care of the Authorized Dealer.
3. LIABILITY FOR INJURY OR DAMAGE
The Contractor shall not be liable for any injury to ordering activity personnel or damage to ordering activity property arising from the use of equipment maintained by the Contractor, unless such injury or damage is due to the fault or negligence of the Contractor.
4. STATISTICAL DATA FOR GOVERNMENT ORDERING OFFICE COMPLETION
OF STANDARD FORM 279:
Block 9: G. Order/Modification Under Federal Schedule Contract Block 16: Data Universal Numbering System (DUNS) Number: 079331519 Block 30: Type of Contractor: B. Other Small Business Block 31: Woman-Owned Small Business - No Block 37: Contractor's Taxpayer Identification Number (TIN): 47-2520527 Block 40: Veteran Owned Small Business (VOSB): A: Service-Disabled Veteran Owned Small Business
4a. CAGE Code: 73F75 4b. Contractor has registered with the Central Contractor Registration SAM Database.
5. FOB DESTINATION
6. DELIVERY SCHEDULE
a. TIME OF DELIVERY: The Contractor shall deliver to destination within the number of calendar days after receipt of order (ARO), as set forth below:
SPECIAL ITEM NUMBER DELIVERY TIME (Days ARO)
54151s & 54151HACS 30 Days
b. URGENT REQUIREMENTS: When the Federal Supply Schedule contract delivery period does not meet the bona fide urgent delivery requirements of an ordering activity, ordering activities are encouraged, if time permits, to contact the Contractor for the purpose of obtaining accelerated delivery.
The Contractor shall reply to the inquiry within 3 workdays after receipt. (Telephonic replies shall be confirmed by the Contractor in writing.) If the Contractor offers an accelerated delivery time acceptable
Page | 7 to the ordering activity, any order(s) placed pursuant to the agreed upon accelerated delivery time frame shall be delivered within this shorter delivery time and in accordance with all other terms and conditions of the contract.
7. DISCOUNTS: Prices shown are NET Prices; Basic Discounts have been deducted.
a. Prompt Payment: None
b. Quantity: None
c. Dollar Volume: None
d. Government Educational Institutions: None
e. Other: None
8. TRADE AGREEMENTS ACT OF 1979, as amended:
All items are U.S. made end products, designated country end products, Caribbean Basin country end products, Canadian end products, or Mexican end products as defined in the Trade Agreements Act of 1979, as amended.
9. STATEMENT CONCERNING AVAILABILITY OF EXPORT PACKING:
10. SMALL REQUIREMENTS: The minimum dollar value of orders to be issued is $100.
11. MAXIMUM ORDER (All dollar amounts are exclusive of any discount for prompt payment.)
The Maximum Order value for the following Special Item Numbers (SINs) is $500,000:
Special Item Number 54151S (132-51) - Information Technology Professional Services
12. ORDERING PROCEDURES FOR FEDERAL SUPPLY SCHEDULE CONTRACTS
Ordering activities shall use the ordering procedures of Federal Acquisition Regulation (FAR) 8.405 when placing an order or establishing a BPA for supplies or services. These procedures apply to all schedules.
FAR 8.405-1 Ordering procedures for supplies, and services not requiring a statement of work.
FAR 8.405-2 Ordering procedures for services requiring a statement of work.
13. FEDERAL INFORMATION TECHNOLOGY/TELECOMMUNICATION
STANDARDS REQUIREMENTS:
Ordering activities acquiring products from this Schedule must comply with the provisions of the Federal Standards Program, as appropriate (reference: NIST Federal Standards Index). Inquiries to determine whether or not specific products listed herein comply with Federal Information Processing Standards (FIPS) or Federal Telecommunication Standards (FED-STDS), which are cited by ordering activities, shall be responded to promptly by the Contractor.
Page | 8
13.1 FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATIONS
(FIPS PUBS): Information Technology products under this Schedule that do not conform to Federal Information Processing Standards (FIPS) should not be acquired unless a waiver has been granted in accordance with the applicable "FIPS Publication." Federal Information Processing Standards Publications (FIPS PUBS) are issued by the U.S. Department of Commerce, National Institute of Standards and Technology (NIST), pursuant to National Security Act. Information concerning their availability and applicability should be obtained from the National Technical Information Service (NTIS), 5285 Port Royal Road, Springfield, Virginia 22161. FIPS PUBS include voluntary standards when these are adopted for Federal use. Individual orders for FIPS PUBS should be referred to the NTIS Sales Office, and orders for subscription service should be referred to the NTIS Subscription Officer, both at the above address, or telephone number (703) 487- 4650.
13.2 FEDERAL TELECOMMUNICATION STANDARDS (FED-STDS):
Telecommunication products under this Schedule that do not conform to Federal Telecommunication Standards (FED-STDS) should not be acquired unless a waiver has been granted in accordance with the applicable "FED-STD." Federal Telecommunication Standards are issued by the U.S. Department of Commerce, National Institute of Standards and Technology (NIST), pursuant to National Security Act. Ordering information and information concerning the availability of FED-STDS should be obtained from the GSA, Federal Acquisition Service, Specification Section, 470 East L’Enfant Plaza, Suite 8100, SW, Washington, DC 20407, telephone number (202)619-8925. Please include a self-addressed mailing label when requesting information by mail. Information concerning their applicability can be obtained by writing or calling the U.S. Department of Commerce, National Institute of Standards and Technology, Gaithersburg, MD 20899, telephone number (301)975-2833.
14. CONTRACTOR TASKS / SPECIAL REQUIREMENTS (C-FSS-370) (NOV 2003)
(a) Security Clearances: The Contractor may be required to obtain/possess varying levels of security clearances in the performance of orders issued under this contract. All costs associated with obtaining/possessing such security clearances should be factored into the price offered under the Multiple Award Schedule.
(b) Travel: The Contractor may be required to travel in performance of orders issued under this contract. Allowable travel and per diem charges are governed by Pub .L. 99-234 and FAR Part 31, and are reimbursable by the ordering agency or can be priced as a fixed price item on orders placed under the Multiple Award Schedule. Travel in performance of a task order will only be reimbursable to the extent authorized by the ordering agency. The Industrial Funding Fee does NOT apply to travel and per diem charges.
(c) Certifications, Licenses and Accreditations: As a commercial practice, the Contractor may be required to obtain/possess any variety of certifications, licenses and accreditations for specific FSC/service code classifications offered. All costs associated with obtaining/ possessing such certifications, licenses and accreditations should be factored into the price offered under the Multiple Award Schedule program.
(d) Insurance: As a commercial practice, the Contractor may be required to obtain/possess insurance coverage for specific FSC/service code classifications offered. All costs associated with obtaining/possessing such insurance should be factored into the price offered under the Multiple Award Schedule program.
Page | 9
(e) Personnel: The Contractor may be required to provide key personnel, resumes or skill category descriptions in the performance of orders issued under this contract. Ordering activities may require agency approval of additions or replacements to key personnel.
(f) Organizational Conflicts of Interest: Where there may be an organizational conflict of interest as determined by the ordering agency, the Contractor’s participation in such order may be restricted in accordance with FAR Part 9.5.
(g) Documentation/Standards: The Contractor may be requested to provide products or services in accordance with rules, regulations, OMB orders, standards and documentation as specified by the agency’s order.
(h) Data/Deliverable Requirements: Any required data/deliverables at the ordering level will be as specified or negotiated in the agency’s order.
(i) Government-Furnished Property: As specified by the agency’s order, the Government may provide property, equipment, materials or resources as necessary.
(j) Availability of Funds: Many Government agencies’ operating funds are appropriated for a specific fiscal year. Funds may not be presently available for any orders placed under the contract or any option year. The Government’s obligation on orders placed under this contract is contingent upon the availability of appropriated funds from which payment for ordering purposes can be made. No legal liability on the part of the Government for any payment may arise until funds are available to the ordering Contracting Officer.
(k) Overtime: For professional services, the labor rates in the Schedule should not vary by virtue of the Contractor having worked overtime. For services applicable to the Service
Contract Act (as identified in the Schedule), the labor rates in the Schedule will vary as governed by labor laws (usually assessed a time and a half of the labor rate).
15. CONTRACT ADMINISTRATION FOR ORDERING ACTIVITIES:
Any ordering activity, with respect to any one or more delivery orders placed by it under this contract, may exercise the same rights of termination as might the GSA Contracting Officer under provisions of FAR 52.212-4, paragraphs (l) Termination for the ordering activity’s convenience, and (m) Termination for Cause (See 52.212-4)
16. GSA ADVANTAGE!
GSA Advantage! is an on-line, interactive electronic information and ordering system that provides on-line access to vendors' schedule prices with ordering information. GSA Advantage!
will allow the user to perform various searches across all contracts including, but not limited to:
(1) Manufacturer;
(2) Manufacturer's Part Number; and
(3) Product categories.
Agencies can browse GSA Advantage! by accessing the Internet World Wide Web utilizing a browser (ex.: NetScape). The Internet address is http://www.gsaadvantage.gov http://www.gsaadvantage.gov/
Page | 10
17. PURCHASE OF OPEN MARKET ITEMS
NOTE: Open Market Items are also known as incidental items, noncontract items, non- Schedule items, and items not on a Federal Supply Schedule contract. ODCs (Other Direct Costs) are not part of this contract and should be treated as open market purchases. Ordering Activities procuring open market items must follow FAR 8.402(f).
For administrative convenience, an ordering activity contracting officer may add items not on the Federal Supply Multiple Award Schedule (MAS) -- referred to as open market items -- to a Federal Supply Schedule blanket purchase agreement (BPA) or an individual task or delivery order, only if-
(1) All applicable acquisition regulations pertaining to the purchase of the items not on the Federal Supply Schedule have been followed (e.g., publicizing (Part 5), competition requirements (Part 6), acquisition of commercial items (Part 12), contracting methods (Parts 13, 14, and 15), and small business programs (Part 19));
(2) The ordering activity contracting officer has determined the price for the items not on the Federal Supply Schedule is fair and reasonable;
(3) The items are clearly labeled on the order as items not on the Federal Supply Schedule; and
(4) All clauses applicable to items not on the Federal Supply Schedule are included in the order.
18. CONTRACTOR COMMITMENTS, WARRANTIES AND REPRESENTATIONS
a. For the purpose of this contract, commitments, warranties and representations include, in addition to those agreed to for the entire schedule contract:
(1) Time of delivery/installation quotations for individual orders;
(2) Technical representations and/or warranties of products concerning performance, total system performance and/or configuration, physical, design and/or functional characteristics and capabilities of a product/equipment/ service/software package submitted in response to requirements which result in orders under this schedule contract.
(3) Any representations and/or warranties concerning the products made in any literature, description, drawings and/or specifications furnished by the Contractor.
b. The above is not intended to encompass items not currently covered by the GSA Schedule contract.
19. OVERSEAS ACTIVITIES
The terms and conditions of this contract shall apply to all orders for installation, maintenance and repair of equipment in areas listed in the pricelist outside the 48 contiguous states and the District of Columbia, except as indicated below: N/A
Upon request of the Contractor, the ordering activity may provide the Contractor with logistics support, as available, in accordance with all applicable ordering activity regulations. Such ordering activity support will be provided on a reimbursable basis, and will only be provided to
Page | 11 the Contractor's technical personnel whose services are exclusively required for the fulfillment of the terms and conditions of this contract.
20. BLANKET PURCHASE AGREEMENTS (BPAs)
The use of BPAs under any schedule contract to fill repetitive needs for supplies or services is allowable. BPAs may be established with one or more schedule contractors. The number of BPAs to be established is within the discretion of the ordering activity establishing the BPA and should be based on a strategy that is expected to maximize the effectiveness of the BPA(s).
Ordering activities shall follow FAR 8.405-3 when creating and implementing BPA(s).
21. CONTRACTOR TEAM ARRANGEMENTS
Contractors participating in contractor team arrangements must abide by all terms and conditions of their respective contracts. This includes compliance with Clauses 552.238-74, Industrial Funding Fee and Sales Reporting, i.e., each contractor (team member) must report sales and remit the IFF for all products and services provided under its individual contract.
22. INSTALLATION, DEINSTALLATION, REINSTALLATION
The Davis-Bacon Act (40 U.S.C. 276a-276a-7) provides that contracts in excess of $2,000 to which the United States or the District of Columbia is a party for construction, alteration, or repair (including painting and decorating) of public buildings or public works with the United States, shall contain a clause that no laborer or mechanic employed directly upon the site of the work shall receive less than the prevailing wage rates as determined by the Secretary of Labor.
The requirements of the Davis-Bacon Act do not apply if the construction work is incidental to the furnishing of supplies, equipment, or services. For example, the requirements do not apply to simple installation or alteration of a public building or public work that is incidental to furnishing supplies or equipment under a supply contract. However, if the construction, alteration or repair is segregable and exceeds $2,000, then the requirements of the Davis-Bacon Act applies.
The ordering activity issuing the task order against this contract will be responsible for proper administration and enforcement of the Federal labor standards covered by the Davis-Bacon Act.
The proper Davis-Bacon wage determination will be issued by the ordering activity at the time a request for quotations is made for applicable construction classified installation, deinstallation, and reinstallation services under SIN 132-8 or 132-9.
23. SECTION 508 COMPLIANCE.
If applicable, Section 508 compliance information on the supplies and services in this contract are available in Electronic and Information Technology (EIT) at the following: N/A
The EIT standard can be found at: www.Section508.gov/.
http://www.section508.gov/
Page | 12
24. PRIME CONTRACTOR ORDERING FROM FEDERAL SUPPLY SCHEDULES.
Prime Contractors (on cost reimbursement contracts) placing orders under Federal Supply Schedules, on behalf of an ordering activity, shall follow the terms of the applicable schedule and authorization and include with each order –
(a) A copy of the authorization from the ordering activity with whom the contractor has the prime contract (unless a copy was previously furnished to the Federal Supply Schedule contractor); and
(b) The following statement:
This order is placed under written authorization from dated . In the event of any inconsistency between the terms and conditions of this order and those of your Federal Supply Schedule contract, the latter will govern.
25. INSURANCE—WORK ON A GOVERNMENT INSTALLATION (JAN 1997) (FAR
52.228-5)
(a) The Contractor shall, at its own expense, provide and maintain during the entire performance of this contract, at least the kinds and minimum amounts of insurance required in the Schedule or elsewhere in the contract.
(b) Before commencing work under this contract, the Contractor shall notify the Contracting Officer in writing that the required insurance has been obtained. The policies evidencing required insurance shall contain an endorsement to the effect that any cancellation or any material change adversely affecting the Government's interest shall not be effective—
(1) For such period as the laws of the State in which this contract is to be performed prescribe; or
(2) Until 30 days after the insurer or the Contractor gives written notice to the
Contracting Officer, whichever period is longer.
(c) The Contractor shall insert the substance of this clause, including this paragraph (c), in subcontracts under this contract that require work on a Government installation and shall require subcontractors to provide and maintain the insurance required in the Schedule or elsewhere in the contract. The Contractor shall maintain a copy of all subcontractors' proofs of required insurance, and shall make copies available to the Contracting Officer upon request.
26. SOFTWARE INTEROPERABILITY.
Offerors are encouraged to identify within their software items any component interfaces that support open standard interoperability. An item’s interface may be identified as interoperable on the basis of participation in a Government agency-sponsored program or in an independent organization program. Interfaces may be identified by reference to an interface registered in the component registry located at http://www.core.gov.
27. ADVANCE PAYMENTS
A payment under this contract to provide a service or deliver an article for the United States Government may not be more than the value of the service already provided or the article already delivered. Advance or pre-payment is not authorized or allowed under this contract. (31 U.S.C. 3324) http://www.core.gov/
Page | 13
Vendor suitability for offering services through the Highly Adaptive Cybersecurity Services (HACS) SIN must be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:
● Federal Acquisition Regulation (FAR) Part 52.204-21
● OMB Memorandum M-17-12 - Preparing for and Responding to a Breach of Personally
Identifiable Information (PII)
● OMB Memorandum M- 19-03 - Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program
● 2017 Report to the President on Federal IT Modernization
● The Cybersecurity National Action Plan (CNAP)
● NIST SP 800-14 - Generally Accepted Principles and Practices for Securing
Information Technology Systems
● NIST SP 800-27A - Engineering Principles for Information Technology Security (A
Baseline for Achieving Security)
● NIST SP 800-30 - Guide for Conducting Risk Assessments
● NIST SP 800-35 - Guide to Information Technology Security Services
● NIST SP 800-37 - Risk Management Framework for Information Systems and
Organizations: A Systems Life Cycle Approach for Security and Privacy
● NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and
Information System View
● NIST SP 800-44 - Guidelines on Securing Public Web Servers
● NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks
● NIST SP 800-53 – Security and Privacy Controls for Federal Information
Systems and Organizations
● NIST SP 800-61 - Computer Security Incident Handling Guide
● NIST SP 800-64 - Security Considerations in the System Development Life Cycle
● NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security
● NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident Response
● NIST SP 800-115 - Technical Guide to Information Security Testing and Assessment
● NIST SP 800-128 - Guide for Security-Focused Configuration Management of
Information Systems
● NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for Federal
Information Systems and Organizations
● NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks (WLANs)
● NIST SP 800-160 - Systems Security Engineering: Considerations for a
Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
● NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal
Information Systems and Organizations
1. SCOPE
a. The labor categories, prices, terms and conditions stated under Special Item Number 132- 45 Highly Adaptive Cybersecurity Services (HACS) apply exclusively to Highly Adaptive Cybersecurity Services within the scope of this Information Technology Schedule.
TERMS AND CONDITIONS APPLICABLE TO HIGHLY ADAPTIVE CYBERSECURITY
SERVICES (HACS) (SPECIAL ITEM NUMBERS 132-45)
Page | 14
b. Services under this SIN are limited to Highly Adaptive Cybersecurity Services only. Software and hardware products are under different Special Item Numbers on IT Schedule 70 (e.g. 132- 32, 132-33, 132-8), and may be quoted along with services to provide a total solution.
c. This SIN provides ordering activities with access to Highly Adaptive Cybersecurity services only.
d. Highly Adaptive Cybersecurity Services provided under this SIN shall comply with all Cybersecurity certifications and industry standards as applicable pertaining to the type of services as specified by ordering agency.
e. SCOPE:
132-45 Highly Adaptive Cybersecurity Services (HACS) - SUBJECT TO COOPERATIVE PURCHASING - includes proactive and reactive cybersecurity services that improve the customer’s enterprise-level security posture.
The scope of this category encompasses a wide range of fields that include, but are not limited to, Risk Management Framework (RMF) services, information assurance (IA), virus detection, network management, situational awareness and incident response, secure web hosting, and backup and security services.
The seven-step RMF includes preparation, information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.. RMF activities may also include Information Security Continuous Monitoring Assessment (ISCMA) which evaluate organization-wide ISCM implementations, and also Federal Incident Response Evaluations (FIREs), which assess an organization’s incident management functions.
The scope of this category also includes Security Operations Center (SOC) services. The SOC scope includes services such as: 24x7x365 monitoring and analysis, traffic analysis, incident response and coordination, penetration testing, anti-virus management, intrusion detection and prevention, and information sharing.
HACS vendors are able to identify and protect a customer’s information resources, detect and respond to cybersecurity events or incidents, and recover capabilities or services impaired by any incidents that emerge.
Sub-Categories - (not all vendors have been placed within the following subcategories. To view a complete list of vendors, click on the SIN)
● High Value Asset (HVA) Assessments include Risk and Vulnerability Assessment (RVA) which assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub- category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing. Security Architecture Review (SAR) evaluates a subset of the agency’s HVA security posture to determine whether the agency has properly architected its cybersecurity solutions and ensures that agency leadership fully understands the risks inherent in the implemented cybersecurity solution. The SAR process utilizes in-person interviews, documentation reviews, and leading practice evaluations of the HVA environment and supporting systems. SAR provides a holistic analysis of how an HVA’s individual security components integrate and operate, including how data is protected
Page | 15 during operations. Systems Security Engineering (SSE)identifies security vulnerabilities and minimizes or contains risks associated with these vulnerabilities spanning the Systems Development Life Cycle. SSE focuses on, but is not limited to the following security areas:
perimeter security, network security, endpoint security, application security, physical security, and data security.
● Risk and Vulnerability Assessment (RVA) assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing.
● Cyber Hunt activities respond to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Cyber Hunts start with the premise that threat actors known to target some organizations in a specific industry or with specific systems are likely to also target other organizations in the same industry or with the same systems.
● Incident Response services help organizations impacted by a cybersecurity compromise determine the extent of the incident, remove the adversary from their systems, and restore their networks to a more secure state.
● Penetration Testing is security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network.
f. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.
2. ORDER
a. Agencies may use written orders, Electronic Data Interchange (EDI) orders, Blanket Purchase Agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
3. PERFORMANCE OF SERVICES
a. The Contractor shall commence performance of services on the date agreed to by the Contractor and the ordering activity. All Contracts will be fully funded.
b. The Contractor agrees to render services during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
Page | 16
c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.
d. Any Contractor travel required in the performance of Highly Adaptive Cybersecurity Services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts. All travel will be agreed upon with the client prior to the Contractor’s travel.
4. INSPECTION OF SERVICES
Inspection of services is in accordance with 552.212-4 - CONTRACT TERMS AND CONDITIONS– COMMERCIAL ITEMS (Jan 2017) & (ALTERNATE I-Jan 2017) for Time-and-Materials and Labor-Hour orders placed under this contract.
5. RESPONSIBILITIES OF THE CONTRACTOR
The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR 52.227-14 (May 2014) Rights in Data – General, may apply.
The Contractor shall comply with contract clause (52.204-21) to the Federal Acquisition Regulation (FAR) for the basic safeguarding of contractor information systems that process, store, or transmit Federal data received by the contract in performance of the contract. This includes contract documents and all information generated in the performance of the contract.
6. RESPONSIBILITIES OF THE ORDERING ACTIVITY
Subject to the ordering activity security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite Highly Adaptive Cybersecurity Services.
7. INDEPENDENT CONTRACTOR
All Highly Adaptive Cybersecurity Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.
8. ORGANIZATIONAL CONFLICTS OF INTEREST
a. Definitions.
“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.
Page | 17
“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.
An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.
b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.
9. INVOICES
The Contractor, upon completion of the work ordered, shall submit invoices for Highly Adaptive Cybersecurity Services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.
10. RESUMES
Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.
11. APPROVAL OF SUBCONTRACTS
The ordering activity may require that the Contractor receive, from the ordering activity Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.
12. DESCRIPTION OF HIGHLY ADAPTIVE CYBERSECURITY SERVICES AND PRICING
a. The Contractor shall provide a description of each type of Highly Adaptive Cybersecurity
Service offered under Special Item Number 132-45 for Highly Adaptive Cybersecurity Services and it should be presented in the same manner as the Contractor sells to its commercial and other ordering activity customers. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles (labor categories) for those individuals who will perform the service should be provided.
b. Pricing for all Highly Adaptive Cybersecurity Services shall be in accordance with the Contractor’s customary commercial practices; e.g., hourly rates, minimum general
Page | 18 experience and minimum education. The following is an example of the manner in which the description of a commercial job title should be presented (see SCP FSS 004)
EXAMPLE
Commercial Job Title: Computer Network Defense Analysis
Description: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Professionals involved in this specialty perform the following tasks:
▪ Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
▪ Provide daily summary reports of network events and activity relevant to Computer Network Defense practices
▪ Monitor external data sources (e.g., Computer Network Defense vendor sites, Computer Emergency Response Teams, SANS, Security Focus) to maintain currency of Computer Network Defense threat condition and determine which security issues may have an impact on the enterprise.
Knowledge, Skills and Abilities: Knowledge of applicable laws (e.g., Electronic Communications Privacy Act, Foreign Intelligence Surveillance Act, Protect America Act, search and seizure laws, civil liberties and privacy laws, etc.), statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code), Presidential Directives, executive branch guidelines, and/or administrative/criminal legal guidelines and procedures relevant to work performed
Minimum Experience: 5 Years
Minimum Education Requirements: a bachelor's of science degree with a concentration in computer science, cybersecurity services, management information systems (MIS), engineering or information science is essential.
Highly Desirable: Offensive Security Certified Professional (OSCP) or commercial Cybersecurity advanced certification(s).
Page | 19
1. SCOPE
a. The prices, terms and conditions stated under Special Item Number 132-51 Information Technology Professional Services apply exclusively to IT/IAM Professional Services within the scope of this Information Technology Schedule.
b. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.
2. PERFORMANCE INCENTIVES I-FSS-60 Performance Incentives (April 2000)
a. Performance incentives may be agreed upon between the Contractor and the ordering activity on individual fixed price orders or Blanket Purchase Agreements under this contract.
b. The ordering activity must establish a maximum performance incentive price for these services and/or total solutions on individual orders or Blanket Purchase Agreements.
c. Incentives should be designed to relate results achieved by the contractor to specified targets. To the maximum extent practicable, ordering activities shall consider establishing incentives where performance is critical to the ordering activity’s mission and incentives are likely to motivate the contractor. Incentives shall be based on objectively measurable tasks.
3. ORDER
a. Agencies may use written orders, EDI orders, blanket purchase agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
4. PERFORMANCE OF SERVICES
a. The Contractor shall commence performance of services on the date agreed to by the Contractor and the ordering activity.
b. The Contractor agrees to render services only during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.
d. Any Contractor travel required in the performance of IT/IAM Services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the
TERMS AND CONDITIONS APPLICABLE TO INFORMATION TECHNOLOGY (IT)
PROFESSIONAL SERVICES (SPECIAL ITEM NUMBER 132-51)
Page | 20 date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts.
5. STOP-WORK ORDER (FAR 52.242-15) (AUG 1989)
a. The Contracting Officer may, at any time, by written order to the Contractor, require the Contractor to stop all, or any part, of the work called for by this contract for a period of 90 days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 days after a stop-work is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the Contracting Officer shall either
(1) Cancel the stop-work order; or
(2) Terminate the work covered by the order as provided in the Default, or the Termination for Convenience of the Government, clause of this contract.
b. If a stop-work order issued under this clause is canceled or the period of the order or any extension thereof expires, the Contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule or contract price, or both, and the contract shall be modified, in writing, accordingly, if
i. the stop-work order results in an increase in the time required for, or in the Contractor's cost properly allocable to, the performance of any part of this contract; and
ii. The Contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage; provided, that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and act upon the claim submitted at any time before final payment under this contract.
c. If a stop-work order is not canceled and the work covered by the order is terminated for the convenience of the Government, the Contracting Officer shall allow reasonable costs resulting from the stop-work order in arriving at the termination settlement.
d. If a stop-work order is not canceled and the work covered by the order is terminated for default, the Contracting Officer shall allow, by equitable adjustment or otherwise, reasonable costs resulting from the stop-work order.
6. INSPECTION OF SERVICES
In accordance with 552.212-4 CONTRACT TERMS AND CONDITIONS–COMMERCIAL ITEMS (JAN 2017) (DEVIATION – FEB 2007)(DEVIATION - FEB 2018) for Firm-Fixed Price orders; or
GSAR 552.212-4 CONTRACT TERMS AND CONDITIONS-COMMERCIAL ITEMS (JAN 2017)
(DEVIATION - FEB 2018) (ALTERNATE I - JAN 2017) (DEVIATION -FEB 2007) for Time-and- Materials and Labor-Hour Contracts orders placed under this contract.
7. RESPONSIBILITIES OF THE CONTRACTOR
The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .