MAS - Cyber Defense Technologies LLC - 47QTCA20D006K
PDF 648 KB
- Attached to
- Federal Supply Schedule 47QTCA20D006K Federal contract IDV
- Contract number
- 47QTCA20D006K
- Issued by
- GSA Federal Acquisition Service
About this file
This is a federal supply schedule pricelist for information technology products and services. Cyber Defense Technologies was awarded contract number 47QTCA20D006K, effective from February 25, 2020 through February 24, 2025. The contractor provides highly adaptive cybersecurity services, IT professional services, and IT equipment, software and related items. Offerings include cyber program management, project management, exploitation engineering, incident response, SOC analysis, information assurance engineering, and engineering labor categories up to the senior level. Rates are available from 2-7% off list price. The contract supports federal civilian agencies and is available for use under cooperative purchasing agreements.
Cyber Defense Technologies LLC Pricelist and/or Vendor Terms and Conditions for 47QTCA20D006K, a Federal Supply Schedule awarded to Cyber Defense Technologies LLC, under Information Technology Schedule 70 (IT-70)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AUTHORIZED FEDERAL SUPPLY SERVICE
INFORMATION TECHNOLOGY SCHEDULE PRICELIST
GENERAL PURPOSE COMMERCIAL INFORMATION TECHNOLOGY
EQUIPMENT, SOFTWARE AND SERVICES
Cyber Defense Technologies, LLC 22375 Broderick Drive, #115, Dulles, VA 20166 www. cyberdefensetechnologies.com | (Tel) 800.658.1846 Contract Administrator: William Kimble | William. Kimble @cyberdefensetechnologies.com
Business Size Status: Small Business Concern/SDVOSB.
General Services Administration Contract Number: 47QTCA20D006K Period Covered by Contract: 2/25/2020 – 2/24/2025 Pricelist current through Modification: A826.
Schedule Title: Multiple Award Schedule Large Category: Information Technology PSCs for Associated SINs: D310, D399
Online access to contract ordering information, terms, and conditions, up to date pricing, and the option to create an electronic delivery order are available through GSA Advantage! a menu driven database system. The INTERNET address for GSA Advantage! is: GSAAdvantage.gov.
For more information on ordering from Federal Supply Schedules click on the FSS Schedules button at fss.gsa.gov.
Online access to contract ordering information, terms and conditions, up to date pricing, and the option to create an electronic delivery order are available through GSA Advantage!, a menu driven database system. The INTERNET address GSA Advantage! is: GSAAdvantage.gov.
For more information on ordering from Federal Supply Schedules click on the FSS Schedules button at fss.gsa.gov., Contract period.
#47QTCA20D006K
2 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
Table of Contents
CUSTOMER INFORMATION
TERMS AND CONDITIONS APPLICABLE TO HIGHLY ADAPTIVE CYBERSECURITY SERVICES (HACS) (SPECIAL ITEM
NUMBERS 54151HACS
TERMS AND CONDITIONS IT PROFESSIONAL SERVICES (SPECIAL ITEM NUMBER 54151S)
3 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
CUSTOMER INFORMATION
1a. Table of awarded special item numbers with appropriate cross-reference to item descriptions and awarded prices.
SIN 54151HACS and 54151S see Terms and Conditions.
1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract. This price is the Government price based on a unit of one, exclusive of any quantity/dollar volume, prompt payment, or any other concession affecting price. Those contracts that have unit prices based on the geographic location of the customer, should show the range of the lowest price, and cite the areas to which the prices apply. N/A
1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided. If hourly rates are not applicable, indicate “Not applicable” for this item.
See Terms and Conditions.
2. Maximum order. SIN 54151HACS and 54151S - $500,000
3. Minimum order. $100.00
4. Geographic coverage (delivery area). CONUS
5. Points of production (city, county, and State or foreign country). Same as Contractor Address
6. Discount from list prices or statement of net price. 2% - 7% from list price
7. Quantity discounts. None
8. Prompt payment terms. Note: Prompt payment terms must be followed by the statement "Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions." 0.0% Disount
9a. Notification that Government purchase cards are accepted at or below the micro-purchase threshold.
Purchase cards are accepted at or below the micro-purchase threshold.
9b. Notification whether Government purchase cards are accepted or not accepted above the micro-purchase threshold.
Purchase cards are accepted above the micro-purchase threshold.
10. Foreign items (list items by country of origin). None
11a. Time of delivery. (Contractor insert number of days.) Negotiate with Contractor at task order level.
11b. Expedited Delivery. The Contractor will insert the sentence “Items available for expedited delivery are noted in this price list.” under this heading. The Contractor may use a symbol of its choosing to highlight items in its price lists that have expedited delivery. Customer may contact the Contractor for expedited delivery
11c. Overnight and 2-day delivery. The Contractor will indicate whether overnight and 2-day delivery are available.
Also, the Contractor will indicate that the schedule customer may contact the Contractor for rates for overnight and 2-day delivery. Customer may contact the Contractor for rates for overnight and 2-day delivery
4 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
11d. Urgent Requirements. The Contractor will note in its price list the “Urgent Requirements” clause of its contract and advise agencies that they can also contact the Contractor’s representative to effect a faster delivery.
Customer may contact the Contractor to effect a faster delivery
12. F.O.B. point. N/A - Services
13a. Ordering address. Same as Contractor address
13b. Ordering procedures: For supplies and services, the ordering procedures, information on Blanket Purchase Agreements (BPA’s) are found in Federal Acquisition Regulation (FAR) 8.405-3.
14. Payment address. Same as Contractor address
15. Warranty provision. Standard
16. Export packing charges, if applicable. N/A
17. Terms and conditions of Government purchase card acceptance (any thresholds above the micro-purchase level). N/A
18. Terms and conditions of rental, maintenance, and repair. N/A
19. Terms and conditions of installation. N/A
20. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices. N/A
20a. Terms and conditions for any other services. N/A
21. List of service and distribution points. N/A
22. List of participating dealers. N/A
23. Preventive maintenance. N/A
24a. Special attributes such as environmental attributes. N/A
24b. If applicable, indicate that Section 508 compliance information is available on Electronic and Information Technology (EIT) supplies and services and show where full details can be found (e.g. contractor’s website or other location.) The EIT standards can be found at: www.Section508.gov/.
25. Data Universal Number System (DUNS) number. 033454696
26. Notification regarding registration in is registered in the System for Award Management (SAM) Database.
7K6K4 http://www.section508.gov/
5 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
TERMS AND CONDITIONS APPLICABLE TO HIGHLY ADAPTIVE CYBERSECURITY SERVICES (HACS)
(SPECIAL ITEM NUMBERS 54151HACS)
Vendor suitability for offering services through the Highly Adaptive Cybersecurity Services (HACS) SIN must be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:
● Federal Acquisition Regulation (FAR) Part 52.204-21
● OMB Memorandum M-17-12 - Preparing for and Responding to a Breach of Personally Identifiable Information (PII)
● OMB Memorandum M- 19-03 - Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program
● 2017 Report to the President on Federal IT Modernization
● The Cybersecurity National Action Plan (CNAP)
● NIST SP 800-14 - Generally Accepted Principles and Practices for Securing
Information Technology Systems
● NIST SP 800-27A - Engineering Principles for Information Technology Security (A
Baseline for Achieving Security)
● NIST SP 800-30 - Guide for Conducting Risk Assessments
● NIST SP 800-35 - Guide to Information Technology Security Services
● NIST SP 800-37 - Risk Management Framework for Information Systems and
Organizations: A Systems Life Cycle Approach for Security and Privacy
● NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and
Information System View
● NIST SP 800-44 - Guidelines on Securing Public Web Servers
● NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks
● NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations
● NIST SP 800-61 - Computer Security Incident Handling Guide
● NIST SP 800-64 - Security Considerations in the System Development Life Cycle
● NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security
● NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident
Response
● NIST SP 800-115 - Technical Guide to Information Security Testing and
Assessment
● NIST SP 800-128 - Guide for Security-Focused Configuration Management of
Information Systems
● NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for
Federal Information Systems and Organizations
6 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
● NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks (WLANs) ● NIST SP 800-160 - Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
● NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal Information Systems and Organizations
1. SCOPE
a. The labor categories, prices, terms and conditions stated under Special
Item Number 132- 45 Highly Adaptive Cybersecurity Services (HACS) apply exclusively to Highly Adaptive Cybersecurity Services within the scope of this Information Technology Schedule.
b. Services under this SIN are limited to Highly Adaptive Cybersecurity Services only. Software and hardware products are under different Special Item Numbers on IT Schedule 70 (e.g. 132-32, 132-33, 132-8), and may be quoted along with services to provide a total solution.
c. This SIN provides ordering activities with access to Highly Adaptive Cybersecurity services only.
d. Highly Adaptive Cybersecurity Services provided under this SIN shall comply with all Cybersecurity certifications and industry standards as applicable pertaining to the type of services as specified by ordering agency.
e. SCOPE:
54151HACS Highly Adaptive Cybersecurity Services (HACS) - SUBJECT TO COOPERATIVE PURCHASING - includes proactive and reactive cybersecurity services that improve the customer’s enterprise-level security posture.
The scope of this category encompasses a wide range of fields that include, but are not limited to, Risk Management Framework (RMF) services, information assurance (IA), virus detection, network management, situational awareness and incident response, secure web hosting, and backup and security services.
The seven-step RMF includes preparation, information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.. RMF activities may also include Information Security Continuous Monitoring Assessment (ISCMA) which evaluate organization-wide ISCM implementations, and also Federal Incident Response Evaluations (FIREs), which assess an organization’s incident management functions.
7 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
The scope of this category also includes Security Operations Center (SOC) services. The SOC scope includes services such as: 24x7x365 monitoring and analysis, traffic analysis, incident response and coordination, penetration testing, anti-virus management, intrusion detection and prevention, and information sharing.
HACS vendors are able to identify and protect a customer’s information resources, detect and respond to cybersecurity events or incidents, and recover capabilities or services impaired by any incidents that emerge.
Sub-Categories - (not all vendors have been placed within the following subcategories.
To view a complete list of vendors, click on the SIN)
● High Value Asset (HVA) Assessments include Risk and Vulnerability Assessment (RVA) which assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA subcategory include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing. Security Architecture Review (SAR) evaluates a subset of the agency’s HVA security posture to determine whether the agency has properly architected its cybersecurity solutions and ensures that agency leadership fully understands the risks inherent in the implemented cybersecurity solution. The SAR process utilizes in-person interviews, documentation reviews, and leading practice evaluations of the HVA environment and supporting systems. SAR provides a holistic analysis of how an HVA’s individual security components integrate and operate, including how data is protected during operations. Systems Security Engineering (SSE) identifies security vulnerabilities and minimizes or contains risks associated with these vulnerabilities spanning the Systems Development Life Cycle. SSE focuses on, but is not limited to the following security areas: perimeter security, network security, endpoint security, application security, physical security, and data security.
● Risk and Vulnerability Assessment (RVA) assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, 8 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing.
● Cyber Hunt activities respond to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Cyber Hunts start with the premise that threat actors known to target some organizations in a specific industry or with specific systems are likely to also target other organizations in the same industry or with the same systems.
● Incident Response services help organizations impacted by a cybersecurity compromise determine the extent of the incident, remove the adversary from their systems, and restore their networks to a more secure state.
● Penetration Testing is security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network.
f. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.
2. ORDER
a. Agencies may use written orders, Electronic Data Interchange (EDI) orders, Blanket Purchase Agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order.
Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
3. PERFORMANCE OF SERVICES
a. The Contractor shall commence performance of services on the date agreed to by the Contractor and the ordering activity. All Contracts will be fully funded.
b. The Contractor agrees to render services during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
9 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order.
Services shall be completed in a good and workmanlike manner.
d. Any Contractor travel required in the performance of Highly Adaptive Cybersecurity Services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed.
Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts. All travel will be agreed upon with the client prior to the Contractor’s travel.
4. INSPECTION OF SERVICES
Inspection of services is in accordance with 552.212-4 - CONTRACT TERMS AND CONDITIONS– COMMERCIAL ITEMS (Jan 2017) & (ALTERNATE I-Jan 2017) for Time-and-Materials and Labor-Hour orders placed under this contract.
5. RESPONSIBILITIES OF THE CONTRACTOR
The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR 52.227-14 (May 2014) Rights in Data – General, may apply.
The Contractor shall comply with contract clause (52.204-21) to the Federal Acquisition Regulation (FAR) for the basic safeguarding of contractor information systems that process, store, or transmit Federal data received by the contract in performance of the contract. This includes contract documents and all information generated in the performance of the contract.
6. RESPONSIBILITIES OF THE ORDERING ACTIVITY
Subject to the ordering activity security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite Highly Adaptive Cybersecurity Services.
7. INDEPENDENT CONTRACTOR
All Highly Adaptive Cybersecurity Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.
8. ORGANIZATIONAL CONFLICTS OF INTEREST
10 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
a. Definitions.
“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.
“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.
An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.
b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.
9. INVOICES
The Contractor, upon completion of the work ordered, shall submit invoices for Highly Adaptive Cybersecurity Services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.
10. RESUMES
Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.
11. APPROVAL OF SUBCONTRACTS
11 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
The ordering activity may require that the Contractor receive, from the ordering activity Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.
12. DESCRIPTION OF HIGHLY ADAPTIVE CYBERSECURITY SERVICES
AND PRICING
a. The Contractor shall provide a description of each type of Highly Adaptive Cybersecurity Service offered under Special Item Number 54151HACS for Highly Adaptive Cybersecurity Services and it should be presented in the same manner as the Contractor sells to its commercial and other ordering activity customers. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles (labor categories) for those individuals who will perform the service should be provided.
b. Pricing for all Highly Adaptive Cybersecurity Services shall be in accordance with the Contractor’s customary commercial practices; e.g., hourly rates, minimum general experience and minimum education.
12 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
TERMS AND CONDITIONS IT PROFESSIONAL SERVICES
(SPECIAL ITEM NUMBER 54151S)
1. SCOPE
The prices, terms and conditions stated under Special Item Number 54151S Information Technology Professional Services apply exclusively to IT Professional Services within the scope of this Information Technology Schedule.
The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.
2. PERFORMANCE INCENTIVES I-FSS-60 Performance Incentives (April 2000)
Performance incentives may be agreed upon between the Contractor and the ordering activity on individual fixed price orders or Blanket Purchase Agreements under this contract.
The ordering activity must establish a maximum performance incentive price for these services and/or total solutions on individual orders or Blanket Purchase Agreements.
Incentives should be designed to relate results achieved by the contractor to specified targets. To the maximum extent practicable, ordering activities shall consider establishing incentives where performance is critical to the ordering activity’s mission and incentives are likely to motivate the contractor. Incentives shall be based on objectively measurable tasks.
3. ORDER
Agencies may use written orders, EDI orders, blanket purchase agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
4. PERFORMANCE OF SERVICES
The Contractor shall commence performance of services on the date agreed to by the Contractor and the ordering activity.
The Contractor agrees to render services only during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
13 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.
Any Contractor travel required in the performance of IT Services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed.
Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts.
5. STOP-WORK ORDER (FAR 52.242-15) (AUG 1989)
The Contracting Officer may, at any time, by written order to the Contractor, require the Contractor to stop all, or any part, of the work called for by this contract for a period of 90 days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 days after a stop-work is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the Contracting Officer shall either-
Cancel the stop-work order; or
Terminate the work covered by the order as provided in the Default, or the Termination for Convenience of the Government, clause of this contract.
If a stop-work order issued under this clause is canceled or the period of the order or any extension thereof expires, the Contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule or contract price, or both, and the contract shall be modified, in writing, accordingly, if-
The stop-work order results in an increase in the time required for, or in the Contractor's cost properly allocable to, the performance of any part of this contract; and
The Contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage; provided, that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and act upon the claim submitted at any time before final payment under this contract.
If a stop-work order is not canceled and the work covered by the order is terminated for the convenience of the Government, the Contracting Officer shall allow reasonable costs resulting from the stop-work order in arriving at the termination settlement.
14 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
If a stop-work order is not canceled and the work covered by the order is terminated for default, the Contracting Officer shall allow, by equitable adjustment or otherwise, reasonable costs resulting from the stop-work order.
6. INSPECTION OF SERVICES
In accordance with FAR 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (MAR 2009) (DEVIATION I - FEB 2007) for Firm-Fixed Price orders and FAR 52.212-4 CONTRACT TERMS AND COMMERCIAL ITEMS (MAR 2009) OCT 2008) (DEVIATION I – FEB 2007) applies to Time-and- Materials and Labor-Hour Contracts orders placed under this contract.
7. RESPONSIBILITIES OF THE CONTRACTOR
The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR 52.227-14 (Dec 2007) Rights in Data – General, may apply.
8. RESPONSIBILITIES OF THE ORDERING ACTIVITY
Subject to security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite IT Professional Services.
9. INDEPENDENT CONTRACTOR
All IT Professional Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.
10. ORGANIZATIONAL CONFLICTS OF INTEREST
Definitions.
“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.
“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.
An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.
To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against
15 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.
11. INVOICES
The Contractor, upon completion of the work ordered, shall submit invoices for IT Professional services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.
12. PAYMENTS
For firm-fixed price orders the ordering activity shall pay the Contractor, upon submission of proper invoices or vouchers, the prices stipulated in this contract for service rendered and accepted.
Progress payments shall be made only when authorized by the order. For time-and-materials orders, the Payments under Time-and-Materials and Labor-Hour Contracts at FAR 52.212-4 (MAR 2009) (ALTERNATE I – OCT 2008) (DEVIATION I – FEB 2007) applies to time-and-materials orders placed under this contract. For labor-hour orders, the Payment under Time-and-Materials and LaborHour Contracts at FAR 52.212-4 (MAR 2009) (ALTERNATE I – OCT 2008) (DEVIATION I – FEB 2007) applies to labor-hour orders placed under this contract. 52.216-31(Feb 2007) Time-and Materials/Labor-Hour Proposal Requirements—Commercial Item Acquisition. As prescribed in 16.601(e)(3), insert the following provision:
The Government contemplates award of a Time-and-Materials or Labor-Hour type of contract resulting from this solicitation.
The offeror must specify fixed hourly rates in its offer that include wages, overhead, general and administrative expenses, and profit. The offeror must specify whether the fixed hourly rate for each labor category applies to labor performed by—
The offeror;
Subcontractors; and/or
Divisions, subsidiaries, or affiliates of the offeror under a common control.
13. RESUMES
Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.
14. INCIDENTAL SUPPORT COSTS
16 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
Incidental support costs are available outside the scope of this contract. The costs will be negotiated separately with the ordering activity in accordance with the guidelines set forth in the FAR.
15. APPROVAL OF SUBCONTRACTS
The ordering activity may require that the Contractor receive, from the ordering activity's Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.
16. DESCRIPTION OF IT PROFESSIONAL SERVICES AND PRICING
17 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
Labor Categories
SIN 54151HACS
Title: Cyber Program Manager V
Functional Duties/Responsibilities: Responsible for the initiation, scope planning (including decomposing work effort into work packages), resource assignment, team technical/schedule/cost delivery performance, monitoring and reporting, change management, and project close for a defined Cyber project. Engages external clients and internal resources and management for all items related to the Cyber program. May provide Cyber and/or business insights and guidance to the delivery team to resolve complex challenges. May have responsibility for the oversight of multiple concurrent Cyber projects or programs.
Minimum Education: A Master’s degree in Computer Science, Engineering, or Information Technology/Operations Management, or an equivalent technical degree. Bachelor’s degree requires two (2) additional years of minimum experience. Non-technical degrees must be supplemented by various technical Cyber certifications.
Minimum Experience Requirements: Technically-degreed individuals must have ten (10) years of overall experience which exhibit increasing levels of responsibility including eight (8) years of Cyber-specific Program Manager experience. Non-technically degreed individuals must have twelve (12) years of Cyber-specific experience.
Required/Supplemental Certifications: Advanced technical Cyber certifications in aggregate equivalent to a CISSP, CISM or GSLC or related. Advanced knowledge of PMBOK required, Project Management Professional (PMP) preferred.
Title: Cyber Project Manager III
Functional Duties/Responsibilities: Responsible for the initiation, scope planning (including decomposing work effort into work packages), resource assignment, team technical/schedule/cost delivery performance, monitoring and reporting, change management and project close for a defined Cyber project. Engages external clients and internal resources and management for all items related to the Cyber program. May provide Cyber and business insights and guidance to the delivery team to resolve complex challenges. Project Manager may be responsible for the oversight of multiple concurrent Cyber projects or programs.
Minimum Education: A Bachelor’s degree in Computer Science, Engineering, or Information Technology/Operations Management, or an equivalent technical degree. Master’s degree requires two (2) less years of minimum experience. Non-technical degrees must be supplemented by various technical Cyber certifications.
Minimum Experience Requirements: Technically-degreed individuals must have six (6) years of overall experiences which exhibit increasing levels of responsibility including four (4) years of Cyber-specific experience. Non-technically degreed individuals must have ten (10) years of Cyber-specific Project Manager experience.
Required/Supplemental Certifications: Multiple advanced technical Cyber certifications (e.g. CISSP, CISM, GSLC) required. Working knowledge of PMBOK required, Project Management Professional (PMP) preferred.
18 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
Title: Cyber Project Manager II
Functional Duties/Responsibilities: Responsible for the initiation, scope planning (including decomposing work effort into work packages), resource assignment, team technical/schedule/cost delivery performance, monitoring and reporting, change management and project close for a defined Cyber project. Engages external clients and internal resources and management for all items related to the Cyber program. May provide Cyber and business insights and guidance to the delivery team to resolve complex challenges. Project Manager may be responsible for the oversight of several concurrent Cyber projects or programs.
Minimum Education: A Bachelor’s degree in Computer Science, Engineering, or Information Technology/Operations Management, or an equivalent technical degree. Master’s degree requires two (2) less years of minimum experience. Non-technical degrees must be supplemented by various technical Cyber certifications.
Minimum Experience Requirements: Technically-degreed individuals must have four (4) years of overall experiences which exhibit increasing levels of responsibility including two (2) years of Cyber-specific Project Manager experience. Non-technically degreed individuals must have eight (8) years of Cyber-specific experience.
Required/Supplemental Certifications: An advanced technical Cyber certification required (e.g. CISSP, CISM, GSLC). Understanding of PMBOK required, Project Management Professional (PMP) desired.
Title: Emergency Cyber Engineer
Functional Duties/Responsibilities: Provide expert, on-demand emergency, triage or other immediate services to implement or remediate a broad range of Cyber-related technical issues including Vulnerability and Malware Analysis, System Security Hardening including Security Technical Implementation Guidelines (STIG) Digital Forensics and Incident Response (DFIR), as well as No-Notice Cyber Command Readiness Inspections (CCRI) on a strict timeline basis. Engages customer technical POCs as necessary to trouble-shoot issues and identify/implement resolutions.
Minimum Education: A Bachelor’s degree in Computer Science, Engineering, or Information Technology/Operations Management, or an equivalent technical degree. Master’s degree requires two (2) less years of minimum experience. Non-technical degrees must be supplemented by various technical Cyber certifications. An Associate degree must be supplemented by various technical Cyber certifications and two (2) additional years of experience beyond the Minimum Experience Requirements. The absence of a degree must be supplemented by various technical Cyber certifications and four (4) additional years of experience beyond the Minimum Experience Requirements.
Minimum Experience Requirements: Individuals must possess five (5) years of hands-on Cyber-specific experience.
19 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com
Required/Supplemental Certifications: One or more technical certifications such as DOD 8570 IAT Level I or technology-specific platforms (e.g. CISCO, VMWare, Microsoft, etc.) as necessary to perform the specific Cyber emergency task.
Title: Exploitation Engineer SME
Functional Duties/Responsibilities: Lead vulnerability scans and penetration testing (e.g. Network, Web Application, Wireless) in support of Red/Blue or interactive Purple Teaming and report remediation recommendations to proactively maintain the security posture of an enterprise or perform as an individual contributor on complex testing projects. Author Rules of Engagement. Additional responsibilities may include social engineering and physical assessments. Engages customer technical POCs as necessary throughout testing and reporting. May require providing guidance and oversight of other exploitation engineers.
Minimum Education: Master’s degree in Computer Science, Engineering, Information Technology or relative technical discipline. Non-technical degrees must be supplemented by various technical Cyber certifications. A Bachelor’s or Associate degree must be supplemented by various technical Cyber certifications and four (4) or two
(2) additional years of experience, respectively, beyond the Minimum Experience Requirements. The absence of a degree must be supplemented by various technical Cyber certifications and six (6) additional years of experience beyond the Minimum Experience Requirements.
Minimum Experience Requirements: Twelve (12) years of leading and performing information security-related engineering in areas such as: security operations, vulnerability management, security testing, system patching, log analysis, intrusion detection and security device technologies administration and incident analysis. Expert knowledge of Penetration Testing Execution Standard (PTES) and Open Web Application Security Project (OWASP) Frameworks and toolsets such as BurpSuite, NESSUS/ACAS, Kali Linux required. Custom scripting experience required. Advanced knowledge of one or more of the following compliance frameworks (RMF, PCI, HIPAA, IRS, CJIS).
Required/Supplemental Certifications: Multiple advanced Cyber certifications such as Certified Ethical Hacker (CEH), Licensed Penetration Tester (LPT), Offensive Security Certified Professional (OSCP), Offensive Certified Security Expert (OSCE), Offensive Certified Wireless Professional (OSWP), and other related credentials.
Title: Exploitation Engineer V
Functional Duties/Responsibilities: Lead vulnerability scans and penetration testing (e.g. Network, Web Application, Wireless) in support of Red/Blue or interactive Purple Teaming and report remediation recommendations to proactively maintain the security posture of an enterprise or perform as an individual contributor on complex testing projects. Author Rules of Engagement. Additional responsibilities may include social engineering and physical assessments. Engages customer technical POCs as necessary throughout testing and reporting. May require providing guidance and oversight of other exploitation engineers.
Minimum Education: Master’s degree in Computer Science, Engineering, Information Technology or relative technical discipline. Non-technical degrees must be supplemented by various technical Cyber certifications. A Bachelor’s or Associate degree must be supplemented by various technical Cyber certifications and four (4) or two
(2) additional years of experience, respectively beyond the Minimum Experience Requirements. The absence of a
20 | P a g e
Tel: 1-800-658-1846 | www.cyberdefensetechnologies.com degree must be supplemented by various technical Cyber certifications and six (6) additional years of experience beyond the Minimum Experience Requirements.
Minimum Experience Requirements: Ten (10) years of leading and performing information security-related engineering in areas such as: security operations, vulnerability management, security testing, system patching, log analysis, intrusion detection and security device technologies administration and incident analysis. Expert knowledge of Penetration Testing Execution Standard (PTES) and Open Web Application Security Project (OWASP) Frameworks and toolsets such as BurpSuite, NESSUS/ACAS, Kali Linux required. Custom scripting experience required.
Required/Supplemental Certifications: Multiple advanced Cyber certifications such as Certified Ethical Hacker (CEH), Licensed Penetration Tester (LPT), Offensive Security Certified Professional (OSCP), Offensive Certified Security Expert (OSCE), Offensive Certified Wireless Professional (OSWP), GIAC Security Essentials (GSEC), GIAC- Certified Intrusion Analyst (GCIA), GIAC-Certified Incident Handler (GCIH), Certified Information Systems Security Professional (CISSP), Security + and other related credentials.
Title: Exploitation Engineer IV
Functional Duties/Responsibilities: Lead vulnerability scans and penetration testing (e.g. Network, Web Application, Wireless) in support of Red/Blue or interactive Purple Teaming and report remediation recommendations to proactively maintain the security posture of an enterprise or perform as an individual contributor on complex testing projects. Author Rules of Engagement. Additional responsibilities may include social engineering and physical assessments. Engages customer technical POCs as necessary throughout testing and reporting. May require providing guidance and oversight of other exploitation engineers.
Minimum Education: Bachelor’s degree in Computer Science, Engineering, Information Technology or relative technical discipline. Non-technical degrees must be supplemented by various technical Cyber certifications. An Associate degree must be supplemented by various technical Cyber certifications and two (2) additional years of experience beyond the Minimum Experience Requirements. The absence of a degree must be supplemented by various technical Cyber certifications and four (4) additional years of experience beyond the Minimum Experience Requirements.
Minimum Experience Requirements: Eight (8) years of leading and performing information security-related engineering in areas such as: security operations, vulnerability management, security testing, system patching, log analysis, intrusion detection and security device technologies administration and incident analysis. Advanced knowledge of Penetration Testing Execution Standard (PTES) and Open Web Application Security Project (OWASP) Frameworks and toolsets such as BurpSuite, NESSUS/ACAS, Kali Linux required. Custom scripting experience required.
Required/Supplemental Certifications: Multiple Cyber certifications such as Certified Ethical Hacker (CEH), GIAC Security Essentials (GSEC), GIAC-Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), Certified Information Systems Security Professional (CISSP), Security + and other related credentials. Licensed Penetration Tester (LPT) or Offensive Security Certified Professional (OSCP) desired.
Title: Exploitation Engineer III
21 | P a g e
Functional Duties/Responsibilities: Perform or lead vulnerability scans and penetration testing (e.g. Network, Web Application, Wireless) in support of Red/Blue or interactive Purple Teaming and report remediation recommendations to proactively maintain the security posture of an enterprise. Additional responsibilities may include social engineering and physical assessments. Engages customer technical POCs as necessary throughout testing and reporting. May require providing guidance and oversight of other exploitation engineers.
Minimum Education: Bachelor’s degree in Computer Science, Engineering, Information Technology or relative technical discipline. Non-technical degrees must be supplemented by various technical Cyber certifications. An Associate degree must be supplemented by various technical Cyber certifications and two (2) additional years of experience beyond the Minimum Experience Requirements. The absence of a degree must be supplemented by various technical Cyber certifications and four (4) additional years of experience beyond the Minimum Experience Requirements.
Minimum Experience Requirements: Six (6) years of leading and performing information security-related engineering in areas such as: security operations, vulnerability management, security testing, system patching, log analysis, intrusion detection and security device technologies administration and incident analysis. Knowledge of Penetration Testing Execution Standard (PTES) and Open Web Application Security Project (OWASP) Frameworks and toolsets such as BurpSuite, NESSUS/ACAS, Kali Linux required. Custom scripting experience a plus.
Required/Supplemental Certifications: Multiple Cyber certifications such as Certified Ethical Hacker (CEH), GIAC Security Essentials (GSEC), GIAC-Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), Certified Information Systems Security Professional (CISSP), Security + and other related credentials.
Title: Exploitation Engineer II
Functional Duties/Responsibilities: Individually performs vulnerability scans and penetration testing (e.g.
Network, Web Application, Wireless) or in support of a Red/Blue or interactive Purple Teaming activity and report remediation recommendations to proactively maintain the security posture of an enterprise. Additional responsibilities may include social engineering and physical assessments. May engage customer technical POCs as necessary throughout testing and reporting. May require providing guidance and oversight of other exploitation engineers.
Minimum Education: Bachelor’s degree in Computer Science, Engineering, Information Technology or relative technical discipline. Non-technical degrees must be supplemented by various technical Cyber certifications. An Associate degree must be supplemented by various technical Cyber certifications and two (2) additional years of experience beyond the Minimum Experience Requirements. The absence of a degree must be supplemented by various technical Cyber certifications and four (4) additional years of experience beyond the Minimum Experience Requirements.
Minimum Experience Requirements: Four (4) years leading or performing information security-related engineering in areas such as: security operations, vulnerability management, security testing, system patching, log analysis, intrusion detection and security device technologies administration and incident analysis. Understanding of Penetration Testing Execution Standard (PTES) and Open Web Application Security Project (OWASP) Frameworks and toolsets such as BurpSuite, NESSUS/ACAS, Kali Linux required. Custom scripting experience a plus.
22 | P a g e
Required/Supplemental Certifications: A Cyber certification such as Certified Ethical Hacker (CEH), GIAC Security Essentials (GSEC), GIAC-Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), Certified Information Systems Security Professional (CISSP), Security + and other related credentials.
Title: Incident Responder IV
Functional Duties/Responsibilities: Lead teams or proactively and/or reactively individually receive unique and/or complex anomalous security incidents from security engineers and/or SOC analysts and follow appropriate handling and response procedures to analyze data, review system and device audit logs for unauthorized intrusions or activities, identify root causes sustained by artifacts, devise potential triage solutions and report recommendations to stakeholders to re-establish the security posture of a technology or enterprise. Lead complex trend analysis initiatives across the enterprise. Recommend Process Improvements and lead implementations. Engages customer technical POCs as necessary throughout Incident Response. May require providing guidance and oversight of other Incident Responders.
Minimum…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .