ProV_JA_Redacted.pdf

PDF 370 KB Posted

Attached to
ProVisioner (ProV) Enterprise Software License and Maintenance Federal contract opportunity
Solicitation number
621812725
Issued by
Defense Information Systems Agency

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JUSTIFICATION FOR OTHER THAN FULL AND

OPEN COMPETITION (OTFAOC)

Federal Acquisition Regulation (FAR) Part 6 Justification & Approval (J&A), Supporting Procurements under FAR Part 12 and FAR Part 15

Purchase Request Number: DSEMC80029 Contract Number: To be determined (TBD) Task/Delivery Order Number: TBD Procurement Title: ProVisioner (ProV) Enterprise Software License and Maintenance Statutory Authority: 10 U.S.C. 2304(c)(1)

JUSTIFICATION FOR OTHER THAN FULL AND OPEN COMPETITION (OTFAOC)

Justification for OTFAOC Number: JA18-117

Upon the basis of the following justification, I, as Procuring Activity Competition Advocate, hereby approve the use of other than full and open competition of the proposed contractual action pursuant to the authority of 10 U.S.C. 2304(c)(1) as implemented by FAR 6.302-1 , because the supplies or services required by the agency are available from only one responsible source and no other supplies or services will satisfy agency requirements.

1. REQUIRING AGENCY AND CONTRACTING OFFICE:

Requiring Agency:

Defense Information Systems Agency (DISA) Enterprise Directory Services (SE321) P.O. Box 549 Ft. Meade, MD 20755-0549

Contracting Office:

Defense Information Systems Agency (DISA) Defense Information Technology Contracting Organization (DITCO) National Capital Region (DITCO –NCR) / PL62 P.O. Box 549 Ft. Meade, MD 20755

2. NATURE / DESCRIPTION OF ACTION(S):

The purpose of this contract is to procure proprietary brand-name software licenses and supporting maintenance on a Firm-Fixed Price contract for ProVisioner (ProV) enterprise software to support the Program Management Office - Enterprise Directory Services (PMO-EDS)’ mission. ProV is a commercial off the shelf (COTS) enterprise software. The resultant contract will be funded with FY18 Operation and Maintenance (O&M) funds.

ProVisioner (ProV) Enterprise Software License and Maintenance-JA18-117

3. DESCRIPTION OF SUPPLIES / SERVICES:

PMO-EDS requires a ProV enterprise software license and supporting maintenance to run on the Windows Domain Controllers to authenticate end-users logging in to local networks. ProV enterprise software automatically adds, modifies and deactivates Active Directory accounts for smart card logon to a network based on the contents of users’ smart cards. ProV enterprise software allows organizations to provide automated access to their local IT resources for users with smart cards from civilian and defense organizations with their Personal Identity Verification (PIV) card or Common Access Card (CAC). Administrators will simply define ProV policies that assign temporary accounts based on the certificate data cryptographically validated from user smart cards at logon. The period of performance will be a 12-month base year, from date of contract award, and four (4) one-year options for license renewal and supporting ProV enterprise software maintenance.

4. IDENTIFICATION OF STATUTORY AUTHORITY:

Only one responsible source and no other supplies or services will satisfy agency requirements, 10 U.S.C.2304(c)(1) as implemented by FAR 6.302-1 and DFARS 206.302-1.

5. DEMONSTRATION OF CONTRACTOR’S UNIQUE QUALIFICATIONS:

Tangible Security, Inc. is the original manufacturer and only supplier of the ProV enterprise software license and its associated maintenance support, and no other COTS solutions assessed were able to meet the minimum Government requirements.

(a) Description of Events. ProV was originally developed as Department of Defense (DoD) –Visitor, a Government Off The Shelf (GOTS) software product, and then the Government relinquished all the rights over to the contractor, who then converted it to a Commercial Off The Shelf (COTS) product, reducing O&M costs by approximately 50% from the level of the original Service contract. Tangible Security, Inc. is the only contractor which has supplied this software in the current market.

The PMO-EDS Section (SE321) conducted market research during April 2018 to determine available commercial resources to satisfy the requirement for a Department of Defense (DOD) Public Key Infrastructure (PKI) enabled system able to provision accounts and provide a solution for Common Access Card (CAC) and / or Hardware Token users’ temporary access to NIPRNet and SIPRNet end-user devices.

While there were similar commercial tools available, only Tangible Security, Inc.’s ProV enterprise software could meet the Government requirement. Tangible Security, Inc can provide a DOD PKI enabled system able to provision accounts and provide a solution for

Common Access Card (CAC) and/or Hardware Token users’ temporary access to NIPRNet and SIPRNet end-user devices with a small footprint on the domain controller where it is installed. ProV enterprise software also met the minimum Government requirement to provide dynamic account provisioning controlled by Country of Citizenship, or other attributes contained within the CAC or PIV smart card logon messages and controlling who is allowed to be auto provisioned based on credentials provided in logon messages. ProV has the capability to provision accounts using already in place PKI enabled devices as well as the unique ability to allow the conversion of existing accounts dynamically between CAC email signing certificate UPN format to the PIV-AUTH ID Certificate UPN. This will be beneficial to local System Administrators as the DoD transitions away from the email signing certificate to PIV ID. Other COTS solutions assessed required the procurement of additional hardware and licensing by the component, and were dependent on the network size and number of users, creating a financial and staffing burden..

The ProV COTS enterprise software eliminates information technology (IT) operation staff-hours not only from Active Directory account tasks, but also from the people-centric workflows of helpdesk ticket creation, account change definition, and the multiple levels of the approval and fulfillment processes. Cyber security experts have been urging organizations to employ smart card logons for over a decade to better protect an organization’s data. Password reset help desk tickets are a constant drain on IT operations.

Despite the overwhelming superiority of a smart card logon, the difficulty of enabling them has deterred most federal organizations from implementing them. Tangible Security, Inc.

has administered, designed and engineered high-volume PKI, developing innovative tools to improve security, increase scalability and lower operational costs. From this experience, ProV enterprise software was designed by Tangible Security, Inc. to automate secure account creation and modification DOD-wide. With ProV enterprise software installed, errors associated with manual data entry and error correction for access to NIPRNet and SIPRNet end-user devices would be eliminated, a ProV enterprise software administrator would need only to define a number of simple rules that define the criteria for determining what users are issued what accounts. In other words, ProV creates prescribed accounts for users based upon a combination of cryptographically validated data fields found in their smart card. The ProV solution developed by Tangible Security, Inc. yields high security and scalability assurance and has low workflow costs.

ProV is a sole sourced COTS software produced by Tangible Security, Inc. and deployed to DISA's Software Forge for download and installation by any DoD Agency to support creation of temporary visitor accounts within Active Directory. DoD-Visitor/ProV software has been downloaded for installation more than 2,500 times in directory systems dispersed throughout Combatant Commands, Services and Agencies within DoD. If ProV licenses are not renewed, all existing versions of DoD-Visitor/ProV will become unsupported. Running unsupported software is a Security Technical Implementation Guide (STIG) finding that could place the Authority To Operate (ATO) of each system in jeopardy, until the software is removed. Assuming approximately one staff day of effort to remove DoD-Visitor/ProV from existing directories and replacing the software with another software product, if one were available that met all requirements, a minimum of

2500 staff days would be required to remove the unsupported software from DoD Networks.

The estimated cost for labor to remove and replace ProV is based on an average hourly rate of the Application Systems Analyst (Journeyman) labor category from the Alliant Contract Vehicle. The average hourly rate of $XXX multiplied by a standard eight hour work day multiplied by an estimated 2500 days results in an estimated labor cost to the Department of Defense components of approximately $XXX.

Additional resources would be required to train the system administrators on configuration and functionality of any replacement software. The estimated training costs are based on an average training course at Phoenix Training Center of $XXX per student with a minimum of two personnel requiring training in the new software for each of the 2500 directory systems resulting in an estimated training cost of $XXXX ($XXX x 2 personnel x 2500 directory systems). The training course assumes a 40 hour week. The estimated labor cost per personnel while in training is $XXXX ($XXX/hr x 40 hour week) multiplied by 2 personnel per each of the 2,500 directory system equates to $XXX.

Other products evaluated would need separate server platforms which would require that each of the DOD components procure and configure one or more servers on their network to support the capability, significantly increasing IT costs. Assuming the addition of two windows servers to each of the estimated 2500 directory systems currently using DoD-Visitor/ProV at a cost of $XXX/server, the cost would be $XXX. The basis for this assumption is to provide a pair of servers at a single location to allow for minimal redundancy and extrapolating to the number of time DoD-Visitor/ProV was downloaded. More complex directories, consisting of multiple locations would expand this estimate to account for at least 4 servers per directory, to accommodate local redundancy at each location, thereby increasing the required number of servers exponentially.

The total estimated cost for replacement of the ProV software throughout the Department of Defense is $XXX which consists of $XXX in labor to remove and replace ProV; $XXX in training courses for personnel on the ProV replacement software; $XXX in labor for training personnel on replacement software; and $XXX to procure and configure on networks.

(b) Justification:

(1) Minimum Government Requirements.

a. Provide a DOD PKI enabled system able to provision accounts and provide a solution for Common Access Card (CAC) and / or Hardware Token users’ temporary access to NIPRNet and SIPRNet end-user devices with a small footprint on the domain controller where it is installed.

b. Provide dynamic account provisioning controlled by Country of Citizenship, or other attributes contained within the CAC or PIV smart card logon messages.

Controlling who is allowed to be auto provisioned based on credentials provided in logon messages ProV has the capability to provision accounts using already in place PKI enabled devices as well as the unique ability to allow the conversion of existing accounts dynamically between CAC email signing certificate UPN format to the PIV-AUTH ID Certificate UPN.

(2) Proposed Sole Source Contractor. Tangible Security, Inc.

ProV was originally developed as DoD – Visitor, a Government Off The Shelf (GOTS) software product, and then the Government relinquished all the rights over to the contractor, who then converted it to a Commercial Off The Shelf (COTS) product, reducing O&M costs by approximately 50% from the level of the original Service contract. Tangible is the only contractor that has supplied this software in the current market. No other COTS product assessed could meet the minimum Government requirements in addition to yielding higher assurance and scalability than the other options at a much lower operational cost. ProV enterprise software and its associated maintenance is proprietary to Tangible Security, Inc. and there are no authorized resellers. Tangible Security, Inc. is the only supplier that can provide the enterprise software and its associated maintenance support.

(3) Discussion regarding cause of the sole source situation. ProV was previously acquired under existing contract number HC1047-14-P-0157 from Tangible Security, Inc. This requirement is a continuation of the previous effort. Tangible Security, Inc. has the only known enterprise software (ProV) that can meet all the capabilities needed to fulfill the Government requirement. Tangible Security, Inc does not license out their product to other vendors, has sole ownership of the software code, and the ProV enterprise software and its associated maintenance is proprietary to Tangible Security, Inc.

(4) Impact. Failure to acquire ProV enterprise software and its associated maintenance support would result in implementation delays by DOD components and extensive delays while transitioning from ProV to another COTS product. Furthermore, removal of the existing ProV software from existing server enclaves would require additional man-hours and system downtime, which could compromise network integrity and increase the cost.

6. FEDBIZOPPS ANNOUNCEMENT / POTENTIAL SOURCES:

ProV COTS enterprise software is proprietary to Tangible Security, Inc. and there are no authorized resellers. A combined synopsis/solicitation for commercial items/services in accordance with FAR 12.6 and the redacted J&A will be published on FedBizOpps.

7. DETERMINATION OF FAIR AND REASONABLE COST:

The Contracting Officer will make a determination that the anticipated cost for this acquisition is fair and reasonable using the quote received from the contractor in comparison to the Independent Government Cost Estimate (IGCE) and other market research data obtained from similar procurements of comparable licenses and maintenance.

8. MARKET RESEARCH:

The PMO-EDS Section (SE321) conducted extensive market research during April 2018 to determine available commercial resources to satisfy PMO requirements for a solution for Common Access Card (CAC) and / or Hardware Token temporary access to NIPRNet and SIPRNet end-user devices. Market research was performed utilizing the Google search engine, GSA, and NASA SEWP vehicles. In addition, the PMO searched the Small Business Dynamic Database Search engine using the subject word Pro V.. While there are no Commercial off the Shelf products that match the capabilities of the ProV product, some tools reviewed did provid limited auto provisioning. Four other solutions were assessed during market research. Quest, Manage Engine’s ADManager Plus, Centrify’s Lifecycle Management / Identity Services and the AD-Pro Active Directory Authentication v3.5 from Glanton Solutions. During the assessment of these auto-provisioning tools, the PMO found that none provided the complete set of technical features and requirements the Government needs.

Based on these findings and the market research performed, ProV is the only Information Assurance approved solution that can meet the Government’s needs. Market research found Tangible Security, Inc. was the only authorized reseller. ProV is the only COTS enterprise software available that allows a user with a valid CAC and / or Hardware Token temporary access to NIPRNet / SIPRNet end-user devices when they are away from their home domain. No other COTS solution assessed was found that could provide the capabilities the Government requires.

9. ANY OTHER SUPPORTING FACTS:

None

10. LISTING OF INTERESTED SOURCES:

The source for the ProV COTS solution is:

Tangible Security, Inc.

2010 Corporate Ridge, Suite 250 McLean, VA 22102 Email: info@TangibleSecurity.com Phone: 800-913-9901

11. ACTIONS THE AGENCY MAY TAKE TO REMOVE OR OVERCOME BARRIERS

THAT LED TO THE EXCEPTION TO FULL AND OPEN COMPETITION.

(a) Procurement History.

(1) Contract Number: HC1047-14-P-0157, September 15, 2014 – September 14, 2018

(2) Sole Source

(3) Total Small Business Set-Aside

(b) If other enterprise software becomes available that meets the minimum Government requirements, those products or solutions will be considered for future requirements Technologies or solutions that meet the requirement to provide a DOD PKI enabled systems to provision accounts and provide a solution for Common Access Card (CAC) and / or Hardware Token users’ temporary access to NIPRNet and SIPRNet.

(c) Prior to HC1047-14-P-0157, no other award was accomplished without the need for other than a full and open competition justification because it was a GOTS requirement.

12. REFERENCE TO THE APPROVED ACQUISITION PLAN (AP):

In accordance with the exceptions under DISA Acquisition Regulation Supplement 7.103 Table 7-1, an AP is not required.

ARNOLD.GAY.

D.1230359101

Digitally signed by

ARNOLD.GAY.D.1230359101

Date: 2018.08.07 11:38:23 -05'00'

File details come from the government source that posted it.