DHS TRP Pre-Proposal Conference - QA - Final 02-22-2022.pdf
PDF 167 KB Posted
- Attached to
- DHS HSPD-12 IDMS Technology Refresh Project Federal contract opportunity
- Solicitation number
- 70RDAD22R00000001
About this file
This document outlines requirements for an Identity Enrollment System and Credential Management System solution for the Department of Homeland Security's Identity Management System Technology Refresh Project. Key requirements include supporting identity enrollment and issuance of credentials for over 2 million identities and 1.5 million credentials, with scalability to grow over time. The solution must integrate with existing DHS systems using open standards like RESTful APIs and support identity capabilities such as offline enrollment, multi-modal biometrics collection including fingerprints, photos and iris scans, and credential management for smart cards, physical and logical access. Offerors must demonstrate how their commercial off-the-shelf solution meets these requirements through an in-person oral presentation and demonstration with no more than five speakers. The contract type will be an Indefinite Delivery Indefinite Quantity agreement awarded after full and open competition to the responsible offeror providing the best value to the government.
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DHS TRP Pre-Proposal Conference - Questions and Answers
Question
Category Question/Topic Answers
1 Evaluation Does the Government intend that part of the evaluation includes a prototype demonstration?
Entire presentation will be no more than 2 hours. Schedule will be provided promptly after Phase 3 written submissions are due.
Demonstration must be live and in person. Not virtual nor pre-recorded.
2 Evaluation In an effort to gain a thorough understanding of each offerors technical capabilities, it is our experience that in person demonstrations give government the best capability of evaluating demonstrations. We would recommned inperson demonstrations would government be open to that approach
Presentation / Demonstrations will be rquired in person. Not virtual nor pre-recorded.
3 Evaluation Does the Government intend that part of the evaluation includes a prototype demonstration?
DHS seeks COTS that currently exists. DHS seeks to avoid prototypes and future development roadmap of COTS solutions for this solicitation. Future roadmap will be important as part of vendor innovation and delivery of market anticipated future capabilities.
4 Procurement 3.9 CONTRACT REQUIREMENTS, page Draft RFP page 42 of 78 - Please clarify the purpose of this section?
This is the list of use cases offerors need to demonstrate.
5 Procurement 3.9 CONTRACT REQUIREMENTS, page Draft RFP page 42 of 78 - We would appreciate clarification on what 'demonstrate' means as used in this section.
Demonstration must show DHS how the solution meets DHS requirements. Essentially answering: "How would DHS do this using our solution?"
6 Procurement 3.9 CONTRACT REQUIREMENTS, page Draft RFP page 42 of 78 - How will the Use Cases in this section be demonstrated?
Through the written responses to the RFP.
7 Procurement Will the Government provide an inventory of the Government
Furnished Equipment in use on the current contract?
The HW peripherals list and inventory will be posted with the final RFP. All equipment is in GOOD condition, fully functional and functions as intended, and currently under a maintenance agreement
8 Procurement Does the Government have a complete inventory of the equipment in the inventory tracking system?
DHS maintains a complete inventory of equipment in the
Government's asset management system.
DHS Technology Refresh Project Pre-Proposal Conference Q&As
9 Procurement Question: Please confirm company and personnel security requirements for the contact. Recommend Offerors be required to hold a Top Secret Facility Clearance (FCL) in order to ensure
DHS system development and access security requirements are addressed.
DHS does require the vendor to be able to hold clearances for their personnel. This does require a Top Secret Facility
Clearance.
10 Procurement Section 3.11.8 Operating Environment states that the offeror shall provide a solution where all servers run in a virtual machine environment, and shall provide support for DHS selected systems: Government Furnished Equipment (GFE) hardware, Government Cloud Service providers (i.e., IaaS, PaaS). What is the government's selected cloud environment?
The VM environments are already owned by the Government.
DHS uses the Microsoft Azure platform hosted by DHS CIO called "Cirrus". It is a FIPS 199 H-H-H platform with DHS specific security requirements met. DEV, Pre-PROD and PROD are already defined and available.
It is the goverments desire that the vendor's technical services will be available to engage with DHS administrators to install their COTS offering.
The government is asking COTS solutions to be installed and hosted within Cirrus IaaS or Cirrus PaaS. The bidder is not being asked to provide hosting recommendations.
11 Procurement Section 3.11.7 Change Control 1. states that the offeror shall provide the government all installation binaries and
Government Off The Shelf (GOTS) source code (“glue code”) developed to support integration within the DHS environment
(i.e., for the system and associated dependencies). What is the government's approved source code repository?
DHS CIO provides Bamboo and Bitbucket for source code control. DHS will collaborate with the awardee on a solution for configuration management and source code control.
12 Procurement Section 3.12 IDENTITY ENROLLMENT SERVICES specifies the requirements for Identity enrollment. Section 3.12.2 Mobile
Enrollment specifies the requirement for Mobile Enrollment.
Does the government intend that the Mobile Enrollment also enable Supervised Remote Identity Proofing for all NIST defined Identity Assurance levels (IA1, IA2, IA3)?
Mobile Enrollment can be either fixed station or SRIP.
13 Procurement Section 3.12 IDENTITY ENROLLMENT SERVICES specifies the requirements for Identity enrollment. Section 3.12.2 Mobile
Enrollment specifies the requirement for Mobile Enrollment.
Does the government intend that the Mobile Enrollment capability also include Mobile Issuance?
Mobile Enrollment is not required to support issuance. The
CMS is required to use the SRIP environment for issuance. This may apply to a Mobile Enrollment scenarios, enabling issuance.
DHS requires use of COTS GFE computers for issuance workstations. It is a DHS logistics decision to determine the type of computer (e.g., desktop or harsh environment hardened), and an issuance workstation may be deployed in a mobile environment.
14 Procurement Section 3.12 IDENTITY ENROLLMENT SERVICES specifies the requirements for Identity enrollment. Section 3.12.2 Mobile
Enrollment specifies the requirement for Mobile Enrollment.
Does the government intend that the Mobile Enrollment capability be available in disconnected or low bandwidth environments?
The Mobile Enrollment capability needs to be available in both the disconnected and low bandwidth environments.
15 Procurement Section 3.12.5 Biometric Data Capture states that the offeror shall provide multi-modal biometric capture as required by
DHS. Minimally, this includes: a. Ten flats for fingerprint capture with quality scoring in accordance with NIST
Fingerprint Image Quality (NFIQ) v1.0, ISO/IEC 29794-4
(NFIQ v2.0), and FBI Electronic Biometric Transmission
Specification (EBTS) b. Facial image capture in accordance with NIST SP 800-76-2 c. Iris image capture in accordance with
NIST SP 800-76-2. What is the government’s current collection, storage and use of Iris Image biometrics?
DHS does not have iris capability today and seeks to change that through this procurement.
16 Procurement Section 3.12.10 Video Management System (VMS) states that the offeror’s solution shall provide a VMS to store recordings of all enrollment sessions; the solution shall provide support for attended lifecycle activities by Issuance Officials; and that the solution shall store video recordings in accordance with DHS policy for records retention and audit purposes. Please provide the governments policy and requirements for storage of video recordings.
DHS will manage the VMS. The VMS is anticipated to be a
COTS software solution provided as part of the Enrollment
System.
The VMS is meant to store all enrollments that are processed through the Enrollment System SRIP solution.
The VMS is anticipated to be collocated with the Enrollment
Server. Records retention policy is being developed, but anticipated to be no less than seven years.
17 Scope In section 3.9 CONTRACT REQUIREMENTS sections a.-i, Is this a list of use cases offerors should demonstrate in the oral presentation/demonstration or has the government determined a subset of these requirements to be shown.
See Final RFP.
18 Technical 3.2 OBJECTIVE, page 37 of 78 - Regarding DHS’s objective on the acquisition and timely deployment of COTS HW
(enrollment and issuance peripherals), will the government provide a list of existing equipment to be supported?
The HW peripherals list and inventory will be posted with the final RFP. All equipment is in GOOD condition, fully functional and functions as intended, and currently under a maintenance agreement
19 Technical 3.6 TECHNICAL ARCHITECTURE, pages 39 and 40 of 78 -
Regarding the Interface Control Documents (ICD), will the government provide the ICD and/or similar documentation for the interfaces applicable to the new solution?
ICDs will be provided post-award.
20 Technical 3.7 IDENTITY ENROLLMENT SERVICES, page 41 of 78, Regarding future offline enrollment capability, for how long does the government assume the offline capability will last/endure? Also, could the government confirm if batch upload is to be utilized upon re-connection to the network?
In disaster operations, where we anticipate this requirement, the process is to gather up all offline enrollments within a 24 hour period, get to a networked site, transmit the enrollments, clear the enrollments from the offline workstations.
21 Technical 3.10.2 Identity Enrollment Innovation, pages 44 and 45 of 78 -
Regarding off-line enrollment, does it also need to issue certificates?
Enrollment does not perform issuance nor issuance of certificates.
22 Technical 3.10.3 Credential Management Innovation, page 45 of 78 -
Regarding credential management functionality to support the
Internet of Things (IoT), are there specific classes of IoT devices that the government considers a priority?
The priority for Non-Person-Entity IoT devices that connect to
DHS networks is to be determined.
23 Technical 3.11.8 Operating Environment, page 47 of 78 - Regarding running the new solution in a virtual machine (VM) environment installed at DHS, does DHS expect the new
IDMS solution will be implemented and operated in a VM environment already owned and operated by/for DHS, or does DHS wish bidders to include cloud hosting services in their proposals?
If DHS expects the new IDMS solution will be implemented and operated in a VM environment already owned and operated by/for DHS, does DHS wish bidders to provide technical requirements for environments to support the new
IDMS solution, to include multiple development and test environments in addition to production?
Also, if the new solution is to be implemented in a VM environment already owned and operated by/for DHS, please advise whether it would expect the successfull bidder to engage with the current VM infrastructure support team, i.e., database administrators, server administrators, etc., in connection with software installation and server and database configuration, including applying upgrade and bug fix patches, etc. for the new solution?
Alternatively, if DHS wishes bidders to include cloud hosting services in their responses, is it DHS’s expectation that the entirety of the identity enrollment and credentialing
The VM environments are already owned by the Government.
DHS uses the Microsoft Azure platform hosted by DHS CIO called "Cirrus". It is a FIPS 199 H-H-H platform with DHS specific security requirements met. DEV, Pre-PROD and PROD are already defined and available.
It is the goverments desire that the vendor's technical services will be available to engage with DHS administrators to install their COTS offering.
The government is asking COTS solutions to be installed and hosted within Cirrus IaaS or Cirrus PaaS. The bidder is not being asked to provide hosting recommendations.
24 Technical 3.11.8 Operating Environment, page 47 of 78 - Regarding maximizing reuse of existing peripherals, could the government provide a list of existing Government Furnished
Equipment (GFE) and its condition to support bidders' assessment of the level of re-use that can be provided?
The HW peripherals list and inventory will be posted with the final RFP. All equipment is in GOOD condition, fully functional and functions as intended, and currently under a maintenance agreement
25 Technical 3.11.9 Communications, page 47 of 78 - Regarding DHS approved encrypted and unencrypted protocols and TCP/IP port numbers over DHS networks, could the government provide a list of DHS approved encrypted and unencrypted protocols and TCP/IP port numbers?
Please refer to the General RTM. The Requirements Traceability
Matrix (TRM) will be posted with the final RFP.
26 Technical 3.11.10 Cryptography, PKI and Security, pages 47 and 48 of 78 -
Regarding bullet #11, could the government confirm that the requirement for manufacturing in the United States applies only to cryptographic modules and their client software?
The requirement applies primarily to Hardware Security
Modules, but all cryptographic modules (e.g., TLS, SSL, full disk encryption) should be from United States sources .
27 Technical 3.11.12 Scalability, page 48 of 78 - Regarding the DHS metrics for scalability, does the delta (500,000) between the number of identities (2,000,000) and the number of credentials
(1,500,000) represent inactive card holders that are still being tracked in the new solution?
DHS has identities that are no longer active and do not hold credentials. This requirement is for scalability of the solution to manage all DHS identities and their credentials.
28 Technical 3.12.1 Identity Enrollment, pages 49 and 50 of 78 - Regarding the enrollment workstation and server NOT storing enrollment data after an enrollment is submitted (bullet #8), in Section 3.7
Identity Enrollment Services, it’s noted in 3.7.1 that a future offline enrollment capability is sought. Should there be a disconnect of the enrollment stations to the enrollment server, or enrollment server to the EDS, all enrollment data would be lost. Does DHS desire to store enrollment data locally, short-term, to support re-sending the enrollment data when network connectivity is re-established or should the enrollment fail and need to be completed again?
No data is cached at the Enrollment Workstation. If network connectivity is lost and not resumed promptly between the
Enrollment Workstation and the Enrollment Server, then the solution shall re-start the full enrollment process. Delivery services from the Enrollment Server to the eIDMS are expected to have failure management and re-try capabilities.
29 Technical 3.13.1 Credential Issuance/Management, pages 51 and 52 of 78
- Regarding bullet #4, which official smart card versions and app versions (from the vendors) are currently being used?
Also, will issued cards data, including card management keys (e.g., Global Platform and 9B), be available for ongoing management of existing issued cards?
The CMS will manage cards it issues only. The CMS will not manage cards issued by the current infrastructure. DHS owns all issuance keys for all card platforms. Appropriate keying material will be made available after award.
30 Technical 3.13.1 Credential Issuance/Management, pages 51 and 52 of 78
- Regarding bullet #5, will the government provide information on future DHS Batch Approval Process (BAP) specifications for new vendors or cards using Global
Platform management technology prior to the solicitation release?
Future BAPs will be developed in collaboration with the awarded CMS vendor. Global Platform is required.
31 Technical HSAR Class Deviation 15-01 (e), pages 26, 27, and 28 of 78 -
The solicitation requires the bidder to hire an independent third party to validate the security and privacy controls against
FISMA. There are a number of related ATO and privacy assessment activities that are mandated to occur every third year as ongoing support. Does DHS anticipate the third party assessment to be needed every third year as well?
DHS anticipates a need for an independent third party assessment every third year.
32 Technical 3.9 CONTRACT REQUIREMENTS, page 43 of 78 - Regarding demonstrating crypto agility, is a demonstration of switching algorithms between the various ones defined in table 3-1 of
NIST 800-78-4 sufficient to demonstrate the crypto agility of the CMS?
Demonstrating switching algorithms will not be sufficient. It is a part of crypto agility and it includes managing TLS, SSL, card platform, and all cryptographic modules.
33 Technical Section 3.11.7 Change Control, pages 46 and 47 of 78 -
Regarding the provision of a DHS approved method, could
DHS specify the governing regulation or policy?
All vendors shall follow the DHS Sensitive Systems Policy
Directive
34 Technical Section 3.11.8 Operating Environment, page 47 of 78 - What level of support is required over the solutions in these subsections?
DHS will provide Tier 1 support, with some Tier 2 support. The vendor is expected to collaborate with DHS on Tier 2 and is required to provide Tier 3 support.
35 Technical Section 3.11.8 Operating Environment, page 47 of 78 -
Regarding operational availability metric, could DHS confirm if this is an operations and maintenance requirement?
Scheduled outages are not part of the 99.95% operational availablity requirement.
36 Technical Section 3.11.10 Cryptography, PKI, and Security, page 47 of 78 -
Regarding data encryption, what are the DHS 4300A, DHS
Sensitive Systems , requirements for symmetric algorithms?
DHS 4300A mandates systems requiring encryption use the
AES-256 method.
37 Technical Section 3.11.10 Cryptography, PKI, and Security, page 48 of 78 -
Regarding configurable administration, could DHS specify the type of alert and to whom it should be sent? Could DHS also specify whether the activity logging is to be push or pull?
DHS anticipates use of email and SMS for alerts, or any other innovative means provided by the vendor. DHS seeks full configurability of events and who is notified, and how they choose to be notified.
38 Technical Section 3.11.13 Training and Documentation, pages 48 and 49 of 78 - Regarding training, what is the frequency, location, and medium of the instructor-led and train-the-trainer training?
DHS seeks vendor recommendations based on vendor experience with similar sized solutions to the DHS environment.
DHS will provide training locations post-award.
39 Technical Section 3.12.5 Biometric Data Capture, pages 50 and 51 of 78 -
Regarding multi-model biometric capture, what are the additional modalities that DHS may request?
DHS seeks fingerprint, facial image, and iris image, as the known modalities, to support current operational needs. There may be additional modalities defined in the future.
40 Technical Section 3.12.10 Video Management System (VMS), page 51 of
78 - Regarding a Video Management System (VMS), could
DHS confirm whether the bidder is responsible for managing the VMS?
Could DHS confirm whether the VMS is meant to store enrollment sessions from all of the enrollment locations?
Could DHS specify where the enrollment session data would need to be stored and what is the record retention policy?
DHS will manage the VMS. The VMS is anticipated to be a
COTS software solution provided as part of the Enrollment
System.
The VMS is meant to store all enrollments that are processed through the Enrollment System SRIP solution.
The VMS is anticipated to be collocated with the Enrollment
Server. Records retention policy is being developed, but anticipated to be no less than seven years.
41 Technical Section 3.13.4 Alt-Cred, page 53 of 78 - Regarding credential management for high-side credentials, could DHS confirm whether this would require separate hardware connected to
SIPRNET?
Managing high-side credentials may require a separate hardware connection to a high-side network hosting the high-side credential management solution. Potential solution may have to support multiple fabrics of classification.
42 Technical Section 3.13.1 Credential Issuance / Management, page 51 and
52 of 78 - Regarding the requirement to manage DHS's existing porfolio of issued smart card credentials, please describe what this management activity will entail.
The CMS will manage cards it issues only. The CMS will not manage cards issued by the current infrastructure. DHS owns all issuance keys for all card platforms. Appropriate keying material will be made available after award.
43 Technical HSAR Class Deviation 15-01 (e), pages 26, 27, and 28 of 78 -
The document defines a long term obligation of the initial integration and configuration awardee to keep the ATO and privacy certifications current for a period of up to 10 years. If a separate award is made for O&M to a separate entity, could
DHS specify how the awardee is expected to maintain the
ATO and privacy certifications?
DHS is acquiring COTS software solutions for IES and CMS.
The awardee shall support DHS in any O&M activity required to maintain ATO using the awardee's COTS software solution.
44 Technical Can the governement speak to hardware enrollment peripherals.
Is there a requirement to reuse what you already have? Do you want new peripherals? Can DHS provide a list of what you currently have and which ones you require to be re-used?
The HW peripherals list and inventory will be posted with the final RFP. All equipment is in GOOD condition, fully functional and functions as intended, and currently under a maintenance agreement
45 Technical Will systems developed or COTS obtained be required to be on any specific system such as on-premises or are cloud systems
(IaaS, PaaS, SaaS) applicable? If cloud (IaaS, PaaS, SaaS) is acceptable, is there any restriction on cloud providers?
The VM environments are already owned by the Government.
DHS uses the Microsoft Azure platform hosted by DHS CIO called "Cirrus". It is a FIPS 199 H-H-H platform with DHS specific security requirements met. DEV, Pre-PROD and PROD are already defined and available.46 Technical While systems to interface include ICDs, can you provide context to Authentication methods, return types, and what protocols are used in communications between systems? IE:
There is mention of RESTFul interfaces, are these using standard Authentication headers? Are the responses in JSON?
DHS seeks to use RESTful webservices and open standards wherever possible. Each ICD defines the interface that is supported by the system we connect to. Not all of them have developed RESTful webservices and they use alternate means of communication. Some of them use SOAP, SMTP, XML, JSON, delimited data files. DHS requires use of DHS CA4 certificates for authentication where supported by the system we connect to.
47 Technical For reporting purposes, (operationally vs data lake) what is the likely storage size of information within the system? If not known, an estimate of registered/enrolled users is sufficient.
DHS has identities that are no longer active and do not hold credentials. This requirement is for scalability of the solution to manage all DHS identities and their credentials.
48 Topic of
Discussion
Please discuss the requirements of the Orals and Demonstration See Final RFP.
49 Topic of
Discussion
Oral Presentation/Demonstration - What is the duration of the orals, and how will that duration be broken out between demonstration and Q&A
See Final RFP.
50 Topic of
Discussion
How will the contractors approach to transition be evaluated and under which factors will it be evaluated.
Tranistion will be evaluated as part of Factor 2, Past
Performance
51 Topic of
Discussion
During Orals, government has stated only 5 people are able to have spoeaking roles. Does this preclude additional staff performing non speaking tasks during the demonstration
Due to the risk of COVID exposure, the vendor is limited to only 5 people in order to maintain safety for all parties involved.
File details come from the government source that posted it. Updated .