FY19-0460_JOFOC-GrammaTech.pdf

PDF 206 KB Posted

Attached to
STAMP Out: Improving Software Security with Open Source Static Analysis Tools Federal contract opportunity
Solicitation number
70RSAT19R00000039
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

Justification for Other Than Full and Open Competition (JOFOC)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

J&A Other Than Full and Open Competition J&A No.: FY19-0460

- 1 -

OPOAM 3006.301-90(a)(1) Justification &Approval (J&A)

Justification For Other Than Full And Open Competition 41 U.S.C. 3304

Pursuant to the requirements of the Competition in Contracting Act (CICA) as implemented by the Federal Acquisition Regulation (FAR) Subpart 6.3 and in accordance with the requirements of FAR 6.303-1, the justification for the use of the statutory authority under FAR Subpart 6.3 is justified by the following facts and rationale required under FAR 6.303-2 as follows:

1. Agency and Contracting Activity.

The Department of Homeland Security, Office of Procurement Operations, Science and Technology Acquistion Division, proposes to enter into a contract on a basis other than full and open competition.

2. Nature and/or description of the action being approved.

(a) Type of action: Cost Plus Fixed Fee

(b) Type of funding: Research and Development

(c) Year of funding: FY2019

(d) Other brief descriptive words and phrases:

DHS intends to procure on a sole source basis “STAMP Out: Improving Software Security with Open Source Static Analysis Tools” software assurance research and development services. GrammaTech is the only qualified source capable of providing these services.

GrammaTech, Inc.

531 Etsy Street Ithaca, NY 14850

3. Description of Supplies/Services. Describe the supplies or services to be acquired. Provide the estimated total value (including options, if any).

The requirement is to provide “STAMP Out: Improving Software Security with Open Source Static Analysis Tools” software assurance research and development services. The Static Tool Analysis Modernization Project (STAMP) project will modernize selected software analysis tools based on market research on key factors (e.g. market penetration, programming language)

- 2 -to improve tool performance and coverage, to seamlessly integrate and support continuous integration and DevOps operational environments, and provide more accurate analysis of results by reducing false-positives and provide more visibility into false-negatives that often leave residual risks. The tools will be selected by GrammaTech and approved by the S&T Technical Representative. STAMP is designed to create new techniques that advance the state-of-the-art capabilities found in software analysis tools and will help address the risks posed by the increasing use of software.

STAMP will improve the testing and evaluation of static analysis tools, with a focus towards improving deployment and understanding as well as expanding weakness coverage and strength of tools for use in the Software Assurance Marketplace (SWAMP). In addition, GrammaTech Inc. will develop and implement a repeatable methodology for testing, evaluation, and modernizing existing open-source static analysis tools.

GrammaTech will leverage its deep understanding and direct corporate experience to achieve benefits to the Government in the technical areas below:

Technical Understanding Area Resulting Benefit Current state of static analysis tools, including the shortcomings of the various tool vendors, the challenges facing software security implementers as they consider acquiring software assurance tools

Improved understanding for software assurance acquision decision makers, thus increasing adoption of software assurance tools

Software security life cycle and how it must be integrated into the software development work flow

Increases adoption of software assurance tools because the testing is integrated into existing work flows and doesn’t create additional steps for development teams

National Institute of Standards and Technology activities, specifically their Software Assurance Metrics And Tool Evaluation (SAMATE) program

Helps improving software assurance by contributing realistic test cases for software tool evaluations, a critical element for measuring the effectiveness of tools and techniques, and identifying gaps in tools and methods.

Developing a unified methodology for software assurance testing, including consideration of the following: test-case generation, target development languages and existing tools, assessment, tool development, evaluation, and deployment.

Helps ensure the deployment of holistic solutions rather than point solutions

The primary places of performance will be GrammaTech and certain Government facilities designated by DHS S&T.

- 3 -

4. Identification of statutory authority permitting other than full and open competition.

The statutory authority permitting other than full and open competition is 41 U.S.C.

3304(a)(1) pursuant to FAR 6.302-1, Only one responsible source and no other services will satisfy agency requirements.

5. Demonstration that the nature of the acquisition require use of the authority cited.

a. Background information about the requirement DHS is committed to using cutting-edge technologies and scientific talent in its quest to make America safer. The DHS S&T is tasked with researching and organizing the scientific, engineering, and technological resources of the United States and leveraging these existing resources into technological tools to help protect the homeland. One element of the DHS S&T R&D portfolio is Cyber Security research and more specifically, software assurance. The nation’s critical infrastructure (e.g., energy, transportation, financial services) and society are extensively, and increasingly, controlled by software. However, weaknesses in software expose vulnerabilities that put these critical infrastructure resources at risk. As of October 2017, the National Vulnerability Database (NVD) reported more than 12,000 vulnerabilities in the calendar year. That's nearly double the number reported in 2015 and 2016. This risk is compounded by software size and complexity and the growing reliance on reusable software code and open-source software in organizations.

The current state-of-the-art software assurance tools have not kept pace with modern software.

The complexity and size of software make it more difficult for software analysis tools to perform. Often these tools have difficulty tracking data flows through complex and large software systems, to the point that software analysis tools oversimplify and make assumptions about software code that is inaccurate.

The incorporation of GrammaTech’s research will help modernize Static Analysis software testing tools, thereby providing a much needed capability for organizations and developers to better secure their software. It will also help increase transparency of the software assurance market by providing a publicly available comparison tool that will enable acquisition decision makers to make informed decisions about the the best software assurance tool(s) for their environment.

b. Details covering what events lead to the situation requiring use of other than full and open competition procedures

DHS S&T originally awarded this research to GrammaTech via Interagency Agreements HSHQDC-16-X-00076 and 70RSAT18KPM000161 with the Department of Health and Human Services (HHS). DHS S&T funded GrammaTech through HHS assisted acquistion through the base period, Option Period 1 and through partial funding of Option Period 2. At the end of June 2019, HHS informed DHS S&T that they would no longer be providing assisted acquisiton services. This sole source award constitutes a continuation of the work being

- 4 -executed for the past two and a half years under HHSP23320160062C. The estimated cost of this sole source effort constitutes the remainder of the originally planned investment in the project.

c. Why considered alternatives will not work

While there are other firms that provide static analysis tools, the area of research being conducted by GrammaTech is unique because it seeks to help modernize multiple tools, commercial and open source, and develop improved products for use across the software development community.

Past experience is also a critical factor towards further achievements and completion of the required research efforts to be pursued under this project. It is essential to acquire the services of GrammaTech through a sole source award since they possess the unique and comprehensive knowledge of all Statement of Work requirements and have proven capable of successfully performing these services over the past two and a half years under HHS Contract No.

HHSP233201600062C. DHS will be able to capitalize on the previous contract achievements to take advantage of GrammaTech’s existing technologies and realize efficiencies, lower costs, and obtain the necessary tools under this project.

Consideration of alternatives does not represent a viable solution in the required timeline, due to the substantial investment to date, loss of research momentum during a period of solicitation, competition, and stand up time required by a new start and new award. GrammaTech had already undergone multiple reviews of their approach to arrive at the point of being the sole performer under STAMP. They were selected during the original Broad Agency Announcement (BAA) review process along with one other performer from a total of 5 offers.

DHS S&T had GrammaTech and the other performer execute their research through the base period and option period 1, and conducted a downselection in June 2018. The downselection process involved the following: Both perfomers had 1 hour to present their technical progress and proposed approach for the remainder of their project. A panel consisting of technical experts from DHS S&T, the National Instititue of Standards and Technology and the National Security Agency evaluated each for technical merit, management and proposed investment benefit of their work. Based on this review, GrammaTech was selected to proceed.

Commercial suppliers of software assurance tools are also not viable sources for these required R&D services because none of them are developing open source protocols to exchange information between different proprietary tools.

d. Which authority applies and why

OPO intends to procure on a non-competive basis the Static Analysis tools capability and research from GrammaTech pursuant to FAR 6.302-1 because GrammaTech’s unique approach represents the only viable approach, and based upon the level of expertise achieved in developing the capability, they are the only qualified source to perform these services.

- 5 -

e. Explain the impact to the mission that would result if the J&A is not approved and, consequently, the product or service not provided.

The DHS S&T software assurance R&D mission will be significantly impacted if the J&A is not approved. The software development community, and by extension, the DHS and critical infrastructure owners and operators who use that software, require more robust and modern software assurance testing tools to help ensure the software they deploy has a high level of assurance and that the software is free from critical vulnerabilities. They also require a comparison tool that will help guide their acquisition decisions.

To gain the required knowledge and skills to develop and mature the STAMP Project, the Government has made a substantial investment. It has taken nearly 3 years of research effort to develop the necessary highly skilled technical team and facilities required to perform and make significant contributions to rapidly advance this technology. If this J&A is not approved, organizations and developers will not receive a much needed capability to better secure their software. In addition, the software assurance market will still be without a necessary comparison tool to inform decisions about the best software assurance tool for the environment.

6. Description of efforts made to ensure that offers are solicited from as many potential sources as is practicable.

A FedBizOpps synopsis notice was publicized as required by FAR 5.2 on August 9, 2019. The intent of DHS is to add and make this justification publically available pursuant to FAR 6.305.

The sole source solicitation will be issued to GrammaTech following the synopsis posted for 15 days in FedBizOpps.

7. Determination by the contracting officer that the anticipated cost to the Government will be fair and reasonable.

The Contracting Officer has determined that the anticipated prices will be fair and reasonable based upon cost and price analyses of the cost proposal. The Contracting Officer will require submission of certified cost or pricing data for use in performing a cost analysis in accordance with FAR 15.404-1(c)(2) and a price analysis to determine that the overall price is fair and reasonable. A certificate of current cost or pricing data will be required for this award.

8. Description of market research.

Market research was conducted by reviewing the following sources: DHS acquisition history, other recent market research, surveying recent published papers and conference proceedings in the area of static analysis software assurance tools, interactions with other Federal agencies conducting research and development.

Market research verified that only GrammaTech has the capability to deliver the components of an improved software assurance ecosystem, namely: 1) automatically develop thousands of

- 6 -realistic test cases, 2) develop a scoring and benchmarking framework including mappings to NIST SP 800-53, and 3) develop consumer guidance for a range of tools (more than 70) to increase transparency of tool capabilities, thereby increasing adoption.

9. Any other facts supporting the use of other than full and open competition.

To gain the required knowledge and skills to develop and mature the STAMP capability, the Government has made a substantial capital investment,. It has taken nearly three years of research effort to develop the necessary highly skilled technical team and accompanying technologies to advance the state of the art in static analysis tools. To stand up and replicate this capability, if required by a new start full and open activity, would risk loss of both substantial intellectual and laboratory capital and require significant funds and time to be invested by the Government. Commercial suppliers of software assurance tools are also not viable sources for these required R&D services due to the significant complexity of this requirement; this research is covering on several aspects of the software assurance lifecycle and most vendors focus on a narrow element of the challenge.

10. A listing of the sources, if any that expressed, in writing, an interest in the acquisition.

A synopsis was issued in the FedBizOpps on August 9, 2019 requesting that parties express their interest in writing to the contracting officer. No other sources have responded to the FedBizOpps synopsis.

11. A statement of the actions, if any, the agency may take to remove or overcome any barriers to competition before any subsequent acquisition for supplies or services required.

Future software assurance services will be acquired under competitive vehicles such as the DHS S&T Long Range Broad Agency Announcement (LRBAA) 18-01 and, potentially, future Targeted Broad Agency Announcements.

File details come from the government source that posted it.