Amendment 0001_RFP 70RTAC22R00000010_Responses to Vendor Questions on Final RFP.pdf
PDF 377 KB Posted
- Attached to
- Solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Federal contract opportunity
- Solicitation number
- 70RTAC22R00000010
About this file
This document contains responses to vendor questions on a final solicitation for crowdsourced vulnerability assessment services. The solicitation seeks a contractor to operate a vulnerability discovery and disclosure platform to conduct security assessments of Department of Homeland Security systems. The contract will be available government-wide and task orders may be set aside for small businesses. Proposals are due by June 27, 2022 for phase one and July 14, 2022 for phase two. The contractor must own and operate an active researcher community and platform, conduct pre-assessment checks of researchers, and provide final reports on findings and recommendations. Continuous engagement reports are due annually. Only the prime contractor may utilize a subcontractor's platform for the work.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 0001_RFP 70RTAC22R00000010_J.2 - PWS.pdf | ||
| Amendment 0001_RFP 70RTAC22R00000010_SF30.pdf | ||
| Amendment 0001_RFP 70RTAC22R00000010.pdf | ||
| RFP 70RTAC22R00000010.pdf | ||
| RFP 70RTAC22R00000010 J.1 - SF1449.pdf | ||
| RFP 70RTAC22R00000010 J.2 - PWS.pdf | ||
| RFP 70RTAC22R00000010 J.7 - Pricing Template.xlsx | XLSX spreadsheet | |
| RFP 70RTAC22R00000010 J.3 - Cert of IDIQ VDDP Platform Compliance.pdf | ||
| RFP 70RTAC22R00000010 J.5 - Cert of HSAR 3052.204-70 and Data Req.pdf | ||
| Responses to Vendor Questions on DRAFT RFP.pdf | ||
| RFP 70RTAC22R00000010 J.6 - Past Performance Questionnaire.pdf | ||
| RFP 70RTAC22R00000010 J.4 - Cert of Active Researcher Community.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP 70RTAC22R00000010_0001 Responses to Vendor Questions on RFP
Question No.
Reference RFP Section
Paragraph No.
Page No.(s)
Question Response
1 B6 8 - 9 Will this contract be available for all of DHS or just DHS HQ? This contract is a DHS-wide contract, which will be available for all of DHS.
2 B6 8 - 9
"Competition will be promoted to the maximum extent practicable through full and open competition. The Government reserves the right, however, to reserve up to three (3) of the four (4) IDIQ awards for small business concerns under FAR 52.219-31 Notice of Small Business Reserve and FAR 52.219-32, Orders Issued Directly Under Small Business Reserves. If the Government exercises this right, then the following guidelines will apply to establishing the small business reserve: "
Will the government give priority to small vs. large businesses for the task orders?
In accordance with RFP G.2 (3), the Task Order CO will provide a fair opportunity to each IDIQ contract awardees to be considered for all task orders exceeding the micro-purchase threshold, except as provided in FAR Parts 16.505(b)(1)(i)(B) and 16.505(b)(2).
Orders under this IDIQ contract may be set-aside for exclusive competitive pariticpation by small business concerns at the discretion of the Task Order Contracting Officer.
Responses to Vendor Questions on Draft RFP
Response #15 3
"In order to maintain maximum flexibility on the range of scope given the sensitivity of assets, the task orders will detail the appropriate safeguards required based on the sensitivity of assets in scope for a given event."
Does the government have an estimation of the number of events/CLINS by security type? Example - FedRAMP Low, Moderate or High?
We do not have an estimate at this time.
J.2 Performance Work Statement (PWS), Vulnerability Discovery and Disclosure Platform
3 6
"At a minimum, DHS requires the contractor to possess the ability to continuously monitor individual researcher activity for the duration of the live-assessment, and the ability to audit researcher activity post-assessment "
Does DHS require insight into testing on ALL assessments or only on private, sensitive assessments? No vendor can provide 100% assurance that publicly accessible assets will be engaged with by researchers in a monitored manner.
We acknowledge the limitation here would be for bounty events which require researchers to use a vendor controlled VPN or proxy and the intent is for the vendor to be able to monitor actions that pass through that system. We acknowledge that for events which do not require the use of a VPN or proxy, that monitoring would be impossible. We also acknowledge that publicly available DHS systems may be accessed by researchers outside of a VPN or proxy, but would prefer vendor best-effort to enforce VPN usage via Rules of Engagement (ROE) and written policy. The PWS has been updated.
J.2 PWS, 2.1 TASK
ONE. Pre-Assessment
2.1.2 7
"The contractor must be willing to provide proof of completion of these checks for each researcher if requested by the government ."
What constitutes adequate proof of a background check?
Records of an invoice to the vendor from the company used to conduct the check.
RFP 70RTAC22R00000010_0001 Responses to Vendor Questions on RFP
J.2 PWS, 2.1 TASK
ONE. Pre-Assessment
2.2.4 8
"Integrate appropriate controls over researcher traffic, include a secure portal for full packet capture capabilities to enable auditability and continuous monitoring of researcher activities. "
Does DHS require insight into testing on ALL assessments or only on private, sensitive assets? No vendor can provide 100% assurance that publicly accessible assets will be engaged with by researchers in a monitored manner.
See Response to Question #4.
J.2, PWS, 2.1 TASK
ONE. Pre-Assessment
2.3.3 9
"Write a final report which shall include:
• An executive summary of findings;
• Impact of the findings to the DHS mission for the in-scope system(s);
• Conclusions based on the contractor’s experience with DHS bounties as well as its own public and private sector bounties to provide recommendations for remediation, technical strategies to better secure the system, and best practices from industry; and
• Lessons learned from the bounty. "
Does this final report requirement apply to continuous (12 month) bounty engagements? If so, at what interval is a report required?
Yes and the report would be due once at the end of the continuous engagement.
8 General Question
Is it allowed for prime contractor to use subcontractor’s platform to provide CVAS. The prime and subcontractor will work seamlessly to deliver the CVAS.
No, the prime shall own and operate the platform in accordance with RFP Attachment J.3.
9 General Question
We see the solicitation was released on June 9 with due date of June 23 for Phase 1 and July 14 for Phase 2. Can the due dates for BOTH phases (Phase 1 and Phase 2) be extended by 4 weeks so we have enough time to go over all the requirements and participate?
The proposal due date for Phase 1 will be extended to 12pm ET on June 27, 2022.
File details come from the government source that posted it. Updated .