832117964 CMRS_sources sought v5.docx
DOCX document 39 KB Posted
- Attached to
- DoD CMRS Development and Sustainment Federal contract opportunity
- Solicitation number
- 832117964
- Issued by
- Defense Information Systems Agency
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| PWS 832117964 CMRS-draft final v1.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOURCES SOUGHT ANNOUNCEMENT
Tracking Number 832117964
The Defense Information Systems Agency (DISA) is seeking sources for the Cyber Development Directorate to provide a solution for the Continuous Monitoring and Risk Scoring (CMRS) program.
CONTRACTING OFFICE ADDRESS: Defense Information Systems Agency Procurement Directorate (PLD) Defense Information Technology Contracting Organization (DITCO) - Scott 2300 East Drive, AFB, IL, 62225-5406
INTRODUCTION:
This is a SOURCES SOUGHT ANNOUNCEMENT to determine the availability and technical capability of small businesses (including the following subsets, Small Disadvantaged Businesses, Certified 8(a), Service-Disabled Veteran-Owned Small Businesses, HUBZone Small Businesses and Woman Owned Small Businesses) to provide the required products and/or services.
The DISA Cyber Development Directorate is seeking information for potential sources for the continued development, enhancement, and sustainment of the Department of Defense Continuous Monitoring and Risk Scoring (CMRS) solution to yield rapid implementation of new features, updates and improvements, including the redesign of certain features of current and future CMRS capabilities identified by the Government to meet operational requirements and to maintain those updates in the Department of Defense (DoD) network. CMRS is a suite of Government off-the-shelf (GOTS) based software solution creating enterprise and organizational risk views by applying threat intelligence and vulnerability-based scoring algorithms. The vision for CMRS is to integrate data from Department of Defense (DoD) Enterprise Cyber Security applications and tools using data standards to provide near-real time risk visualization, automated configuration management (CM) analysis, and continuous monitoring capabilities that enable Defensive Cyber Operations and provide risk awareness information. The objective of CMRS is to assess and measure the risk state of DoD Information Technology (IT) systems in accordance with Enterprise security controls such as software/hardware inventory, Security Technical Implementation Guide (STIG) and patch compliance, anti-virus configurations, and directive compliance. CMRS is built to host DoD security information of mobile devices, workstations and servers, networked user support devices, network infrastructure, Internet of Things (IoT), and Platform Information Technologies in a central repository. The CMRS application currently has over 2,500 users, and is in use by 285 organizations. There are over 2.5 million devices reporting software inventory, antivirus configuration, STIG, IAVM vulnerability, and patch compliance. The awarded vendor shall provide a service desk capable of supporting this workload, to include interfacing with all Combatant Commanders, Services, Agencies, Field Agencies (CC/S/A/FA) using CMRS throughout the DoD; and especially our DoD CIO, JFHQ-DoDIN, USCC, and DISA sponsors. Support also includes lab infrastructure administration for a local enclave located in DISA headquarters on Fort Meade, MD.
Anticipated Time Frame: February 4, 2022 – Feb 3, 2027 Base Year: February 4, 2022- February 3, 2023 Option Year 1: February 4, 2023- February 3, 2024 Option Year 2: February 4, 2024- February 3, 2025 Option Year 3: February 4, 2025- February 3, 2026 Option Year 4: February 4, 2026- February 3, 2027
The Base Period includes a 90 day transition period.
Place of Performance: The contractor shall perform work for this effort at the contractor’s facility. A portion of the work may require contractor support at the DISA Headquarters facilities (including the Government laboratory) at Ft. Meade, MD.
DISCLAIMER:
THIS SOURCES SOUGHT ANNOUNCEMENT IS FOR INFORMATIONAL PURPOSES ONLY. THIS IS NOT A REQUEST FOR PROPOSAL. IT DOES NOT CONSTITUTE A SOLICITATION AND SHALL NOT BE CONSTRUED AS A COMMITMENT BY THE GOVERNMENT. RESPONSES IN ANY FORM ARE NOT OFFERS AND THE GOVERNMENT IS UNDER NO OBLIGATION TO AWARD A CONTRACT AS A RESULT OF THIS ANNOUNCEMENT. NO FUNDS ARE AVAILABLE TO PAY FOR PREPARATION OF RESPONSES TO THIS ANNOUNCEMENT. ANY INFORMATION SUBMITTED BY RESPONDENTS TO THIS SOURCES SOUGHT ANNOUNCEMENT IS STRICTLY VOLUNTARY.
CONTRACT/PROGRAM BACKGROUND:
Contract Number: HC1028-17-A-0010 / HC1028-18-F-0597 Contract Type: Firm Fixed Price Incumbent and their size: Foxhole Technologies, Small Business Method of previous acquisition: Small business set-aside Period of performance: May 2018 - May 2022
The scope of the CMRS development and sustainment effort is to provide systems engineering, development, sustainment, and technical assistance to the DISA CMRS Program Management Office (ID6) for the continued development and deployment of robust CMRS capabilities. This includes:
· Requirements analysis
· Prototyping
· Custom code development and maintenance
· Beta/pilot testing and oversight
· Cybersecurity analysis, Assessment & Authorization (A&A) artifact generation and entry into the eMASS system
· Integration of both Commercial Off The Shelf (COTS) and Government Off the Shelf (GOTS) products and services
· Quality assurance/system evaluation
· Developmental testing
· Installation support
· Documentation
· System performance analysis to improve, enhance, and expand the CMRS capabilities
· Lab Administration Support
· Configuration management process implementation, tracking, and reporting
· Tier II/III Support Responsible for:
· Identifying, isolating, and resolving software anomalies
· The highest order of technical escalations in support
· Isolating and escalating software bugs
· Identifying product flaws – validated configurations with unresolved technical issues
· In-depth analysis of product debug logs/files
· Product enhancement and feature requests (usually routed through CMRS Program Manager PMO)
The contractor shall perform work for this effort at the contractor’s facility. A portion of the work may require contractor support at the DISA Headquarters facilities (including the Government laboratory) at Ft. Meade, MD.
REQUIRED CAPABILITIES:
1) The basic and operational drivers of the CMRS program are asset management, configuration compliance, and patch compliance. Therefore, CMRS must be able integrate with various GOTS/COTS products to maintain inventory of all hardware, and installed software on the DoDIN; in a central repository built to scale. Moreover, CMRS must have the ability to execute on-demand queries to assess employment of DoD patches and updates, mandated configurations (e.g. STIGS), baseline security controls (e.g. DoD sensor deployments, SHB compliance, etc.), anti-malware/anti-virus capabilities, and additional data inputs from various DoD systems and sensors (e.g. Digital Policy Management System (DPMS), Enterprise Mission Assurance Support Service (eMASS), and Comply-to-Connect (C2C) to name a few). Additionally, CMRS must have drilldown capabilities and show vulnerability status from different vantage points (e.g. A&A, CC/S/A/FA, sensor, device, access control, etc.). Furthermore, CMRS must display high priority threat and vulnerability data from the Intelligence Community (IC), provide a Measure of Risk factoring in variable such as network topography, mission criticality, active threats, threat intelligence, etc., and provide historical trending functionality while maintaining DoD security standards (e.g. DoD PKI infrastructure). Accordingly, demonstrate your ability to leverage agile scrum techniques to provide new increments of capabilities, new or upgraded integration interfaces between products or capabilities, and/or modernizations for the aforementioned CMRS foundational requirements.
2) Demonstrate your ability to configure and/or test capabilities of GOTS and COTS products to include unit, integration, operational, and systems testing of an integrated solution, and any necessary regression testing after incorporating new components or changes to the system.
3) Demonstrate your contract management capabilities in deploying, operating and maintaining Enterprise solutions in the DoD environments. Deployment includes support of the system in all applicable environments, to include: ECOSYSTEMS (formally known as DISA Enterprise Computing Centers), DoD lab environments (i.e. JITC), and commercial/government cloud environments.
4) Demonstrate your ability to implement Authorization and Assessment (A&A) and using the DoD A&A solutions. Any potential acquisition effort will require the vendor provide A&A artifact generation and data entry via the Risk Management Framework (RMF). DISA/ID solutions require consistent monitoring to address vulnerabilities, creation of A&A documentation, Plans of Actions and Milestones (POAMs) and submit change requests for minor releases and full Authority to Operate (ATO) before it is placed anywhere on the DoDIN and when new functionality is implemented.
5) Demonstrate your problem resolution, Tier II/III capabilities in support of DoD and/or DoD Mission Partners. Demonstration of problem resolution, Tier II/III capabilities for outside entities may be submitted as well for capability consideration.
6) Demonstrate your ability to configure and operate a test lab that heavily leverages virtualization and provides infrastructure services including user account management in Active Directory, remote access VPN, and different “sandbox” environments to enable concurrent testing of multiple products.
SPECIAL REQUIREMENTS
1. All contractor personnel assigned to this task shall be U.S. citizens and possess at least a minimum final SECRET security clearance on day one of the contract period of performance. The contractor shall comply with the provisions of the DoD Industrial Security Manual for handling classified material and producing deliverables.
2. All personnel supporting A&A or other Cyber Security functions must have the appropriate IA certification in accordance with DoD 8570.01-M.
3. IT-II certification is required for privileged user level access.
SOURCES SOUGHT:
The North American Industry Classification System Code (NAICS) for this requirement is 541511, with the corresponding size standard of $30M.
To assist DISA in making a determination regarding the level of participation by small business in any subsequent procurement that may result from this Sources Sought, you are also encouraged to provide information regarding your plans to use joint venturing (JV) or partnering. Please outline how you would envision your company's areas of expertise and those of any proposed JV/partner would be combined to meet the specific requirements contained in this announcement.
In order to make a determination for a small business set-aside, two or more qualified and capable small businesses must submit responses that demonstrate their qualifications. Responses must demonstrate the company’s ability to perform in accordance with the Limitations on Subcontracting clause (FAR 52.219-14).
SUBMISSION DETAILS:
Responses should include:
1) Business name and address;
2) Name of company representative and their business title;
3) Type of Small Business;
4) CAGE Code;
5) Your contract vehicles that would be available to the Government for the procurement of the product and/or service, to include ENCORE III, SETI, NIH, NASA SEWP, General Service Administration (GSA): OASIS, ALLIANT II, VETS, STARS II, Federal Supply Schedules (FSS) (including applicable SIN(s)), or any other Government Agency contract vehicle that allows for decentralized ordering. (This information is for market research only and does not preclude your company from responding to this notice.)
Vendors who wish to respond to this should send responses via email by Monday May 10, 2021, NLT 2:00PM Central Daylight Time (CDT) to lindsey.m.kahl.civ@mail.mil and roberto.a.kosovic.civ@mail.mil. Interested businesses should submit a brief capabilities statement package addressing the specific questions (no more than five pages) and demonstrating ability to perform the services listed under Required Capabilities.
Proprietary information and trade secrets, if any, must be clearly marked on all materials. All information received that is marked Proprietary will be handled accordingly. Please be advised that all submissions become Government property and will not be returned. All government and contractor personnel reviewing submitted responses will have signed non-disclosure agreements and understand their responsibility for proper use and protection from unauthorized disclosure of proprietary information as described 41 USC 423. The Government shall not be held liable for any damages incurred if proprietary information is not properly identified.
Page 6 of 6 Pages 26 Dec2019
File details come from the government source that posted it. Updated .