832573449 Recompete FO HC102822F0929_CLEAN.docx
DOCX document 236 KB Posted
- Attached to
- Cybersecurity Management Services Federal contract opportunity
- Solicitation number
- 832573449
- Issued by
- Defense Information Systems Agency
About this file
This is a Statement of Work (SOW) for Cybersecurity Management Services for the Defense Information Systems Agency (DISA) J-9 Hosting and Compute (J-9 HaC) Cybersecurity Division. The requirement is for comprehensive cybersecurity support across 19 task areas, including cyber automation, endpoint protection, vulnerability analysis, incident response, and strategic partner integration. The contract includes a 12-month base period with three 12-month option periods, starting October 1, 2026, with personnel required to have a Secret security clearance and work primarily at DISA facilities in Oklahoma City, Mechanicsburg, San Antonio, Montgomery, and Ogden.
Key objectives include providing cybersecurity management support for DISA's Cyber Services Line of Business, with tasks encompassing compliance monitoring, vulnerability management, cyber automation, configuration management, authorization and risk management, and strategic partner engagement. The contractor will support work on NIPRNet and SIPRNet environments, utilizing various cybersecurity tools and performing functions such as access control, audits, application administration, incident response, network defense, and risk management. Personnel must meet specific qualifications, including bachelor's degrees, current 8570/8140 certifications, and extensive experience in cybersecurity and related technical domains.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sources Sought Notice FOHC102822F0929.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK (SOW)
| Award/Mod Effective |
| Version Date |
| Award |
| To be Determined (TBD) |
| Contract Number: |
| TBD |
| Task Order Number: |
| TBD |
| Tracking Number: |
| 832573449 |
| Contractor Name: |
| TBD |
| Follow-on to Previous Contract and Task Order Number: |
| 47QTCA18D00K3 – HC102822F0929 |
1.Contracting Officer’s Representative (COR).
a. Primary COR. See DITCO Additional Text G1 - Points of Contact
b. Alternate COR (ACOR). See DITCO Additional Text G1 - Points of Contact
c. Property Administrator. See DITCO Additional Text G1 - Points of Contact
2. Contract or Task Order Title. Cybersecurity Management
3. Background. A major component of Defense Information Systems Agency (DISA) is Cyber Services Cybersecurity management. The vast mission of Cyber Services the Cybersecurity Division is to deliver secure enterprise-wide information technology services, enabling and enhancing the warfighters’ ability to execute the mission. These services include, but are not limited to, Assessment and Authorization (A&A), Risk Management Framework (RMF) activities, Vulnerability Management activities, continuous monitoring, and program security posture as it pertains to Enterprise Program Services, Network Program Services, Strategic Partner Engagement, and Internal Program Services.
4. Objectives. The objective of this requirement is to provide Cyber Vulnerability Management Cybersecurity Management support for DISA J-9 Hosting and Compute (J-9 HaC) Cybersecurity Division Cyber Services Line of Business (LOB ) by providing compliance monitoring/reporting, response and mitigation, Cyber Automation and Management services, compliance validation, configuration, change and account management, A&A, RMF, Federal Information Security Management Act compliance, Cyber Risk Management, Cyber Standardization and Strategic Partner Engagement and Implementation for DISA Cyber SecurityJ-9 HaC supported systems.
5. Scope. The contractor shall provide cybersecurity support for DISA J-9 HaC and DISA’s J-9 HaC’s Strategic Partners. These cybersecurity services include access control, A&As, audits, application administration, support for commercial off-the-shelf tools and Government off-the-shelf tools, Cybersecurity documentation, DISA Task Orders Management, metrics, incident response, network defense, public key infrastructure support, risk management, training management, security posture validation, and vulnerability analysis. Work accomplished under this task order shall include cybersecurity support ion isolated network, Non-Secured Internet Protocol Router Network (NIPRNet) and Secret Internet Protocol Router Network (SIPRNet) isolated environments. The contractor shall provide the appropriate skilled personnel to support DISA's sustainment activities under the task areas listed below.
· Task Area 1 - Cyber Automation Database
· Task Area 2 - Endpoint Protection Management
· Task Area 3 - Endpoint Scanning Management
· Task Area 4 - Application Vulnerability Analysis
· Task Area 5 - Database Vulnerability Analysis
· Task Area 6- Web Vulnerability Analysis
· Task Area 7 - OS Vulnerability Analysis
· Task Area 8 - Cyber Security Configuration Validation (Optional)
· Task Area 9 - Cyber Automation Operating System (OS) (Optional)
· Task Area 10 – J-9 HaC Incident Response (Optional)
· Task Area 11 - RMF Database Administration (DBA) (Optional)
· Task Area 12 - Network Vulnerability Analysis (Optional)
· Task Area 13 - UNIX and Linux Vulnerability Analysis (Optional)
· Task Area 14 - Cyber Administration and Support (Orders Management and Standardization, Information Technology Service Management (ITSM), Information Technology Infrastructure Library (ITIL) and Process Improvement, Metrics) (Optional)
· Task Area 15 - Strategic Partner Integration (Optional)
· Task Area 16 – Risk Management Framework (RMF) (Optional)
· Task Area 17 - Cyber Threat Planning (Optional)
· Task Area 18 - Task Order Management
· Task Area 19 - After-Hours Support (Ad-Hoc/On-Call)
The Government may require surge support during the base or any option period, and surge modifications will be within the scope of the contract and provide increased support for the defined task areas of this SOW. Surge support over the life of the contract will not exceed 50% of the contractor’s total proposed cost/price for the base and all option periods, excluding any six-month extension of services pursuant to Federal Acquisition Regulation (FAR) 52.217-8.
6. Specific Tasks. For all tasks the contractor shall:
· During assigned duty hours, ensure contractor personnel are present and responsive in chat, email, and other collaboration tools (including Cisco Jabber, Global Video Service, Microsoft Teams, and Microsoft Outlook). V Adhere to a 30-minute response window when not in meetings or performing assigned tasks which prohibit NIPRNet workstation access. Provide project schedules and Project Status Report (PSR) representing the current state of major milestones, project schedules, activities, risks, and challenges.
· Create and maintain Tactics, Techniques and Procedures (TTPs), work instructions/job aids, and user guides for applicable functions.
· Monitor, maintain and submit ticket updates, change requests, and documentation in Ecosystem’s ticketing system.
· Provide in-depth on-the-job training for the DISA Cyber LOB workforce.
· Participate in meetings for applicable functions.
· Research, provide input to, and participate in the Cyber LOB Continuity of Operations Plan (COOP) activities.
· Follow applicable TTPs and work instructions. Support Cyber LOB implementation, sustainment, authorization, and assessment activities.
· Properly use DISA cybersecurity tools as outlined by assigned duties. Tools currently implemented include Endpoint Security System (ESS), Assured Compliance Assessment Solution (ACAS), Enterprise Security Posture System (ESPS), Ecosystem’s ticketing system, Defense Information Technology Portfolio Repository (DITPR), Enterprise Mission Assurance Support Service (eMASS), Continuous Monitoring and Risk Scoring (CMRS), Global Information Grid Interconnection Approval Process (GIAP), Systems Network Approval Process (SNAP), Ports, Protocols and Services Management (PPSM), Security Technical Implementation Guides (STIG) Viewer, Web Application Filter (WAF) F5, IronPort, Splunk, and TrueSight.
· Provide audience targeted and accurate feedback to requests for information.
· Support, review, and submit recommendations for improvements in efficiencies and effectiveness for cybersecurity activities, processes, and documentation.
· Provide on-call support for Cyber LOB assistance (On-call support estimated to occur approximately 33 hours per month).
· Maintain due diligence when handling sensitive data to include Controlled Unclassified Information (CUI), Personally identifiable information (PII), Health Insurance Portability and Accountability Act (HIPAA) information and Payment Card Industry (PCI) information based on applicable federal, departmental, and/or agency policies and guidelines.
· Complete and submit all deliverables in a timely manner.
· Obtain the appropriate Department of Defense (DoD)-approved Information Assurance (IA) certification prior to being engaged, and any additional certifications for the position within six months of start date.
Deliverables (applicable to all Tasks):
· After Action Report per incident
· Audit support documents
· Cybersecurity tool (current version) certification and/or training as published by the DoD Job aids Monthly Status Report (MSR)
· Meeting minutes
· Lessons learned
· Process flowcharts
· Project schedules
· Reports from anomalous events
· RMF support documents
· PSR
· TTPs
· Technical interpretations
· Training support documents
· Updated security procedures
· White papers
6.1 Task 1 - Cyber Automation Database. See Minimum Qualifications Matrix for required minimum qualifications for full-time equivalents (FTEs) performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.1.1 Subtask – DBA.
Key Personnel: Cyber Automation Database Developer (Senior)
The contractor shall:
| Evaluate DISA cybersecurity STIGs, tools and processes to identify and implement consolidation, integration, and automation opportunities. This effort will focus on improving the efficiency and effectiveness of J-9 HaC services. |
| Analyze and understand customer data requirements and specifications. |
| Create and maintain automated solutions for vulnerability lifecycle management of database applications, utilizing Shell Scripting, Java, and UNIX environments. |
| Create and maintain automated database reporting solutions using Extensible Markup Language (XML) interfaces. |
| Implement and maintain security controls for database environments (Oracle, International Business Machines DataBase2 (IBM DB2), MariaDB, MongoDB, PostgreSQL, MySQL) hosted on UNIX environments, adhering to all applicable DoD security. |
| Conduct performance tuning activities designed to optimize data management processes. |
| Coordinate with Strategic Partners and/or DISA personnel prior to development, testing or implementation. |
| Conduct functional testing of developed solutions; create and maintain supporting documentation; and provide Tier III application support for developed tools. |
| Maintain the development environment and ensure compliance with all relevant security guidance. |
| Create and maintain documentation for software releases supporting user base; maintain code control using the Government-defined software repository. |
| Participate in normal sprint releases meeting stakeholders' timelines, as well as emergency software releases when dictated by operational tempo. |
| Provide A&A for Strategic Partners. |
| Complete peer code reviews as required. |
Deliverables:
· Completed UNIX Database Toolkit
· Database Toolkit Documentation
· Documentation of the peer code review process and findings
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title |
| Format |
| Due Date |
| Distribution/Copies |
| Frequency and Remarks |
| 6.1 |
| UNIX Data- base Toolkit |
| Government Provided Template |
| 30 calendar days upon STIG release or upon request |
| Stored on Servers, |
Reviewed by Government Section Chief Up to 12 per year typically monthly
| 6.1 |
| Database Toolkit Documentation |
| Government Provided Template |
| Seven business days upon initial toolkit release |
| Standard Distribution |
| Up to 12 per year typically monthly |
| 6.1 |
| Peer Code Reviews |
| Government |
Provided Template
| One – five business days upon request |
| Standard Distribution |
| Up to four |
typically, yearly
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.2 Task 2 – Endpoint Protection Management. See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.2.1 Subtask 1 – Tier II Endpoint Protection Operation. Key Personnel: Endpoint Protection Administrator (Senior) and Endpoint Protection Administrator (Master)
The contractor shall:
| Operate, manage, and deploy DISA approved endpoint security tools and components to include ESS and Microsoft Defender/Mobile Distributed File System (MDE/MDfS) in accordance with (IAW) all active DoD and DISA policies and procedures in isolated environments, SIPRNET, and NIPRNet. Monitor, maintain, and facilitate endpoint protection compliance throughout DISA and the life cycle. |
| Perform rogue system and removable storage monitoring and registration, testing, module installation, policy, tag, and security scan creation and application, firewall, Intrusion Protection System, Antivirus tuning and enforcement. |
| Validate, register, update and maintain approved mass storage device documentation to include removable spinning disk drives. |
| Participate in and adhere to change control board and stakeholder weekly meetings, determinations, and requirements. |
| Investigate, remediate, prevent, and document issues resulting in denials of service. |
| Create, maintain, and facilitate custom queries, reports, and dashboards for system, module, and policy compliance. |
| Monitor and report cyber and insider threats. |
| Facilitate and approve endpoint protection application upgrades and changes. |
| Coordinate Tier III vendor support troubleshooting. |
| Monitor, evaluate, remediate, and prevent performance impacting issues. |
| Manage DISA approved endpoint security tool accounts and credentials IAW DISA privileged access policies and procedures. |
| Conduct audits and provide documentation. |
Deliverables:
· Compliance reports and trending analysis
· Current registered device documentation
· Security Violation Reports
· Weekly Metrics
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title |
| Format |
| Due Date |
| Distribution/Copies |
| Frequency and Remarks |
| 6.2 |
| Compliance reports and trending |
analysis
| Government Provided Template |
| Schedule release dates provided by the Government |
| Standard Distribution |
Up to 52 per year weekly
| 6.2 |
| Current registered device documentation |
| Government Provided Template |
| Schedule release dates provided by the Government |
| Standard Distribution |
Up to 365 per year daily
| 6.2 |
| Security violation reports |
| Government Provided Template |
| Schedule release dates provided by the Government |
| Standard Distribution |
Up to 730 per year twice per day
| 6.2 |
| Weekly Metrics |
| Government Provided |
Template Schedule release dates provided by the Government Standard Distribution
Up to 104 per year weekly
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.3 Task 3 – Endpoint Scanning Management. See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.3.1 Subtask 1 – Tier III Endpoint Scanning Operation. Key Personnel: Endpoint Scanning Specialist (Master).
The contractor shall:
| Operate and maintain DISA approved security scanners to plan, create, manage, and retire schedule for ad hoc scans and scan groups for new and existing workloads across isolated environments, NIPRNet and SIPRNet IAW all active DoD and DISA policies and procedures. |
| Maintain and ensure scans, accounts, and configurations are set IAW best practice guides and DISA privileged access policies and procedures. |
| Communicate, resolve, revalidate, and prevent scan failures with all stakeholders IAW DISA policies and procedures. |
| Test, evaluate, and deploy endpoint scanning tools and configurations to DISA and other applicable endpoints. |
| Analyze mission requirements and organizational feedback to create, configure, maintain, and improve scan reports. |
| Monitor, identify, and facilitate the resolution of performance impacting issues. |
| Create and/or review security scan reports with stakeholders. |
| Participate in audits and provide documentation. |
Deliverables:
· Metrics and trending analysis reports
· Scan systems (Government provided list)
· Scan failures report
· Scanning vulnerability reports
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title |
| Format |
| Due Date |
| Distribution/Copies |
| Frequency and Remarks |
| 6.3 |
| Metrics and trending analysis |
Reports
| Government Provided Template |
| Schedule release dates provided by |
the Government
| Standard Distribution |
| Up to 1300 per year typically |
daily
| 6.3 |
| Scan systems |
| Government Provided Template |
| Schedule release dates provided |
by the Government Standard Distribution
Up to 52 per year typically weekly
| 6.3 |
| Scan failures report |
| Government Provided Template |
| Schedule release dates provided |
by the Government Standard Distribution
Up to 730 per year twice per day
| 6.3 |
| Scanning |
vulnerability reports
| Government Provided Template |
| Schedule release dates provided |
by the Government Standard Distribution
Up to 52 per year typically weekly
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.4 Task 4 – Application Vulnerability Analysis. See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.4.1 Subtask 1 – Application Specialist Support.
The contractor shall:
· Serve as an App technical specialist for assets connected to isolated environments, NIPRNet and SIPRNet to support cybersecurity and IT services.
· Review, identify, and report problems with the installation and operations of application instances to include system options, software used and not used, default security controls that are enabled, disabled, or bypassed, and system wide options or parameters that may create security vulnerabilities.
· Determine the impact and risk of submitted change requests prior to implementation and participate in change advisory board meetings (up to daily) to provide cyber oversight for database changes that affect the level of risk.
· Recommend security countermeasures to mitigate identified app risks.
6.4.2 Subtask 2 – Application Vulnerability Analysis.
The contractor shall:
· Identify, monitor, analyze, report, and brief status of vulnerabilities.
· Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated.
· Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders.
· Create, maintain, and provide automated and customized vulnerability reports.
· Analyze mission requirements and organizational feedback to improve vulnerability reports and processes.
· Provide recommendations for app vulnerability analysis, guidance, deficiency resolution, and implementation suggestions to DISA customers and Mission Partners.
6.4.3 Subtask 3 – Application Compliance Validation and Support.
The contractor shall:
· Assess, audit, review analyze, validate, and report database Security Requirements Guide (SRG) and STIG vulnerabilities, and ensure security controls are implemented within databases IAW DoD, DISA and cybersecurity policies and procedures.
· Evaluate discrepancies as they relate to policy, orders, and database SRG and/or STIGs, and document recommended additions, deletions, or changes.
· Identify and report the need to add technical guidance for modification of policies and Orders.
· Review and validate the installation and configuration of cyber tools on assets, and report deficiencies.
· Review database SRG and/or STIGs as updates are released, and report changes with the potential to have significant impact.
· Determine the impact and risk of submitted change requests prior to implementation and participate in meetings to provide cyber oversight for web changes that affect the level of risk.
· Recommend security countermeasures to mitigate identified web risks.
· Participate in audits and provide documentation (up to daily).
Deliverables:
· Daily/weekly/monthly/quarterly/annual vulnerability analysis reports
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title | |
| Format | |
| Due Date | |
| Distribution/Copies | Frequency |
and Remarks
| 6.4 |
| Vulnerability Analysis Reports |
| Government Provided Template |
| Schedule release dates provided by |
the Government
| Standard Distribution |
| Up to 700 per year typically |
weekly
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.5 Task 5 – Database Vulnerability Analysis. See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.5.1 Subtask 1 – Database Specialist Support.
The contractor shall:
· Serve as a Database technical specialist for assets connected to isolated environments, NIPRNet and SIPRNet to support cybersecurity and IT services.
· Review, identify, and report problems with the installation and operations of Database instances to include system options, software used and not used, default security controls that are enabled, disabled, or bypassed, and system wide options or parameters that may create security vulnerabilities.
· Possess database expertise including Oracle, SQL, MySQL, or DB2 database software.
· Determine the impact and risk of submitted change requests prior to implementation and participate in change advisory board meetings (up to daily) to provide cyber oversight for data- base changes that affect the level of risk.
· Recommend security countermeasures to mitigate identified database risks.
6.5.2 Subtask 2 – Database Vulnerability Analysis.
The contractor shall:
· Identify, monitor, analyze, report, and brief status of vulnerabilities.
· Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated.
· Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders.
· Create, maintain, and provide automated and customized vulnerability reports.
· Analyze mission requirements and organizational feedback to improve vulnerability reports and processes.
· Provide recommendations for database vulnerability analysis, guidance, deficiency resolution, and implementation suggestions to DISA customers and Mission Partners.
6.5.3 Subtask 3 – Database Compliance Validation and Support.
The contractor shall:
· Assess, audit, review analyze, validate, and report database SRG and STIG vulnerabilities, and ensure security controls are implemented within databases IAW DoD, DISA and cybersecurity policies and procedures.
· Evaluate discrepancies as they relate to policy, orders, and database SRG and/or STIGs, and document recommended additions, deletions, or changes.
· Identify and report the need to add technical guidance for modification of policies and Orders.
· Review and validate the installation and configuration of cyber tools on assets, and report deficiencies.
· Review database SRG and/or STIGs as updates are released, and report changes with the potential to have significant impact.
· Determine the impact and risk of submitted change requests prior to implementation and participate in meetings to provide cyber oversight for web changes that affect the level of risk.
· Recommend security countermeasures to mitigate identified web risks.
· Participate in audits and provide documentation (up to daily).
Deliverables:
· Daily/weekly/monthly/quarterly/annual vulnerability analysis reports A&A Documentation
· SSP Documentation
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title | |
| Format | |
| Due Date | |
| Distribution/Copies | Frequency |
and Remarks
| 6.5 |
| Vulnerability Reports |
| Government Provided |
Template Schedule release dates provided by the Government
| Standard Distribution |
| Up to 700 per year typically |
weekly
| 6.5 |
| A&A Documentation |
| Government |
Provided Template Schedule release dates provided by the Government
| Standard Distribution |
| Up to 900 per |
year typically weekly
| 6.5 |
| SSP |
Documentation Government Provided Template Schedule release dates provided by the Government
| Standard Distribution |
| Up to 4 per year Quarterly |
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.6 Task 6 –Web Vulnerability Analysis. See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.6.1 Subtask 1 – Web Specialist Support.
The contractor shall:
· Serve as a Web technical specialist for assets connected to isolated environments, NIPRNet and SIPRNet to support cybersecurity and IT services.
· Review, identify, and report problems with the installation and operations of web instances to include system options, software used and not used, default security controls that are enabled, disabled, or bypassed, and system wide options or parameters that may create security vulnerabilities.
· Determine the impact and risk of submitted change requests prior to implementation and participate in change advisory board meetings (up to daily) to provide cyber oversight for data- base changes that affect the level of risk.
· Recommend security countermeasures to mitigate identified web risks.
6.6.2 Subtask 2 – Web Vulnerability Analysis.
The contractor shall:
· Identify, monitor, analyze, report, and brief status of vulnerabilities.
· Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated.
· Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders.
· Create, maintain, and provide automated and customized vulnerability reports.
· Analyze mission requirements and organizational feedback to improve vulnerability reports and processes.
· Provide recommendations for web vulnerability analysis, guidance, deficiency resolution, and implementation suggestions to DISA customers and Mission Partners.
6.6.3 Subtask 3 – Web Compliance Validation and Support.
The contractor shall:
· Assess, audit, review analyze, validate, and report database SRG and STIG vulnerabilities, and ensure security controls are implemented within databases IAW DoD, DISA and cybersecurity policies and procedures.
· Evaluate discrepancies as they relate to policy, orders, and database SRG and/or STIGs, and document recommended additions, deletions, or changes.
· Identify and report the need to add technical guidance for modification of policies and Orders.
· Review and validate the installation and configuration of cyber tools on assets, and report deficiencies.
· Review database SRG and/or STIGs as updates are released, and report changes with the potential to have significant impact.
· Determine the impact and risk of submitted change requests prior to implementation and participate in meetings to provide cyber oversight for web changes that affect the level of risk.
· Recommend security countermeasures to mitigate identified web risks.
· Participate in audits and provide documentation (up to daily).
Deliverables:
· Daily/weekly/monthly/quarterly/annual vulnerability analysis reports
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title |
| Format |
| Due Date |
| Distribution/Copies |
| Frequency and Remarks |
| 6.6 |
| Vulnerability Report |
| Government Provided Template |
| Schedule release |
dates provided by the Government
| Standard Distribution |
| Up to 700 per |
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.7 Task 7 – OS Vulnerability Analysis. See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.7.1 Subtask 1 – OS Specialist Support.
The contractor shall:
· Serve as an OS technical specialist for assets connected to isolated & Cloud environments, NIPRNet and SIPRNet, to support cybersecurity and IT services.
· Serve as technical specialist for assets connected to isolated environments to support cybersecurity and IT services. Review, identify, and report problems with the installation and operations of assets to include system options, software used and not used, default security controls that are enabled, disabled, or bypassed, and system wide options or parameters that may create security vulnerabilities. Determine the impact and risk of submitted change requests prior to implementation and participate in meetings to provide cyber oversight for OS changes that affect the level of risk. Recommend security countermeasures to mitigate identified risks.
· Determine the impact and risk of submitted change requests prior to implementation and participate in meetings to provide cyber oversight for changes that affect the level of risk.
· Recommend security countermeasures to mitigate identified risks.
6.7.2 Subtask 2 – OS Vulnerability Analysis.
The contractor shall:
· Identify, monitor, analyze, report, and brief status of all OS vulnerabilities to include, but not limited to, Windows, Unix, Mainframe, Network Devices, Cloud Technologies and Other.
· Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated.
· Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders.
Create, maintain, and provide automated and customized vulnerability reports.
· Analyze mission requirements and organizational feedback to improve vulnerability reports and processes.
· Provide recommendations for OS vulnerability analysis, guidance, deficiency resolution, and implementation suggestions to DISA customers and Mission Partners.
6.7.3 Subtask 3 – OS Compliance Validation and Support.
The contractor shall:
· Assess, audit, review, analyze, validate, and report OS, SRG, and STIG vulnerabilities, and ensure security controls are implemented within OS IAW DoD, DISA and industry cybersecurity policies and procedures.
· Evaluate discrepancies as they relate to policy, orders and OS, SRG, and/or STIGs, and document recommended additions, deletions, or changes.
· Identify and report the need to add technical guidance for modification of policies and orders.
· Review and validate the installation and configuration of cyber tools on assets, and report deficiencies.
· Review OS, SRG, and/or STIGs as updates are released, and report changes with the potential to have significant impact.
· Participate in audits and provide documentation (up to daily).
Deliverables:
· Daily/weekly/monthly/quarterly/annual vulnerability analysis reports
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title | |
| Format | |
| Due Date | |
| Distribution/Copies | Frequency |
and Remarks
| 6.7 |
| Vulnerability Report |
| Government Provided Template |
| Schedule release dates provided by the Government |
| Standard Distribution |
| Up to 700 per year typically weekly |
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.8 Task 8 - Cyber Security Configuration Validation (Optional). See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.8.1 Subtask 1 – Cybersecurity Configuration Validation Oversight.
The contractor shall:
| Oversee and maintain the cyber configuration validation process IAW DoD and DISA policies and procedures for isolated environments, NIPRNet, and SIPRNet networks. |
| Validate cyber configuration validation procedure requirements are followed to ensure DISA J-9 HaC managed operating environments (OEs) meet the responsible Authorizing Official (AO) build specifications in the approved system A&A package prior to full production connectivity to DoD Information Networks (DoDIN). |
| Provide cyber configuration validation guidance and vulnerability resolution recommendations to DISA and Strategic Partner personnel. |
6.8.2 Subtask 2 – Cybersecurity Configuration Compliance.
The contractor shall:
| Validate the cyber configuration validation checklist and supporting compliance documentation have been provided and verify SRG and STIG documentation is for the latest available version. |
| Ensure OEs are registered in the DISA asset connection tracking database and records are updated whenever the connectivity status for an OE change (no more than five times per year). |
| Request network security scans and validate results. |
| Review DISA directives and orders, SRG, STIG and network scan vulnerabilities, and validate that vulnerabilities in an open state meet policy guidelines. |
| Review and validate the complete installation and configuration of mandated cyber tools on DISA OEs. |
| Verify the owning Strategic Partner has acknowledged the security posture of the submitted OE(s) and provide notification of cyber configuration validation approval or denial decisions to the requester. |
Deliverables:
· Refer to all task area required deliverables.
6.9 Task 9 - Cyber Automation OS (Optional). See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.9.1 Subtask Task 1 – UNIX and Windows Administration.
The contractor shall:
| Analyze DISA Cybersecurity tools and processes for consolidation, integration, and incorporation to leverage additional automation opportunities to improve J-9 HaC efficiencies and effectiveness. |
| Analyze customer data requirements and specifications. |
| Secure Windows and UNIX environments using DoD security regulations. |
| Coordinate with appropriate stakeholders prior to testing or implementation. |
| Conduct functional testing of developed solutions. |
| Create and maintain documentation to support the developed solution. |
| Maintain development environment and ensure compliance with all appropriate security guidance. |
| Create and maintain documentation to support the developed solution. |
| Participate in normal sprint releases meeting stakeholders' timelines or emergency software releases when operations tempo dictates. |
| Provide A&A for Strategic Partners. |
| Provide tier 2 application support for supported applications. |
Deliverables:
· Refer to all task area required deliverables.
6.10 Task 10 – J-9 HaC Incident Response (Optional). See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.10.1 Subtask 1 – Incident Response Analysis.
The contractor shall:
· Ensure DISA approved security tools are monitoring, alerting, and retaining event logs in IAW DoD and DISA policies and procedures
· Facilitate remediation of incident report deficiencies with J-9 HaC Points of Contact (PoC).
· Maintain situational awareness of the network within the J-9 HaC and report suspicious activity to include insider threat events. Process all threat events as critically time sensitive.
· Perform audit log reviews with DISA approved security monitoring and data aggregation tools to detect, analyze, investigate, escalate, monitor, and mitigate suspicious events. Escalate suspicious events to DISA CSSP PoCs and stakeholders.
· Maintain chain of custody and data integrity of incident response system data, files, and evidence of reported incidents.
· Investigates and facilitates the mitigation of Negligent Disclosure of Classified Information or other spillage, and DoD threat tippers.
· Coordinate incident response support through Ecosystem PoCs.
· Maintain copies of the latest incident response tool kits per CSSP and Incident Response and Recovery Team IAW DoD and DISA policies and procedures.
· Document, train, and provide awareness of mitigated threats to reduce risk of repeat incidents to Government personnel.
Deliverables:
· Weekly metrics
· MSR
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements
SOW
Task#
| Deliverable Title | |
| Format | |
| Due Date | |
| Distribution/copies | Frequenc |
| Remarks |
| 6.10 |
| Weekly |
| Government |
| Schedule |
Standard Distribution Up to 104
| Metrics |
| Provided Template |
| release dates |
per year provided weekly by the
Government
| 6.10 |
| MSR |
| Government |
| Within five |
| Monthly |
| provided |
| calendar days of |
| template |
| the end |
of the reporting period.
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.11 Task 11 –RMF DBA (Optional). See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.11.1 Subtask 1 – DBA.
The contractor shall:
| Perform DBA in support of Cybersecurity Division RMF requirements. |
| Create, update, modify, and improve database tables. |
| Create, update, modify, and improve simple to complex queries. |
| Create, update, modify and improve simple to complex forms. |
| Provide visual basic scripting support to create, update, modify and improve modules and macros. |
Add and/or update data within the RMF database to include information from RMF supporting documents, links to documents stored on the web, control correlation identifier ownerships, and RMF overlay relationships.
Sustain and maintain RMF database for optimum performance.
Research and innovate database improvements for evolving Cybersecurity Division requirements and assignments.
Deliverables:
· Comprehensive Audit Controls Database
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title | |
| Format | |
| Due Date | |
| Distribution/Copies | Frequency |
and Remarks
| 6.11 |
| Comprehensive Audit Controls Database |
| Government Provided Template |
| Schedule release dates provided by the Government |
| Standard Distribution |
| Up to 52 per year typically weekly |
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.12 Task 12 – Network Vulnerability Analysis (Optional). See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.12.1 Subtask 1 – Network Specialist Support.
The contractor shall:
| Serve as a network technical specialist for assets connected to isolated environments, NIPRNet and SIPRNet, to support cybersecurity and IT services. |
| Review, identify, and report problems with the operations of network assets to include system options, software used and not used, default security controls that are enabled, disabled, or by- passed, and system wide options or parameters that may create security vulnerabilities. |
| Determine the impact and risk of submitted change requests prior to implementation and participate in Change Advisory Board (CAB) meetings to provide cyber oversight for network changes that affect the level of risk. |
| Recommend security countermeasures to mitigate identified network risks. |
6.12.2 Subtask 2 – Network Vulnerability Analysis.
The contractor shall:
Identify, monitor, analyze, report, and brief status of J-9 HaC vulnerabilities.
Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated.
Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders.
Create, maintain, and provide automated and customized vulnerability reports.
Analyze mission requirements and organizational feedback to improve vulnerability reports and processes.
Provide recommendations for Network vulnerability analysis, guidance, deficiency resolution, and implementation suggestions to DISA customers and Strategic Partners.
6.12.3 Subtask 3 – Network Compliance Validation and Support.
The contractor shall:
| Assess, audit, review, analyze, validate, and report network SRG and STIG vulnerabilities, and ensure security controls are implemented within network equipment IAW DoD, DISA and cyber- security policies and procedures. |
| Evaluate discrepancies as they relate to policy, orders and network SRG and/or STIGs, and document recommended additions, deletions, or changes. Identify and report the need to add technical guidance for modification of policies and orders. |
Review and validate the installation and configuration of cyber tools on assets, and report deficiencies.
Review network SRG and/or STIGs as updates are released, and report changes with the potential to have significant impact.
Deliverables:
· Daily/weekly/monthly/quarterly/annual vulnerability analysis reports
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title |
| Format |
| Due Date |
| Distribution/Copies |
| Frequency and Remarks |
| 6.12 |
| Vulnerability Reports |
| Government Provided |
Template Schedule release dates provided by the Government
| Standard Distribution |
| Up to 700 per year typically |
weekly
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; One copy of the transmittal letter with the deliverable to the Primary COR.
6.13 Task 13 – UNIX and Linux Vulnerability Analysis (Optional). See Minimum Qualifications Matrix for required minimum qualifications for FTEs performing this task. Personnel will have access to Secret Classified Information through SIPRNet.
6.13.1 Subtask 1 – UNIX and Linux Specialist Support.
The contractor shall:
| Serve as a UNIX and Linux technical specialist for assets connected to isolated environments, NIPRNet and SIPRNet to support cybersecurity and IT services. |
| Review, identify, and report problems with the installation and operations of UNIX and Linux as- sets to include system options, software used and not used, default security controls that are enabled, disabled, or bypassed, and system wide options or parameters that may create security vulnerabilities. |
| Determine the impact and risk of submitted change requests prior to implementation and participate in CAB meetings to provide cyber oversight for UNIX and Linux changes that affect the level of risk. |
| Recommend security countermeasures to mitigate identified UNIX and Linux risks. |
6.13.2 Subtask 2 – UNIX and Linux Vulnerability Analysis.
The contractor shall:
| Identify, monitor, analyze, report, and brief status of J-9 HaC vulnerabilities. |
| Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated. |
| Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders. |
| Create, maintain, and provide automated and customized vulnerability reports. |
| Analyze mission requirements and organizational feedback to improve vulnerability reports and processes. |
| Provide recommendations for UNIX and Linux vulnerability analysis, guidance, deficiency resolution, and implementation suggestions DISA Customers and Strategic Partners. |
6.13.3 Subtask 3 – UNIX and Linux Compliance Validation and Support.
The contractor shall:
| Assess, audit, review, analyze, validate, and report UNIX and Linux SRG and STIG vulnerabilities, and ensures security controls are implemented within UNIX and Linux IAW DoD, DISA and cybersecurity policies and procedures. |
| Evaluate discrepancies as they relate to policy, orders and UNIX and Linux SRG and/or STIGs, and document recommended additions, deletions, or changes. |
| Identify and report the need to add technical guidance for modification of policies and Orders. |
| Review and validate the installation and configuration of cyber tools on assets, and report deficiencies. |
| Review UNIX and Linux SRG and/or STIGs as updates are released, and report changes with the potential to have significant impact. |
| Conduct audits and provide documentation. |
6.13.4 Subtask 4 – UNIX and Linux Network Monitoring Software Oversight.
The contractor shall:
Review, coordinate, approve temporary use, and verify removal of network monitoring software for troubleshooting on UNIX and Linux assets IAW DISA policy.
Deliverables:
· Daily/weekly/monthly/quarterly/annual vulnerability analysis reports
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task#
| Deliverable Title | |
| Format | |
| Due Date | |
| Distribution/Copies | Frequency |
and Remarks
| 6.13 |
| Vulnerability Reports |
| Government Provided Template |
| Schedule release |
dates provided by the Government
| Standard Distribution |
| Up to 700 per |
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.14 Task 14 – Cyber Administration and Support (Orders Management and Standardization, ITSM, ITIL and Process Improvement, Metrics) (Optional).
6.14.1 Subtask 1 – Cyber Orders.
The contractor shall analyze, assign, facilitate, track and report Cybersecurity Division compliance for approximately 200 DISA Orders annually. The contractor shall serve as Cybersecurity Division’s orders liaison for process stakeholders, to include Data Center LOB, Command and Control (C2), DISA Joint Operations Center (DJOC), Risk Management Executive, and Joint Forces Headquarters (DCDC). The contractor shall receive and acknowledge cyber orders from C2 and distribute clarifying guidance. Further, the contractor shall brief draft and active cyber orders to Cybersecurity Division and J-9 HaC.
6.14.2 Subtask 2 – Cyber Standardization.
The contractor shall collaborate with stakeholders, including DJOC, DCDC, United States (U.S.) Cyber Command, Cybersecurity Division and other DoD components, to review and coordinate on draft or needed cyber orders. Collaborate with DJOC to improve quality of orders. Escalate and communicate Requests for Information (RFI) or necessary order alterations. Provide input and create Orders reports for DoD Chief Information Officer Scorecard compliance.
6.14.3 Subtask 3 – ITSM.
The contractor shall provide System Matter Expertise (SME) with regards to ITSM, tools, and processes used in implementing a successful ITSM program in support of Cybersecurity Division initiatives. Develop, implement, and maintain Cybersecurity Division ITIL Process, Operating Level Agreements, and project plans and schedules. Collaborate with service delivery organizations and stakeholders to document Cybersecurity Division supporting processes. Conduct Cybersecurity Division briefings, technical meetings (internal and external representatives) and serve as a consultant to management on major matters pertaining to its policies, plans, and objectives. Provide strategic definitions, implementations and recommendations in support of Cybersecurity Division processes and work instructions. Communicate with all levels of management within the Cybersecurity Division and function at the strategic level with upper management and across various divisions within the Cybersecurity Division. Create and maintain Cybersecurity Division communication plans, processes, work instructions supporting the execution of change, manage feedback loops within and across program teams. Manage the Cybersecurity Division document approval process until the document is published for use. Provide gap analyses between cyber services current vs. future state conditions. Conduct Cybersecurity Division reviews, ensuring process gaps are remediated.
6.14.4 Subtask 4 - Process Improvement.
The contractor shall evaluate existing Cybersecurity Division processes and procedures and recommend changes to improve or enhance performance and maintainability. Implement a Cybersecurity Division Quality Assurance Program with quality controls to ensure all aspects of the Cybersecurity Division ITSM Program is continuously monitored for process improvement. Identify, refine, report and monitor Cybersecurity Division performance measurements to include Key Performance Indicators and Critical Success Factors.
6.14.5 Subtask 5 - Metrics Management Analysis.
The contractor shall provide compliance metrics and trend analysis, coordinate with stakeholders for feedback on outstanding issues, track status and prepare reports and briefings. Collect, analyze, report and archive cybersecurity metrics in support of Cybersecurity Division initiatives and requirements. Provide metrics analysis and insight into Cybersecurity Division resource performance to include people, processes, and technology to improve Cybersecurity Division efficiency and effectiveness goals and/or objectives.
6.14.6 Subtask 6 - Metrics Management Improvement.
The contractor shall provide existing and/or recommend new processes for developing and documenting metrics, ensuring relevance and efficacy to include identification of data sources, baseline measurements, fiscal year targets, performance thresholds, metric measurement methods and analytic tools.
Deliverables:
· Daily/weekly/monthly/quarterly/annually Orders reports Process Gap analysis
· Updated Security Metric Analysis Procedures Weekly/monthly/quarterly/annually metrics and trending analysis reports
· Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
SOW
Task# Deliverable Title Format Due Date Distribution/Copies Frequency and Remarks
| 6.14 |
| Orders Reports |
| Government Provided Template |
| Schedule release dates provided by the Government |
| Standard Distribution |
| Up to 365 per year typically daily |
| 6.14 |
| Gap analysis |
| Government Provided Template |
| One – five business days after request |
| Standard Distribution |
| Up to 104 per year typically monthly |
| 6.14 |
| Updated Security Metric Analysis Procedures |
| Government Provided Template |
| One – five business days after request |
| Standard Distribution |
| Up to 600 per year typically monthly |
| 6.14 |
| Metrics and trending |
analysis reports
| Government Provided Template |
| Schedule release dates provided by the Government |
| Standard Distribution |
| Up to 416 per year typically weekly |
*Standard Distribution: One copy of the transmittal letter without the deliverable to the Contracting Officer; one copy of the transmittal letter with the deliverable to the Primary COR.
6.15 Task 15 -Strategic Partner Integration (Optional).
The contractor shall have access to Secret Classified Information through SIPRNet.
6.15.1 Subtask 1 – Planning.
The contractor shall, analyze, and solicit Cybersecurity Division feedback for current and planned programs and/or projects to determine security risks and technical feasibility, to include implementation and sustainment resource requirements.
Provide security engineering and integration services to include Service Request Form (SRF) and Letter Estimate evaluations for Strategic Partner programs. Ensure information system programs are registered in DoD’s mandated program registration system during SRF review process.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .