A. Statment of Objectives.pdf
PDF 422 KB Posted
- Attached to
- HID ActivID Professional Services Federal contract opportunity
- Solicitation number
- 89603023Q0010
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 89603023Q0010_1.pdf | ||
| A. BRAND NAME JUSTIFICATION.pdf | ||
| 89603023Q0010.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CUI//PROCURE
Federal Energy Regulatory Commission
(FERC)
Statement of Objective for
HID Global ActivID Credentialing Management System Server
Migration and Maintenance
Contents Purpose
Scope
Background
Period and Place of Performance
Performance Objectives
Hardware, Software, Licenses, Installation Service, Maintenance and Support
Hardware and software requirement
Operating Constraints
Deliverables
Purpose The Federal Energy Regulatory Commission (FERC) seeks to migrate its existing HID Global ActivID Credentialing Management System (CMS). Current CMS needs immediate migration from current end of life HID Global ActivID CMS appliance located at the headquarters facility at 888 First Street NE, Washington, DC 20426.
The Offeror would need to provide software, professional installation, servicing and full turn-key maintenance support to ensure the CMS is operating at 100% of its capabilities. The offeror will be responsible for professionally installing, servicing and updating/maintaining an HID Global CMS product that meets FERC’s needs for Logical Access to our IT Network and Elevated Access Rights for IT System Administrators and Physical Access requirements for personnel. PIV Cards will be used by admins for meeting Homeland Security Presidential Directive 12: Policy for a Common Identification Standard for Federal Employees and Contractors.
Scope FERC requires the HID Global ActivID CMS to have the capability to issue and manage Personal Identity Verification (PIV) cards and PIV-Interoperable cards (HID Global Crescendo Smart Cards) in compliance with FIPS-201. The CMS Administrative Services should incorporate issuance, device life cycle management, PIN management, certificate management, One-Time Password (OTP) management, user management, and configuration. FERC requires the ability to manage our authentication devices, data, and digital credentials (including PKI certificates) through the entire lifecycle. FERC requires the ability to update user access in real-time, without additional costs or resources.
The Offeror must be able to:
1. Integrate into our current Personnel Access Control System and IT network.
2. Migrate the existing ActiveID configurations to new managed appliance
3. Configure FIPS 140-2 ciphers with TLSv1.2 and AES128 bit
4. Configure Active Directory authentication with Role Based Access Control with specific AD group
5. Implementation, testing, and migration of all services and components
6. Provide executable option to all the tracking of issuance and use of temporary cards
7. Provide up to an additional 300 licenses
Background The Federal Energy Regulatory Commission (FERC) is an independent agency that regulates the transmission and wholesale sale of electricity and natural gas, and the transportation of oil by pipeline.
FERC reviews proposals to build interstate natural gas pipelines, natural gas storage projects, and Liquefied Natural Gas (LNG) terminals, in addition to licensing nonfederal hydropower projects.
Period and Place of Performance Period: 5 years of total life cycle Base: 1 years Option: 4 single year options
Place: FERC Data Center and 1D Badging Office at 888 First Street NE, Washington DC 20426.
Performance Objectives Current configuration is represented below:
FERCs current operations receive access card for primary user via FedIDcard.gov USACCESS program.
Temporary access cards typically obtained alternate credentials or stop-gap until receipt of FedIDCard, via secondary internal CA infrastructure via the exhausted CM1000 - ACTIVID CMS Appliance 1000 with HSM and 350 HID as secondary credential cards. Credentials are used for physical access, digital signing, and access to encrypted data on hard drives, documents and emails
FERC OnPrem CA Infrastructure
PKI solution with Microsoft Certificate services and ncipher HSM. PKI environment includes 3 tier CA infrastructure with 2 Offline CAs (Root and Policy) and one Online Issuing CA
Secondary credential card’s primary purpose is to mitigate employee downtime should a user forget, lose, or damage their PIV cards or if a longer access terms are required. Cards are temporary with no photo on the card and required to be returned upon receipt of the new primary access card (government PIV credential). The secondary credential shall afford the user the same privileges as the primary to include physical access, logical access and elevated administrative rights.
Hardware, Software, Licenses, Installation Service, Maintenance and Support Offeror must provide hardware, software, licenses, installation service, maintenance and support for the CMS appliance and products as defined in the table below. Offeror may provide a physical appliance or virtual appliance to meet security needs. Detailed technical specifications are required to determine.
Offeror shall provide solution, related equipment and services to include system components, cables, design and installation services and support for 5 years. Offeror shall possess all capabilities or providing trained personnel, consultancy advice, understanding of various equipment, activation of licenses, different authentication technologies to supply product and perform services as specified under this RFQ.
Quantity Part Number Description
300 CMSXXXXLCM4 ANNUAL ACTIVID CMS
PER USER STANDARD
SUPPORT &
MAINTENANCE
5 ACCXXXXLCM5 ANNUAL HID ACTIVID
ACTIVCLIENT PER USER
LICENSE
Optional up to 300 CMSXXXXLC HID ACTIVID CMS PER
USER LICENSE
Hardware and software requirement
The OFFEROR must be an authorized HID reseller/partner
Card Management System
CMS must be able to:
1. Card Issuance
2. Card Update
3. Requests
4. Credential maintenance
5. PIN Reset
6. Recycle cards
System infrastructure
Provide the following:
7. FedRAMP and or FISMA / NIST compliance
8. NIST 800-53 and 800-32 standards
9. Validated at FIPS 140-2 level 3 or higher
10. Provide an itemized list of the required services: hardware, software, licenses and customization, implementation, operations/management and training components of its proposed solution. Any items providing additional functionalities should be included in a separate table
11. Compatible with USGCB compliant Windows 7 and 10 Enterprise workstations
12. Compatible with Microsoft Active Directory
13. Able to issue certificates for user authentication
Optional Card Use Tracking
1. Provide easily understood reports
2. Allow reports to be ran as needed by FERC staff
3. Provided names and permissions of all issued cards by card number
4. Provide card usage information by card number
Operating Constraints Must meet the validation requirements under Federal Information Processing Standard (FIPS) 140-2. A level 3 assurance is required in order to meet the dual security control requirements the certificate architecture is subject to.
Deliverables Offeror shall provide a written Statement of Work that addresses how Performance Objectives will be accomplished and how FERC will assess work performance against identified Performance Objects. The Offeror must provide Smartcard Activation capability and custom software that installs on any Federal Desktop Compliant Configuration (FDCC) workstation.
The Offeror must provide the required deliverables as outlined below in native formats such as MS Word, Excel or Visio format.
Deliverable Completion Date Provide a system design document.
The Offeror must provide support for Security team required documentation for obtaining internal ATO
Supply necessary functional SOPs for day 2 operations
Site Survey Acceptance Documentation Requirements document Migration plan Testing Plan and Test Cases Acceptance Testing Procedures (ATP) Pre-Deployment Guide (PDG) Low-Level Design (LLD) System Design Document (based on FERC’s requirements)
As-Built Documentation Standard Operating Procedures The Offeror must configure and complete within 30 calendar days from issuing a Purchase Order.
Please note Deliverable table should be included in final proposal with completion dates.
| Purpose |
| Scope |
| Background |
| Period and Place of Performance |
| Performance Objectives |
| Hardware, Software, Licenses, Installation Service, Maintenance and Support |
| Hardware and software requirement |
| Operating Constraints |
| Deliverables |
File details come from the government source that posted it. Updated .