RFP-9351-16-R-0400_MSSP.pdf
PDF 427 KB Posted
- Attached to
- Managed Security Service Provider Federal contract opportunity
- Solicitation number
- 9531-16-R-0400
- Issued by
- United States Holocaust Memorial Museum
About this file
This is USHMM's complete solicitation for a Managed Security Service Provider (MSSP)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP-9351-16-R-0400_MSSP_Q A.pdf | ||
| RFP-9531-16-R-0400-RequirementsMatrix_ATTA.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
USHMM RFP-9531-16-R-0400 Page 1 of 17 Managed Security Service Provider
RFP-9531-16-R-0400
Solicitation for
Managed Security Service Provider
1 BACKGROUND & GOALS
1.1 A living memorial to the Holocaust, the United States Holocaust Memorial Museum
(hereafter referred to as “USHMM” or “Museum”) is America’s national institution for the documentation, study and interpretation of Holocaust history and serves as this country’s memorial to the millions of people murdered during the Holocaust. USHMM inspires citizens and leaders worldwide to confront hatred, prevent genocide, and promote human dignity. As an independent establishment of the U.S. Government with gift acceptance authority, federal support guarantees the Museum’s permanence, while its far-reaching educational programs and global impact are made possible by donors, members, educators, universities, leaders in governments and the public, just to name a few.
1.2 Approximately 1.7 million people visit the Museum each year, with another 13 million visiting USHMM online The United States Holocaust Memorial Museum has numerous externally-facing websites, significant databases of historical documents and information, a digital collection of Holocaust artifacts, substantial IT infrastructure supporting the Museum exhibitions and operations, and the full range of business support systems. The Museum is a high-profile participant in world-wide Holocaust education, contemporary genocide prevention efforts, and other politically-sensitive activities.
1.3 System Information. Confidential elements of the Museum’s security environment such as make and model of the devices, base URL information, web application details, DNS server and specific IP addresses are not given here. More detailed information will be provided to
Offerors who have been determined to meet minimum requirements and may be made subject to signing of a nondisclosure agreement. For purposes of this solicitation, the following information is the only information that can initially be provided:
(1) The Museum currently has approximately 500 users, 800 workstations and 150 servers consisting of the following platforms:
(a) Mixed environment of Unix, Apple and Windows servers and workstations
(b) Firewall systems with IPS and IDS
(c) Common industry routing and switching equipment
(d) Virtualization and a host of enterprise applications
(2) All facilities with major network resources are located in Washington, DC within a radius of ten miles. There are five remote offices with fewer than 20 employees each, all with dedicated VPN tunnels back to DC in a spoke and hub configuration.
(3) Museum has to date deployed LogRhythm for log correlation and SEIM, but
USHMM RFP-9531-16-R-0400 Page 2 of 17 Managed Security Service Provider doesn’t have the staff to meet desired monitoring coverage. The Museum is also beginning a transition to Infrastructure as a Service (IAAS) for its servers and storage and currently employs software as a service solution providers as well as other cloud providers for some of its operational needs.
1.4 Through this solicitation, USHMM is seeking a Managed Security Service Provider
(MSSP) who can provide the security services listed below in paragraph 2.1 (the
"Services"), and potentially, the optional services listed in paragraph 2.2. Our goal is to ensure the Museum’s cyber-defense layers are monitored for attacks or malicious activity and its critical IT assets are protected from such activities.
2 SCOPE OF WORK. In the delivery of the Services, Contractor shall develop, implement, and deliver the requirements detailed herein and otherwise as described in
Contractor's Proposal. Although requirements are further described below and throughout this
RFP, principal performance to be provided by Contractor shall address:
2.1 Required Services.
(1) Log correlation and analysis
(2) 24/7 firewall monitoring and alerting - All monitoring should be performed real time, include both perimeter firewalls and multiple security zones, and be performed from centralized and physically secure operations centers (staff monitoring from any other locations such as work-from-home situations will not be considered due to security risk).
(3) Placement and management of IDS & IPS solution
(4) Incident response assistance, planning & testing
(5) Active real time dashboard; delivered & ad-hoc reporting
(6) 24/7 support and call center access
(7) Provide knowledge transfer and training and maintain and grow the solution as the threat landscape evolves
2.2 Optional Services.
(1) End point collection and detection software/service
(2) Firewall co-management attack prevention
(3) Domain controller / LDAP / Active Directory monitoring
(4) DNS monitoring
(5) Forensic services on an as-needed basis
(6) Security reviews on as as-needed basis
(7) Other optional MSSP services as described in Contractor's Proposal
2.3 General Requirements - Contractor shall submit all Contractor work product to USHMM in a timely manner, and where applicable in accordance with agreed schedules, timetables, production benchmarks, and deadlines. Contractor deliverables shall remain subject to the highest industry standards for accuracy and utility and USHMM’s satisfaction, with prior review and acceptance or rejection ultimately left to USHMM’s sole discretion.
USHMM RFP-9531-16-R-0400 Page 3 of 17 Managed Security Service Provider
2.4 Contractor Representatives - All Contractor personnel are provided below, specifically identified as “Key Personnel” or else as generally defined to meet the minimum qualifications provided below. (Offerors shall provide this information in their technical proposal, and such information shall be treated as though reproduced below.)
(1) General. The following person shall be contracted in the event of award for prompt Contract notification and administration concerning specifications, schedules, and other necessary Contract matters:
(Name)____________________________________
(Title)____________________________________
(Street Address)____________________________
(City, State, Zip)____________________________
(Telephone & Facsimile No.)__________________
(E-mail address)____________________________
(2) Key Personnel & Subcontractors
● Contractor shall include the subcontractor(s) and key personnel to be assigned under this Contract in the format provided below. Offerors shall provide this information in their technical proposal, and such list shall be treated as though reproduced below.
NAME LABOR CATEGORIES
● Contractor shall not remove the Key Personnel assigned to this project without the consent of Museum. Contractor also will not remove such Key Personnel until he/she is replaced with a person/firm of equal or higher qualifications.
● Contractor shall not enter into any subcontracts other than those identified above for any of the work under this Contract without obtaining the prior written approval of the CO.
(3) Qualifications of Contractor Personnel and Minimum Experience
● Contractor shall ensure that staff and/or subcontractors dedicated to this project other than those Key Personnel defined above have the skills and experience level as described in Contractor’s Proposal. The service categories provided by the
Contractor in performance of this Contract shall embrace all critical services described in this contract. All Contractor personnel assigned to this Contract are subject to Museum review in accordance with the provided level of qualifications.
USHMM RFP-9531-16-R-0400 Page 4 of 17 Managed Security Service Provider
● Museum shall reserve the right to recommend dismissal of a Contractor’s employee or subcontractor whose performance is detrimental to the satisfactory completion of contractual obligations.
3 CONTRACT TERMS & CONDITIONS
3.1 General. The terms and conditions of Contractor's GSA-schedule # ________________ shall apply to the awarded contract, if applicable. Otherwise, USHMM shall apply the “Terms and Conditions Applicable to Non-GSA Schedule Contracts” as separately attached to this RFP.
3.2 Travel and Expense. All travel shall be subject to Museum's prior review and approval.
Travel expenses are to be reimbursed according to GSA travel guidelines and the Federal Travel
Regulations (FTR).
3.3 Invoices
(1) Contractor shall submit a single invoice(s) to the COR upon satisfactory completion of the work or otherwise in a manner consistent with Contractor's Proposal for completed deliverables and services received and accepted by the COR To facilitate prompt payment, invoices shall be submitted in English to the United States Holocaust Memorial
Museum, Attn: Accounts Payable Division by e-mail to AccountsPayable@ushmm.org, by fax to (202) 314-0375 and/or if by mail to 100 Raoul Wallenberg Place, SW, Washington, DC
20024-2150 with a copy submitted to the COR. To constitute a proper invoice, the invoices must include the following information and/or attached documentation:
● Name of Business Concern and invoice date
● Contract Number or other authorization for performance of service
● Description, price, and quantity of services delivered or rendered
● Name, title, phone number, and complete mailing address of responsible official to whom payment is to be sent.
(2) Withholding - USHMM shall pay Contractor upon receipt and approval of completed deliverables and in accordance with the schedule provided in Contractor's Proposal.
(3) Nonpayment for Additional Work - Any additional services or services representing a change to work specified herein or as defined in the applicable task order performed by Contractor, either at Contractor’s own volition or at the request of an individual other than a duly appointed CO except as may be explicitly authorized in this Contract are not authorized and will not be paid. Only a duly appointed CO is authorized to change the specifications, terms, and conditions in this Contract. Any such change shall be through a written amendment(s) or modification(s) to this Contract issued by the CO.
(4) Annual Representations and Certifications - Offerors certify that they have completed the annual representations and certifications electronically via the Online mailto:AccountsPayable@ushmm.org
USHMM RFP-9531-16-R-0400 Page 5 of 17 Managed Security Service Provider
Representations and Certifications Application (ORCA) website at http://orca.bpn.gov. After reviewing the ORCA database information, Offerors verify by submission of their proposal and incorporation in their proposal by reference as of the date of the proposal that the representations and certifications currently posted electronically have been entered or updated within the last 12 months, are current, accurate, complete, and applicable to this RFP.
4 RFP INSTRUCTIONS
4.1 FAR 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE
(FEB 1998, cited verbatim). This solicitation incorporates one or more solicitation provisions by reference, with the same force and effect as if they were given in full text. Upon request, the
Contracting Officer will make their full text available. The Offeror is cautioned that the listed provisions may include blocks that must be completed by the Offeror and submitted with its quotation or offer. In lieu of submitting the full text of those provisions, the Offeror may identify the provision by paragraph identifier and provide the appropriate information with its quotation or offer. Also, the full text of a solicitation provision may be accessed electronically at this/these address(es): <www.acquisition.gov/far>.
4.2 FAR 52.215-1 INSTRUCTIONS TO OFFERORS--COMPETITIVE ACQUISITION (JAN
2004) (Reference 15.209)
4.3 FAR 52.216-1 TYPE OF CONTRACT (APR 1984) (Reference 16.105). USHMM contemplates award of a Firm Fixed Price contract resulting from this solicitation. The initial term of the service contract will be one year with four one-year annual renewal options.
4.4 FAR 52.216-25 CONTRACT DEFINITIZATION (OCT 1997, redacted albeit without revision)
(b) The anticipated schedule for definitizing this contract is:
June 25, 2016 RFP Released
July 9, 2016, 5:00 PM ET Q&A Period Closed
July 21, 2016, 5:00 PM ET Proposals Due August 30, 2016 Contract Awarded
4.5 PROPOSAL SUBMISSION REQUIRED IN ELECTRONIC FORMAT
(1) The only acceptable evidence for establishing the time of receipt at Museum shall be the USHMM time/date stamp.
(2) Offerors shall submit their full proposal (Technical and Price as separate, distinct, and individuated files) in soft (electronic) copies, signed by Offeror's authorized signatory, and addressed to: <Bfalk@ushmm.org>
USHMM RFP-9531-16-R-0400 Page 6 of 17 Managed Security Service Provider
Subject: RFP-9531-16-R-0400 – Proposal for Managed Security Service Provider
(3) USHMM expressly disclaims and neither guarantees nor warrants for e-mail security, the legibility of electronic format(s), and/or the corresponding accuracy of any printed submission to its electronic version.
(4) Offeror certifies that all of its electronic submissions have been verified as free of viruses using virus-check software that is standard in the industry and current to the present calendar month and year.
5 PROPOSAL CONTENT
5.1 Technical Proposal. The Technical Proposal should demonstrate that the Offeror clearly understands the requirements and is proposing services built around core capability with the requisite experience in each case essential to successful accomplishment. [Other than where expressly indicated, USHMM has not placed a word or page limit on responses to this RFP section 5.1 et seq., but notes that a bulleted, enumerated, or itemized list consistent with the format provided in the RFP is the preferred means of communication.] The Technical Proposal shall include:
(1) Responsiveness Requirements Matrix. The Museum strives to align security processes and procedures with the National Institute of Standards and Technology (NIST)
Security and Privacy Controls for Federal Information Systems and Organizations (Special
Publication 800-53) and best practices for managing risk outlined in the NIST Cybersecurity
Framework. Bid candidates should be able to exhibit their organization’s service offering and supporting activities demonstrate alignment with the Cybersecurity Framework Core functions
(Identify, Protect, Detect, Respond and Recover). Offerors shall complete and return the matrix provided as Attachment A for the proposed Membership Direct Response Services, identifying by checkbox whether their proposal addresses the stated requirements in the RFP and if so, to what extent, in each case indicating the page/paragraph location in their proposal where such requirements have been addressed, explained, and/or elaborated upon.
(2) Technical Brief. This shall be a narrative description of the Offeror’s proposed solution, delineated in a manner consistent with Museum's stated functional requirements matrix albeit as concise as possible (see 5.1(1), above). This section shall not exceed 1500 words, although USHMM will discount captions of reasonable illustrations and chart labels). The entirety will thereby encompass:
(a) Understanding of the Requirements – Offerors shall hereby confirm their understanding of the project scope and objectives, affirming their intent to completely fulfill all stated project requirements, and noting and justifying exceptions where relevant. Offerors may use or reference to the narrative description(s) in the matrix where necessary for clarification;
USHMM RFP-9531-16-R-0400 Page 7 of 17 Managed Security Service Provider
(b) Explanation of Proposed Methodology – A narrative description of the
Offeror’s proposed methodology, including without limitation discovery and installation, implementation, and engineering documentation [as concise as possible and in a manner consistent with USHMM's stated requirements, excluding illustrations which shall not count against the page limit, max. 600 words];
(c) Detailed Performance Schedule – Offerors shall complete and incorporate their proposed project outline, including timeline and responsibilities for implementation, with proposed delivery dates for all milestone deliverables, construction milestones, and
USHMM reviews/approvals (inclusion of GANTT chart preferred); and
(d) Service Level Agreement – Offerors should include a clearly defined SLA describing their proposed service guarantee, outage compensations including support infrastructure to handle USHMM 24/7 access, and up time requirements.
(e) Alternate Approaches (if applicable) - With the exception of the perimeter firewall systems, USHMM will consider alternative proposals to existing monitoring agents -- including vendor supplied sensors and appliances as required to meet technical and functional requirements -- in zones as described in a separate document ("Devices in
Scope," provided upon request).
(3) Company Profile. This shall be a summary and representation of Offeror’s general qualifications to fulfill the statement of work and provide the Services: a narrative description of
Offeror’s corporate history and capability delineated in a manner consistent with Museum's stated functional requirements matrix albeit as concise as possible (see 5.1(1), above). This section shall not exceed 750 words, although USHMM will discount captions of reasonable illustrations and chart labels).
(4) Past Performance. This shall be a narrative description and delineated in a manner consistent with Museum's stated functional requirements matrix, albeit as concise as possible (see 5.1(1), above). This section shall not exceed 1,000 words, although USHMM will discount captions of reasonable illustrations and chart labels. With respect to references and the chronological history, a bulleted, enumerated, or itemized list consistent with the format provided here is the preferred means of communication.
(a) Case Studies: Offerors should address the questions provided in the matrix.
(b) References: A description of five (5) clients served in the last five (5) years. The contracts should be relevant (similar in size, complexity, and nature) to the service type for which the Offeror is submitting a proposal. Offerors shall demonstrate relevance as well as professionalism by providing verifiable evidence of past experience in all qualification requirements (as provided herein). Information provided shall include:
USHMM RFP-9531-16-R-0400 Page 8 of 17 Managed Security Service Provider
(i) Contract Number/Identifier (if applicable);
(ii) Contract Type (i.e., firm fixed (monthly retainer) price, time and materials, etc.);
(iii) Awarded price/cost and final or projected final price/cost;
(iv) Period of Performance (dates of start and completion of work).
(v) A current point of contact in the contracting client – name, address, e-mail, and telephone number. If the work was performed as a subcontractor, also provide the name of the prime contractor and point of contact (name, address, e-mail, and telephone number).
(vi) Description of work performed and location (excluding excerpts or samples from prior engagements which shall not count against the word limit, max. 200 words). In addition to illustrative screen shots and/or work samples, Offerors should provide information on problems encountered on the contracts and subcontracts identified, and corrective actions taken to resolve those problems. For contracts which did not/do not meet original cost, schedule or performance requirements provide a brief explanation of the reason(s) for the shortcomings and any corrective actions taken to avoid recurrence.
(c) Chronological List of Clients: Provide a listing, in chronological order, of all clients served within the last 5 years and through to current engagements.
Please include:
(i) start date and if applicable, end date (or an indication if relationship is ongoing as of the date of proposal submission);
(ii) a short description of services your company is providing per client;
and
(iii) a listing of clients added to company roster within the last 4-6 months.
(5) Account Support & Staffing Plan [a bulleted, enumerated, or itemized list consistent with the format provided here is the preferred means of communication] - This is
Offeror’s proposed contract team, demonstrating security industry expertise related to Museum security platforms and the federal government. Subfactors that will be evaluated are Key
Personnel and subcontractors, affiliates, or strategic partners (if applicable). In this section of their respective proposals, Offerors shall:
(a) Provide a list of personnel designated as “Key” in the performance of this
Contract, including name, title, organization, full or part-time, and whether they are a salaried employee of the organization, current or planned employee, subcontractor, subject matter expert, or consultant. Key personnel must include, at minimum, the proposed project manager for the USHMM account and (if a different person) USHMM’s principal point of contact. Provide the estimated percentage of time each Key Personnel will be assigned to the USHMM account and a description of the proposed role and responsibilities of the Key Personnel to the USHMM account (See, e.g., section 2.4(2), above, “Key Personnel & Subcontractors”).
USHMM RFP-9531-16-R-0400 Page 9 of 17 Managed Security Service Provider
(b) Submit resumes for Key Personnel which demonstrate the level of competency necessary to successfully complete the work defined herein. Resumes should be formatted as follows:
(i) Name and title
(ii) A brief description of proposed duties and responsibilities of the person for this contract and how the individual fits into the overall organization.
(iii) Relevant work experience for the responsibilities described in (2) above demonstrated by: employment history (including length of employ with Offeror), present and previous employers: dates of employment, job title(s) and description of the specific duties for each position.
(iv) Education including educational institutions attended, dates, and degrees or certificates obtained.
(v) Professional awards or associations related to the current position.
(vi) Training related to current position and experience, especially in mature and emerging technologies. Do not include information that is not relevant to the person’s designated role in this project.
(c) Provide a list of general staffing in the performance of this Contract, including the extent to which they are to be drawn from salaried employees of the organization, current or planned employees, subcontractors, subject matter experts, or outside consultants. Provide the estimated percentage of time such persons will staff the
USHMM account as an ensemble and describe their respective roles and responsibilities to the USHMM account.
(d) If applicable, describe the subcontract management system to be used under this Contract if significant subcontracting is contemplated. Particular emphasis should be placed on procedures for source selection and how performance status is determined, assessed, and projected through subcontract completion. Letters of commitment from major subcontractors must be provided. Define who reports to whom, when and in what form. If a joint venture, indicate if these firms have been associated in the past, or if it is contemplated for this project only.
5.2 Business Proposal. The following shall be provided within Offeror's Business Proposal:
(1) Price.
(a) Firm, Fixed Price (monthly retainer) - Fully itemized in a manner appropriate to Offeror's proposed solution (as an itemized rate schedule showing the estimated hours and, if possible, fully-loaded hourly rates of each team member assisting in delivery of all Required Services listed at RFP paragraph 2.1, et seq. and any included
Optional Services listed at RFP paragraph 2.2, et seq.);
(b) Anticipated a la carte expenses - on a fixed price, flat rate or time and materials basis, to include any itemized Optional Services not prepackaged with the total
USHMM RFP-9531-16-R-0400 Page 10 of 17 Managed Security Service Provider
Service package described in 5.2(1)(a) above. Offerors must clearly distinguish the services that are included in their managed services package from those being priced separately; and
(c) Any other costs not cited above.
(2) Proposed Payment Schedule. Consistent with section 3.3 ("Invoices") et seq., above, this shall be Offeror's proposed payment schedule;
(3) Contract Administration Information. Offerors shall complete all applicable blanks in this RFP and by signature affirm all acceptable contractual language;
(4) Contract Exceptions. Offerors shall here specify their exception(s) (if any) to terms and conditions contained in this RFP in each instance citing the applicable section, clause, paragraph number, and page of the solicitation that they address;
(5) Contract Inclusions. Offerors shall here specify their inclusion(s) (if any) to the standard terms and conditions contained in this RFP, including a short explanation or justification for the supplemental or alternate clause they seek to have incorporated;
(6) Assumptions. Offerors shall here specify and explain any assumptions made in preparing their proposals.
5.3 Negotiations, Oral Presentations, & Proposal Revisions. USHMM expects that following a preliminary determination of competitiveness pursuant to RFP paragraph 6.1(2) et al., USHMM will request selected finalists to address questions specific to their respective proposals. USHMM reserves the right to enter into negotiations with any or all of the Offerors as it deems to be in the best interest of USHMM, to request oral presentations from one or more
Offerors (in which case Museum shall make oral presentation procedures available in advance to selected Offeror(s)), and to request any or all Offerors to clarify or modify the terms and conditions specified in their proposals and resubmit such clarifications or modifications as a
“Revised Proposal.”
6 EVALUATION
6.1 Phases. USHMM shall conduct its evaluation in two phases, trimming the proposal pool in each phase as appropriate.
(1) Phase One - Overall Competitiveness. This shall be a competitive range determination in which each member of USHMM’s evaluation panel is accorded equal weight in his or her rating of proposals, applying the following criteria against the information requested in section 5 of this RFP, first individually and independently, and then meeting collectively to establish consensus against a competitive range (all proposals to be treated in a uniform manner which may or may not include consideration of pricing). Subcriteria are generally treated as
USHMM RFP-9531-16-R-0400 Page 11 of 17 Managed Security Service Provider equivalent and not necessarily prioritized in the order in which they appear. USHMM intends, but is not obligated, to use a qualitative evaluation method for its review.
(3) Phase Two - Discussions/Negotiations. Following resolution of USHMM questions (if any), USHMM shall award a contract to the Offeror whose entire (revised) proposal thereafter is determined to present the best overall value to USHMM when technical and business factors are collectively taken into account. USHMM reserves the right to request oral presentations/interviews, and irrespective of this, in all cases to be the sole judge determining whether an Offeror meets the evaluation criteria.
6.2 Technical Proposal Evaluation Factors. USHMM will assess Offerors' Technical
Proposal as evidenced by Offeror's commitment to meeting all the Museum's requirements and specifications as stated herein and capacity to complete and deliver the Services. This review shall consider all of the following factors:
(1) Technical Brief. Museum will assess Offerors' understanding and fulfillment of the requirements -- the fit of the proposed Services, its completeness and appropriateness in meeting the Museum's requirements and specifications as stated herein.
(2) Company Profile & Past Performance. USHMM will evaluate Offerors on demonstrated corporate capability and past performance for work similar in nature and complexity to this requirement, respectively, using the following specific factors for each, as appropriate. USHMM will focus on information that demonstrates quality of performance relative to the size and complexity of the procurement under consideration. To this extent, USHMM may use information obtained from the Offeror, from calling references, and from sources other than those provided by the Offeror in search of evidence to demonstrate the quality of services, customer satisfaction, timeliness of performance, business relations, cost control, and relative projected performance risk. Ultimately, USHMM expects the successful Offeror to demonstrate the following capabilities (note that these subcriteria are not necessarily prioritized in the order in which they appear):
(a) the level of experience as evidenced by successful implementation of projects in other similar organizations (including expertise in providing similar services to similar size or larger agencies or organizations);
(b) demonstrable evidence of excellence in the delivery of MSSP services;
(c) proof of current SSAE-16 SOC 2, Type 2 audit report and FedRamp certification;
(d) ability to work with third party contractors serving in clients' security ecosystem;
(e) viability (an assessment which may be based in part on independent assessment sources used regularly by Museum); and
(f) overall impression of prior performance (e.g., quality of client list, quality of services, client satisfaction, timeliness of performance, business relations, and cost control).
USHMM RFP-9531-16-R-0400 Page 12 of 17 Managed Security Service Provider
(3) Account Support & Staffing Plan
(a) The stability and cohesion of the proposed account support team (tasked to this project as Key Personnel) as evidenced by quantity and recency of projects jointly fulfilled.
(b) The level of experience of individual staff tasked to this project as Key
Personnel as evidenced by experience, education, and certification; and
(c) The relevance of experience of staff tasked to this project as Key
Personnel as evidenced by prior project performance.
6.3 Price. Museum shall evaluate pricing consistently with inverse correlation to cost such that the lowest price yields the highest rating. USHMM will consider both nonrecurring initial costs and recurring annual costs.
(1) Since the evaluation of pricing will represent a portion of the total evaluation, it is possible that an Offeror might not be selected for award because of unreasonable, unrealistic, incomplete, inaccurate, or noncurrent cost proposal information. Offerors are solely responsible for assuring that pricing information is provided in a manner that allows USHMM to make such a determination.
(2) Each Offeror’s cost information will be evaluated for realism, completeness, and reasonableness to determine the Offeror’s understanding of the work and ability to perform the contract. Realism is evaluated by assessing the compatibility of proposed costs with the technical/management/qualifications of the personnel. Completeness is evaluated by assessing the level of detail the Offeror provides in cost information for all requirements. Reasonableness is evaluated by assessing the acceptability of the Offeror’s methodology used in developing the cost. The existence of adequate cost competition may support a determination of reasonableness.
This includes both original submissions and final proposal revisions (if requested).
6.4 Weight. The Technical Proposal and pricing are considered equally important and shall be given equivalent weight. Accordingly, USHMM shall award a contract to the Offeror whose proposal represents the best value to the Museum.
6.5 Complete Information & Contractual Compliance
(1) Failure to furnish complete information requested in the RFP may cause the
Offeror to be deemed unacceptable and be removed from further consideration.
(2) Offers are solicited on an "all or none" basis and failure to submit offers for all line items listed may be cause for rejection of the offer.
(3) Functional requirements include items desired by USHMM and are meant to be comprehensive but not all inclusive. Thus, if USHMM may have omitted a key operational
USHMM RFP-9531-16-R-0400 Page 13 of 17 Managed Security Service Provider component of a required system that would normally be expected to be included, the Offeror bears the burden of demonstrating the omitted capability.
(4) Offerors are hereby on notice that substantive and material and/or multitudinous exceptions taken to USHMM’s proposed contract language may result in a reduced Business
Proposal rating.
USHMM RFP-9531-16-R-0400 Page 14 of 17 Managed Security Service Provider
ATTACHMENT A
Responsiveness Requirements Matrix
ITEM EVIDENCE SOUGHT BY USHMM (RESPONSIVENESS DETERMINATION)
LOCATION IN
PROPOSAL
5.1(2)(i) Protect - Describe your ability to:
[1]
Provide centralized logging and audit trails, and aggregate and correlate all security event information.
[2]
Monitor, detect and record activity from both in-bound and out-bound traffic that exhibits unusual or malicious behavior and identify attacks from known as well as unknown sources.
[3] Provide a secure customer portal for direct access to data and reporting.
[4] Provide a secure and encrypted channel for all monitoring activities.
5.1(2)(i) Detect - Describe your ability to:
[1] Monitor and detect malicious activity on a 24x7 basis.
[2] Identify potential sources of data leakage.
[3]
How do you manage false positives and tune signatures? What metrics do you offer to support the effectiveness of the IDS/IPS devices you manage?
5.1(2)(i) Respond - Describe:
[1]
Your ability to alert designated Museum staff of any suspicious activity that may lead to a security breach and/or provide rapid response to stop or prevent attacks while allowing acceptable traffic that supports Museum’s Internet-based business initiatives.
[2]
The type of notification and communication included as part of your Managed Security
Services. Please include the timing associated with each type of notification.
[3]
The manner in which your company prioritizes client notification based on potential event impact.
[4]
How you assure timely OS, firmware, patch, and signature upgrades/updates of all monitoring agents and devices under scope. What is your procedure for performing these changes? Include a description of quality assurance measures.
[5]
Your ability to provide a scalable platform that allows for modification and additional integration with existing network architecture.
Managed Security Services Requirements - Technical Brief (Offeror's methodology and strategy for implementing the solution)
This solicitation seeks proposals to provide the Museum with a Managed Security Services solution. Offerors should propose the most cost-efficient and manageable solution along with a timeline for project completion.
Offerors should submit a proposal that outlines technical and functional offerings along with evidence of meeting requirements that include:
USHMM RFP 9531-16-R-0400 page A1 of 3 Managed Security Service Provider
PROPOSAL
Managed Security Services Requirements - Technical Brief (Offeror's methodology and strategy for implementing the solution)
5.1(2)(i) Recover - Describe:
[1]
Your ability to provide prompt corrective recommendations during an event and assist in investigations and forensic analysis of data.
[2]
Your ability to provide access to support engineers 24x7 with the option to request onsite resources should an incident not be resolvable remotely.
[3]
Your ability to routinely test incident response capabilities and perform exercises with
Museum staff to validate process and procedures.
[4] Your ability to retain log data for an extended time frame or a period mutually agreed upon
[5] The lifecycle of a security event, from initial occurrence to closure.
5.1(2)(i) Reporting
5.1(2)(i)(1) Standard
[A] How frequently will we receive standard reports?
[B]
Do you have web-based reporting capability? Provide samples reports and screen shots of web-based interface.
[C] Do you provide a dashboard with metrics related to the Managed Security Services?
[D] Do you provide a portal or web interface for processing alerts and notifications?
5.1(2)(i)(2) Ad-hoc
[A] Can we create custom reports?
[B] Describe the process for requesting ad-hoc reports.
[C] Provide the timeframe for turnaround of ad-hoc reporting.
5.1(2)(i) General Information
[1] A technical outline of Offeror's IDS/IPS platforms and expertise
[2] A technical outline of Offeror's SIEM products and services.
[3] A technical design document showing integration of Offeror's IDS/IPS and SIEM products.
5.1(3)(a)
Number of years providing Managed Security Services, including details on how long each of Offeror's Managed Security Services have been provided to clients
5.1(3)(b)
Percentage of total revenues coming from clients who purchase only monitoring and security device management services
5.1(3)(c) Quantity and size of existing federal clients
5.1(3)(d) Quantity and size of existing non-federal clients
5.1(3)(e)
Quantity of Managed Security Services customers at the end of last calendar year, currently, and projected for the end of this calendar year (device management, security monitoring, SIEM, and log management only)
5.1(3)(f) A description of Offeror's operation centers and sites
5.1(3)(g)
A description and evidence of industry accreditations and references specific to the
Federal government sector
5.1(3)(h)
A description and evidence of internal security practices and procedures covering physical security of facilities, ownership and locations
5.1(3)(i) A description and evidence of staff hiring and vetting procedures
5.1(3)(j) A description and evidence of access and authorization controls
5.1(3)(k) A description and evidence of third party audits and contingency planning
5.1(3)(l)
A description and evidence of other internal security practices and procedures not already specified above
5.1(3)(m) A description and evidence of a successful defense of an attack
Company Profile (Corporate History & Capability)
USHMM RFP 9531-16-R-0400 page A2 of 3 Managed Security Service Provider
PROPOSAL
Managed Security Services Requirements - Technical Brief (Offeror's methodology and strategy for implementing the solution)
5.1(4)(a)(i)
Describe how any of the top research firms (i.e. Gartner, Yankee, IDC, Forrester, Frost &
Sullivan) have ranked your company in the MSSP market and any contract wards your company has won for Managed Security Services.
5.1(4)(a)(ii)
Have you had an independent review of your MSSP infrastructure and service? Please provide detail on this review including who executed it, when it was executed, scope of review, and type of testing, frequency of testing and summary results. If available, please provide the report.
5.1(4)(a)(iii)
How many full, dedicated security operations centers (SOCs) support your Managed
Security Services? How many dedicated staff members perform the monitoring for the
Managed Security Services provided? Where is your primary SOC located? Where are your secondary SOCs located? Describe the level of SOC redundancy and geographic diversity.
5.1(4)(a)(iv)
How long has your Managed Security Services organization been performing firewall management/monitoring? Do you have any management tool for supporting and monitoring multiple vendor firewalls? If yes, please provide the detail. Do you currently have a firewall configuration checkup procedure? And how often would you do this?
5.1(4)(a)(v)
Do you have special relationships with the product and platform vendors of the products you will deploy?
5.1(4)(a)(vi)
Describe how third-party intelligence sources are integrated into monitoring and who those third-party intelligence sources are.
5.1(4)(a)(vii)
Describe any service limitations or thresholds that we would be charged additional fees for exceeding. How many incidents can be escalated before additional fees are charged?
5.1(4)(a)(viii) Provide examples of how threat research has been used to proactively protect customers.
5.1(4)(b) References
5.1(4)(c) Chronological List of Clients
5.1(5)(a&b) Key Personnel & resumes
5.1(5)(c) General staffing
5.1(5)(d) Subcontract management system
Account Support & Staffing Plan
Past Performance (Case Studies)
USHMM RFP 9531-16-R-0400 page A3 of 3 Managed Security Service Provider
File details come from the government source that posted it. Updated .