RFP-9351-16-R-0400_MSSP_Q A.pdf

PDF 3 MB Posted

Attached to
Managed Security Service Provider Federal contract opportunity
Solicitation number
9531-16-R-0400
Issued by
United States Holocaust Memorial Museum

About this file

Attached is the full and complete Q A associated with this solicitation. Please note that the Museum has extended the due date for proposals through to August 11 2016 at 5 PM ET.

View the file

Other files for this federal contract opportunity

Other files attached to Managed Security Service Provider, newest first.
File Type Posted
RFP-9531-16-R-0400-RequirementsMatrix_ATTA.xlsx XLSX spreadsheet
RFP-9351-16-R-0400_MSSP.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

USHMM MSSP RFP Q&A 1 of 8 Last posted 7/14/2016

Managed Security Service Provider RFP Q&A

[RFP-9531-16-R-0400-P00001]

This Q&A posting hereby amends and clarifies USHMM solicitation RFP-9531-16-R-0400, initially released June 24, 2016. While USHMM is no longer accepting questions, the Museum reserves the right to publish further clarifications.

1. Would it be possible to extend the proposal due date an additional two weeks to August

4, 2016?

Yes. Please note that the date for proposals has been extended. USHMM shall consider all proposals submitted in response to this RFP by 5:00 PM ET on Thursday, August 11, 2016.

2. Will it be possible to obtain a list of quantities, makes/models of hardware, and releases/patch levels of Operating System and critical application software systems, organized by each of the six locations, for each of the four (a)-(d) platforms USHMM wishes to be monitored?

Make/model of hardware and patch levels of OS is irrelevant to the MSSP service. The awardee will basically be monitoring our SIEM tool which gathers all of the log files from each device on the network.

USHMM is considering, but not committed to removing and replacing the existing LogRhythm installation.

(See Q&A #3, below.)

The environment is comprised of Windows 7, 10, 2008R2 and 20012 devices, Apple IOX latest version, Cisco and some RedHat Linux. All OS are patched to the latest OS level.

As for critical applications (which are not included in LogRhythm today) we need to compile that list and go through the classification exercise.

3. May Offerors assume that the Log Rhythm installation will be dismantled once the selected solution is operational?

No, USHMM prefers to retain its LogRhythm installation base. Offerors who propose replacing it would either need to buy back the LogRhythm installation and/or make a persuasive financial case that accounts for USHMM’s investment to date.

4. Will the Offerer be expected to provide security services in para. 2.1 to address the risks with IaaS and CSP implementations? If so, would USHMM lease enumerate the

IaaS facilities and CSPs in use or planned for use?

IAAS services in the cloud would look similar to our current environment. USHMM will lease IAAS facilities as necessary from the CSP. Appliances like FW/IDPS, LB, APPFW.

5. Please elaborate on USHMM intent with regard to the IDS & IPS solution. Are

Offerers to assume that these solutions, and the firewalls they reside within [1.3(1)(b)] will be retained as-is, retained but updated according to the Offerers recommendations, or replaced altogether with the Offerers standard product?

USHMM currently deploys Checkpoint firewalls throughout its infrastructure and has no short-term plan to replace them. As part of the move to CSP/IAAS the Museum will more than likely replace the firewall with

USHMM MSSP RFP Q&A 2 of 8 Last posted 7/14/2016

PALO-ALTO. In either case, the Museum more than likely would retain ownership of the firewalls.

Configuration recommendations are always welcome.

6. Could you provide a list of devices that would generate SYSLOG information to feed into our Security Information and Event Management service? Note: we will not be able to build a price without this.

The question rests on a SIEM-replacement premise, which may not be appropriate. USHMM is considering, but not committed to removing and replacing the existing LogRhythm installation. (See Q&A #3, above.) Today, all endpoints (MAC, Windows (7, 10, 2008, 2012), Linux, Cisco (switches, routers), Checkpoint, Forescout, Lightcyber, F5) feed our SIEM tool. There are approximately 1000 devices on the network.

7. Please provide a list of devices that require co-management. Note: we will not be able to build a price for this piece without this.

USHMM will retain management of all services and endpoints, but desires co-management of all networking infrastructure (firewall, routers, and switches). In addition, USHMM would need access to all proposed security tools.

8. Is the Museum using end-point protection services today? If so, what technology is in place?

USHMM is currently using Checkpoint/Kaspersky for endpoint management, but is currently evaluating alternatives, including Sophos and McAfee.

9. 1.3 - Can USHMM provide the number of devices for next-gen firewalls and other cloud based security devices or applications?

CSP is still being discussed, so we can not provide a definitive number at this time. The Museum currently has 7 Checkpoint firewalls to be monitored. Offerors should assume that there will be a couple of firewalls (F5’s or equivalent), A/V, and a log collector in the cloud.

10. Can USHMM provide the number of devices for traditional “static” firewalls, IDS/IPS systems, SIEMs, Endpoint Management systems, VPN concentrators, Data Loss

Prevention systems, DDoS Mitigation systems and other security-specific devices or applications?

The Museum currently has the following:

● 7 Checkpoint UTM Firewalls with all blades (including VPN, IDPS, Url filtering, anti-bot and DLP (note implemented currently)

● Logrhythm for SIEM

● Checkpoint/Kaspersky for endpoint management (with Sophos and McAfee solutions currently under consideration)

● Forescout

● LightCyber

● No DDOS protection currently

USHMM MSSP RFP Q&A 3 of 8 Last posted 7/14/2016

11. Can USHMM provide the number of network devices like routers, switches, WAPs, Load Balancers, etc.?

● Routers - 1 border router

● Router/Switches - 25 cisco 3850, 1 6509-E with dual sup 720s

● WAP Router - 3

● WAP - 45 aruba AP 125/61

● load balancers - 4 Barracuda

12. 1.3(3) System Information - For the SIEM Monitoring of Log Rhythm, would the customer (USHMM) be open to setting up a B2B VPN Tunnel with the MSSP awardee and send syslog messages from LogRhythm to the MSSP-owned SIEM for further correlation?

Yes, USHMM would be open to this as a potential solution.

13. 1.3(1)(b) - In the proposal it is noted that the “firewall systems” have IPS/IDS capabilities, but in the “Requirement Services” section it states, “Placement and management of IDS/IPS” is required from the MSSP. Are the IDS/IPS systems currently functional or is USHMM looking for the MSSP to deploy the service? If functional, please quantify.

USHMM currently has IDPS deployed but is looking for someone to help manage/monitor our devices.

14. Can you please tell us what throughput the IPS system has to be capable of supporting, and if you have a VMware environment that the IPS server could run in?

Our firewall currently has a throughput of 95,000 Kbps. IDPS is generating 1500 events/hr. Yes we have a vmware environment, but would prefer a dedicated appliance for IDPS activity.

15. 1.3(3) - Is Threat Intelligence plugged into the LogRhythm SIEM? If so, what feeds/tools are) you leveraging? Does your current network security report to your

LogRhythm Solution?

We currently have threat intelligence feeding into Checkpoint via Checkpoint feeds. Lightcyber feeds internally into LogRhythm. The Forescout and Lightcyber appliances and all endpoints (1000 - Windows, Linux, Apple devices, Cisco) all feed LogRhythm.

16. 1.3(3) - Does USHMM know the EPS coming from the LogRhythm SIEM? What is the total EPS/GB daily ingestion of your LogRhythm Solution?

EPS=2000 steady state with burst up to 3500.

17. 2.1(2) Required Services - Would the customer (USHMM) be expecting the MSSP to validate any events/incidents/alarms generated in the SIEM by using existing security applications in the customer network such as but not limited to perimeter firewalls? (If so, would the MSSP partner be expected to perform remediation and/or block actions

USHMM MSSP RFP Q&A 4 of 8 Last posted 7/14/2016 with these tools? What are these security tools and what versions are currently installed that the customer would like managed/monitored?)

The MSSP should monitor logs and identify incidents through an internal incident response program for purposes of informing the Museum whether further action or investigation is warranted.

18. 2.1(2) - In the RFP USHMM asks for 24/365 monitoring, alerting, and remediation steps. Would USHMM be interested in having the MSSP provide the remediation on behalf of USHMM? In other words, would USHMM be interested in having the MSSP take care of the prevention, detection, containment, and remediation of the incident and receive a report on what steps were taken to remediate the issue or would USHMM want to take ownership of the remediation effort?

USHMM desires to be able to take ownership of the remediation effort with guidance from the MSSP.

19. 2.1(7) Required Services - What kind of knowledge transfer and training must be performed, and for how often?

The offeror will periodically through reports and/or training education museum staff on active configurations of any devices that are support and threat patterns that are affect the Musuem.

20. If staff are using a corporate asset with a remote VPN connection to the SOC performing monitoring, would a work from home option be available for any analysts performing monitoring duties?

USHMM requires that all remote employees working in a SOC be subject to our background checks for suitability.

21. 2.2 - What is meant by “optional services”?

These are services which USHMM may choose to incorporate in the Service package being solicited, by dint of their integration in an Offeror’s base service package or through exercise at time of award or subsequently by modification. USHMM reserves the right to consider the availability, nature, and pricing of optional services in determining proposal competitiveness and best value, but their inclusion is not essential to a determination of responsiveness.

22. 2.2 - Can USHMM please specify what type of information/services they would like to receive as a part of the “Security Review”? If this consists of running a security assessment which includes Vulnerability Assessments and PenTesting, can USHMM please provide the number of internal and external IPs?

The Museum currently performs its own vulnerability assessment using Nexpose. This “review” is more from a peripheral standpoint as regards firewall and IDPS rulesets.

USHMM MSSP RFP Q&A 5 of 8 Last posted 7/14/2016

23. 5.1(2)(e) - If any, what type of agents are deployed to servers and endpoints today?

These:

● KACE for patch management

● Checkpoint/Endpoint

● Forescout

● Some LogRhythm

24. Can you provide us with the quantity of devices in scope? For example, quantity of

Firewall IDS (P), Firewalls, Security Appliances. Moreover, in 5.1(2)(e) you have written: “Alternate Approaches (if applicable) - With the exception of the perimeter firewall systems...("Devices in Scope," provided upon request)." Please provide this document.

The list is as follows:

● 10 Firewalls (2 integrated with IDPS) - (includes cloud expansion)

● Lightcyber

● Forescout

● A/V console

● LogRhythm

● 1000 - 1200 - desktops/ laptops / servers /printers/ switches

25. Please provide an inventory list of the security devices (firewall, IDPS) to include quantity, make/model, IOS and location. In addition please identify if there are any devices at the 5 remote locations.

Currently the museum has 7 Checkpoint UTM devices (with all blade options):

Two 13500 at the core (running all blades) Five 2100 at the remote facilities.

26. Will the LogRhythm device be out of scope or remain in place? Are you looking for management of your existing LogRhythm Solution?

Yes, USHMM’s preferred option is to have the solution remain in place and be managed by the MSSP, to use its LogRhythm infrastructure as much as possible. But see Q&A #3, above.

27. 6.2(2)(c) - are there any certifications required (eg., FISMA, ISO, etc). There was a question asking if the company had any but did not identify if any were required.

USHMM requires a current SSAE16-SOC2 type 2 assessment and considers FISMA/FEDRAMP and other certifications to be desirable.

28. Are you looking for suggestions about the placement of either new or existing devices?

If after a formal architectural review it is determined that the Museum has a gap in its security posture, it will look for the awardee to recommend potential solutions to fill that gap. Deployment will depend on risk and ROI on the proposed solution.

29. Are you doing any event correlation or log management via your LogRhythm Solution?

Yes, the Museum is doing some but hasn’t fully implemented the solution from a best practice standpoint.

USHMM MSSP RFP Q&A 6 of 8 Last posted 7/14/2016

30. Does USHMM have a current Network Diagram you are willing to share so we can understand the topology?

Yes, these have been attached to this Q&A.

31. What size internet bandwidth does USHMM currently have?

100M

32. Are any of the devices mobile (i.e. tablets, phones)?

USHMM supports mobile devices on its network.

33. Are there any remote users?

Yes, USHMM has a mobile workforce.

Storage Area Network (Planned)

C

Museum Email

C C

C

Proxy Access Server

Chicago

New York

Florida

Development

Los Angeles

USHMM RISK- BASED NETWORK SECURITY OVERVIEW

Museum Web Presence

U

SH

M M

Internet

Oracle Database SQL Database Servers

File Server

Checkpoint Malware Server

Application Servers

Domain Controller

Kaspersky Malware Server

DNS

Redundant Dark Fiber Redundant Dark Fiber

Current Network Tools

1. Network Monitoring and Troubleshooting Tool ► Network Instrument - Observer

2. Network and Application Vulnerability and Penetration Testing Tool► Rapid 7 – Nexpose

3. Network Performance Monitoring Tool ► What’sUPGold

4. Network Log Management Tool ► Logrhythm Appliance

5. Network Access Control Tool ► Forescout CounterAct Appliance

HP Printers

HP Digital Senders

Network Copiers Network Plotter

Incident Database Server

MUSEUM

BACKBONE

Museum Google Mail

Local Museum Database copy

Hosted Museum Data

Museum Office of Finance

Print Server

MySQL Database Server

Finance Servers

Collections Application Server

Museum Office of Human Resource

Linthicum

Facilities

Museum Virtual FW

100MB 100 MB

Kaspersky End-Point

Management

HP Printers

Domain Controller

POS Terminals

PCI Environment

Portals West

IP:

Cisco 3850 Stack

Version 03.03.01.SE

Portals Core

IP

Cisco 3850 Stack

Version 03.03.01.SE

POWER

STATUS

ACCESS

POINT

STATUS

0 1 2 3 4 5 6 7

ACCESS

POINT

STATUS

G IG ABIT

LNK/

ACT

8 SERIAL

LNK/

ACT POE

LNK/

ACT POE

n e t w o r k s

Aruba 800 Controller

IP:

DPS

IP: 1

Cisco 3550

Verison 12.1(20)EA1

Ross 2

IP:

Cisco 3850 Stack

Version 03.03.01.SE

Ross 1

IP: 1

Cisco 3850 Stack

Version 03.03.01.SE

Ross mezz

IP:

Cisco 3850 Stack

Version 03.03.01.SE

Ross Building

Museum

Core

IP: 1

Cisco 6500

Version

12.2(17r)SX5

Museum

RossG

IP:

Cisco 3850 Stack

Version 03.03.01.SE

Mus5SW

IP: 1

Cisco 3850 Stack

Version 03.03.01.SE

CAHS

IP:

Cisco 3850 Stack

Version 03.03.01.SE

LC

IP:

Cisco 3850 Stack

Version 03.03.01.SE

LoadDock

IP:

Cisco 3850 Stack

Version 03.03.01.SE

B61

IP:

Cisco 3850 Stack

Version 03.03.01.SE

Concourse

IP:

Cisco 3850 Stack

Version 03.03.01.SE

Catalyst 3560 SERIES

SYST

MODE

SPEED

DUPLX

POE

STAT

RPS

1X

2X

PoE-24

1 2

1 2X

1 1X

11 121 2 3 4 5 6 7 8 9 10

14 X

13 X 2 3X

2 4X

13 14 15 16 17 18 19 20 21 22 23 24

Internet Switch

Cisco 3560G

Internet Router

Cisco 3945

Linthicum

New York

Chicago

Florida

LA

DCNET

2x 100Mbps Links

Comcast

100/20Mbps Link

Time Warner

22/5Mbps Link

Comcast

25/5Mbps Link

Interax

25Mbps Link

Cogent

100Mbps Link

Catalyst 3560 SERIES

SYST

MODE

SPEED

DUPLX

POE

STAT

RPS

1 X

18 X

1 7X

16 X2X

15 X 31X

32X 34 X

33 X 4 7X

4 8X

11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 481 2 3 4 5 6 7 8 9 10

PoE-48

2 4

Linthcore

IP: 1

Cisco 3550

Version: 12.1

WS-SUP720

SUPERVISOR 720 WITH INTEGRATED SWITCH FABRIC

S Y S T E M

S

TA

TU

S

A C T

IV

E

P W

R

M G M

T EJECT

DISK 0

EJECT

DISK 1

CONSOLE PORT 2

PORT 1

L

IN

K L

IN

K L

IN

K

R E S E T

WS-SUP720

SUPERVISOR 720 WITH INTEGRATED SWITCH FABRIC

S Y S T E M

S

TA

TU

S

A C T

IV

E

P W

R

M G M

T EJECT

DISK 0

EJECT

DISK 1

CONSOLE PORT 2

PORT 1

L

IN

K L

IN

K L

IN

K

R E S E T

STATUS PHONE

WS-X6548-GE-TX

2 5

4 8 P O R T

12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38

10/100/1000 BASE-T

ETHERNET

SWITCHING MO DULE

STATUS PHONE

WS-X6548-GE-TX

2 5

4 8 P O R T

12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38

10/100/1000 BASE-T

ETHERNET

SWITCHING MO DULE

STATUS PHONE

WS-X6548-GE-TX

2 5

4 8 P O R T

12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38

10/100/1000 BASE-T

ETHERNET

SWITCHING MO DULE

STATUS PHONE

WS-X6548-GE-TX

2 5

4 8 P O R T

12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38

10/100/1000 BASE-T

ETHERNET

SWITCHING MO DULE

STATUS PHONE

WS-X6548-GE-TX

2 5

4 8 P O R T

12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38

10/100/1000 BASE-T

ETHERNET

SWITCHING MO DULE

Portals

Linthicum Firewall

E:

I:

Chicago Firewall

E:

I:

New York Firewall

E:

I:

Florida Firewall

E:5

I:

LA Firewall

E:3

I:

Checkpoint Firewall

Light 2

Checkpoint Firewall

Light 1

Canobeam

Museum

Canobeam

Portals

Out-of-Band

DSL

Out-of-Band

Secondary link

ACCESS

POINT

STATUS

ACCESS

POINT

STATUS

LNK/

ACT

POE17 19 21 23

16 18 20 22

LNK/

ACT

POE9 11 13 15

8 10 12 14

ACCESS

POINT

STATUS

6POWER

STATUS

LNK/

ACT

POE1 3 5 7

0 2 4 6 molex molex

LNK/

ACT

LNK/

ACT

SERIAL25

POWER

STATUS

ACCESS

POINT

STATUS

0 1 2 3 4 5 6 7

ACCESS

POINT

STATUS

G IG ABIT

LNK/

ACT

8 SERIAL

LNK/

ACT POE

LNK/

ACT POE

n e t w o r k s

Aruba 3200 Controller

Aruba 800 Controller

1GB Link

Facilities Network Facilities Firewall

Facilities Network

Museum Shop th Floor Switch

Museum Shop

Concourse Switch

Museum Shop

Open Market

Open Market

DSL Router

Open Market

Distribution switch

Guest Services

DSL Router

Guest Services

Distribution Switch

Guest Services

Chicago ATT

DSL Router Internet WTI Console

WTI Console

WTI Console

USHMM IT Security Diagram v5.1.pdf
Page-1�
Future Network 2016 mark 2_Redacted.pdf
Museum�
USHMM IT Security Diagram v5.1.pdf
Page-1�

File details come from the government source that posted it. Updated .