RFP-9351-16-R-0400_MSSP_Q A.pdf
PDF 3 MB Posted
- Attached to
- Managed Security Service Provider Federal contract opportunity
- Solicitation number
- 9531-16-R-0400
- Issued by
- United States Holocaust Memorial Museum
About this file
Attached is the full and complete Q A associated with this solicitation. Please note that the Museum has extended the due date for proposals through to August 11 2016 at 5 PM ET.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP-9531-16-R-0400-RequirementsMatrix_ATTA.xlsx | XLSX spreadsheet | |
| RFP-9351-16-R-0400_MSSP.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
USHMM MSSP RFP Q&A 1 of 8 Last posted 7/14/2016
Managed Security Service Provider RFP Q&A
[RFP-9531-16-R-0400-P00001]
This Q&A posting hereby amends and clarifies USHMM solicitation RFP-9531-16-R-0400, initially released June 24, 2016. While USHMM is no longer accepting questions, the Museum reserves the right to publish further clarifications.
1. Would it be possible to extend the proposal due date an additional two weeks to August
4, 2016?
Yes. Please note that the date for proposals has been extended. USHMM shall consider all proposals submitted in response to this RFP by 5:00 PM ET on Thursday, August 11, 2016.
2. Will it be possible to obtain a list of quantities, makes/models of hardware, and releases/patch levels of Operating System and critical application software systems, organized by each of the six locations, for each of the four (a)-(d) platforms USHMM wishes to be monitored?
Make/model of hardware and patch levels of OS is irrelevant to the MSSP service. The awardee will basically be monitoring our SIEM tool which gathers all of the log files from each device on the network.
USHMM is considering, but not committed to removing and replacing the existing LogRhythm installation.
(See Q&A #3, below.)
The environment is comprised of Windows 7, 10, 2008R2 and 20012 devices, Apple IOX latest version, Cisco and some RedHat Linux. All OS are patched to the latest OS level.
As for critical applications (which are not included in LogRhythm today) we need to compile that list and go through the classification exercise.
3. May Offerors assume that the Log Rhythm installation will be dismantled once the selected solution is operational?
No, USHMM prefers to retain its LogRhythm installation base. Offerors who propose replacing it would either need to buy back the LogRhythm installation and/or make a persuasive financial case that accounts for USHMM’s investment to date.
4. Will the Offerer be expected to provide security services in para. 2.1 to address the risks with IaaS and CSP implementations? If so, would USHMM lease enumerate the
IaaS facilities and CSPs in use or planned for use?
IAAS services in the cloud would look similar to our current environment. USHMM will lease IAAS facilities as necessary from the CSP. Appliances like FW/IDPS, LB, APPFW.
5. Please elaborate on USHMM intent with regard to the IDS & IPS solution. Are
Offerers to assume that these solutions, and the firewalls they reside within [1.3(1)(b)] will be retained as-is, retained but updated according to the Offerers recommendations, or replaced altogether with the Offerers standard product?
USHMM currently deploys Checkpoint firewalls throughout its infrastructure and has no short-term plan to replace them. As part of the move to CSP/IAAS the Museum will more than likely replace the firewall with
USHMM MSSP RFP Q&A 2 of 8 Last posted 7/14/2016
PALO-ALTO. In either case, the Museum more than likely would retain ownership of the firewalls.
Configuration recommendations are always welcome.
6. Could you provide a list of devices that would generate SYSLOG information to feed into our Security Information and Event Management service? Note: we will not be able to build a price without this.
The question rests on a SIEM-replacement premise, which may not be appropriate. USHMM is considering, but not committed to removing and replacing the existing LogRhythm installation. (See Q&A #3, above.) Today, all endpoints (MAC, Windows (7, 10, 2008, 2012), Linux, Cisco (switches, routers), Checkpoint, Forescout, Lightcyber, F5) feed our SIEM tool. There are approximately 1000 devices on the network.
7. Please provide a list of devices that require co-management. Note: we will not be able to build a price for this piece without this.
USHMM will retain management of all services and endpoints, but desires co-management of all networking infrastructure (firewall, routers, and switches). In addition, USHMM would need access to all proposed security tools.
8. Is the Museum using end-point protection services today? If so, what technology is in place?
USHMM is currently using Checkpoint/Kaspersky for endpoint management, but is currently evaluating alternatives, including Sophos and McAfee.
9. 1.3 - Can USHMM provide the number of devices for next-gen firewalls and other cloud based security devices or applications?
CSP is still being discussed, so we can not provide a definitive number at this time. The Museum currently has 7 Checkpoint firewalls to be monitored. Offerors should assume that there will be a couple of firewalls (F5’s or equivalent), A/V, and a log collector in the cloud.
10. Can USHMM provide the number of devices for traditional “static” firewalls, IDS/IPS systems, SIEMs, Endpoint Management systems, VPN concentrators, Data Loss
Prevention systems, DDoS Mitigation systems and other security-specific devices or applications?
The Museum currently has the following:
● 7 Checkpoint UTM Firewalls with all blades (including VPN, IDPS, Url filtering, anti-bot and DLP (note implemented currently)
● Logrhythm for SIEM
● Checkpoint/Kaspersky for endpoint management (with Sophos and McAfee solutions currently under consideration)
● Forescout
● LightCyber
● No DDOS protection currently
USHMM MSSP RFP Q&A 3 of 8 Last posted 7/14/2016
11. Can USHMM provide the number of network devices like routers, switches, WAPs, Load Balancers, etc.?
● Routers - 1 border router
● Router/Switches - 25 cisco 3850, 1 6509-E with dual sup 720s
● WAP Router - 3
● WAP - 45 aruba AP 125/61
● load balancers - 4 Barracuda
12. 1.3(3) System Information - For the SIEM Monitoring of Log Rhythm, would the customer (USHMM) be open to setting up a B2B VPN Tunnel with the MSSP awardee and send syslog messages from LogRhythm to the MSSP-owned SIEM for further correlation?
Yes, USHMM would be open to this as a potential solution.
13. 1.3(1)(b) - In the proposal it is noted that the “firewall systems” have IPS/IDS capabilities, but in the “Requirement Services” section it states, “Placement and management of IDS/IPS” is required from the MSSP. Are the IDS/IPS systems currently functional or is USHMM looking for the MSSP to deploy the service? If functional, please quantify.
USHMM currently has IDPS deployed but is looking for someone to help manage/monitor our devices.
14. Can you please tell us what throughput the IPS system has to be capable of supporting, and if you have a VMware environment that the IPS server could run in?
Our firewall currently has a throughput of 95,000 Kbps. IDPS is generating 1500 events/hr. Yes we have a vmware environment, but would prefer a dedicated appliance for IDPS activity.
15. 1.3(3) - Is Threat Intelligence plugged into the LogRhythm SIEM? If so, what feeds/tools are) you leveraging? Does your current network security report to your
LogRhythm Solution?
We currently have threat intelligence feeding into Checkpoint via Checkpoint feeds. Lightcyber feeds internally into LogRhythm. The Forescout and Lightcyber appliances and all endpoints (1000 - Windows, Linux, Apple devices, Cisco) all feed LogRhythm.
16. 1.3(3) - Does USHMM know the EPS coming from the LogRhythm SIEM? What is the total EPS/GB daily ingestion of your LogRhythm Solution?
EPS=2000 steady state with burst up to 3500.
17. 2.1(2) Required Services - Would the customer (USHMM) be expecting the MSSP to validate any events/incidents/alarms generated in the SIEM by using existing security applications in the customer network such as but not limited to perimeter firewalls? (If so, would the MSSP partner be expected to perform remediation and/or block actions
USHMM MSSP RFP Q&A 4 of 8 Last posted 7/14/2016 with these tools? What are these security tools and what versions are currently installed that the customer would like managed/monitored?)
The MSSP should monitor logs and identify incidents through an internal incident response program for purposes of informing the Museum whether further action or investigation is warranted.
18. 2.1(2) - In the RFP USHMM asks for 24/365 monitoring, alerting, and remediation steps. Would USHMM be interested in having the MSSP provide the remediation on behalf of USHMM? In other words, would USHMM be interested in having the MSSP take care of the prevention, detection, containment, and remediation of the incident and receive a report on what steps were taken to remediate the issue or would USHMM want to take ownership of the remediation effort?
USHMM desires to be able to take ownership of the remediation effort with guidance from the MSSP.
19. 2.1(7) Required Services - What kind of knowledge transfer and training must be performed, and for how often?
The offeror will periodically through reports and/or training education museum staff on active configurations of any devices that are support and threat patterns that are affect the Musuem.
20. If staff are using a corporate asset with a remote VPN connection to the SOC performing monitoring, would a work from home option be available for any analysts performing monitoring duties?
USHMM requires that all remote employees working in a SOC be subject to our background checks for suitability.
21. 2.2 - What is meant by “optional services”?
These are services which USHMM may choose to incorporate in the Service package being solicited, by dint of their integration in an Offeror’s base service package or through exercise at time of award or subsequently by modification. USHMM reserves the right to consider the availability, nature, and pricing of optional services in determining proposal competitiveness and best value, but their inclusion is not essential to a determination of responsiveness.
22. 2.2 - Can USHMM please specify what type of information/services they would like to receive as a part of the “Security Review”? If this consists of running a security assessment which includes Vulnerability Assessments and PenTesting, can USHMM please provide the number of internal and external IPs?
The Museum currently performs its own vulnerability assessment using Nexpose. This “review” is more from a peripheral standpoint as regards firewall and IDPS rulesets.
USHMM MSSP RFP Q&A 5 of 8 Last posted 7/14/2016
23. 5.1(2)(e) - If any, what type of agents are deployed to servers and endpoints today?
These:
● KACE for patch management
● Checkpoint/Endpoint
● Forescout
● Some LogRhythm
24. Can you provide us with the quantity of devices in scope? For example, quantity of
Firewall IDS (P), Firewalls, Security Appliances. Moreover, in 5.1(2)(e) you have written: “Alternate Approaches (if applicable) - With the exception of the perimeter firewall systems...("Devices in Scope," provided upon request)." Please provide this document.
The list is as follows:
● 10 Firewalls (2 integrated with IDPS) - (includes cloud expansion)
● Lightcyber
● Forescout
● A/V console
● LogRhythm
● 1000 - 1200 - desktops/ laptops / servers /printers/ switches
25. Please provide an inventory list of the security devices (firewall, IDPS) to include quantity, make/model, IOS and location. In addition please identify if there are any devices at the 5 remote locations.
Currently the museum has 7 Checkpoint UTM devices (with all blade options):
Two 13500 at the core (running all blades) Five 2100 at the remote facilities.
26. Will the LogRhythm device be out of scope or remain in place? Are you looking for management of your existing LogRhythm Solution?
Yes, USHMM’s preferred option is to have the solution remain in place and be managed by the MSSP, to use its LogRhythm infrastructure as much as possible. But see Q&A #3, above.
27. 6.2(2)(c) - are there any certifications required (eg., FISMA, ISO, etc). There was a question asking if the company had any but did not identify if any were required.
USHMM requires a current SSAE16-SOC2 type 2 assessment and considers FISMA/FEDRAMP and other certifications to be desirable.
28. Are you looking for suggestions about the placement of either new or existing devices?
If after a formal architectural review it is determined that the Museum has a gap in its security posture, it will look for the awardee to recommend potential solutions to fill that gap. Deployment will depend on risk and ROI on the proposed solution.
29. Are you doing any event correlation or log management via your LogRhythm Solution?
Yes, the Museum is doing some but hasn’t fully implemented the solution from a best practice standpoint.
USHMM MSSP RFP Q&A 6 of 8 Last posted 7/14/2016
30. Does USHMM have a current Network Diagram you are willing to share so we can understand the topology?
Yes, these have been attached to this Q&A.
31. What size internet bandwidth does USHMM currently have?
100M
32. Are any of the devices mobile (i.e. tablets, phones)?
USHMM supports mobile devices on its network.
33. Are there any remote users?
Yes, USHMM has a mobile workforce.
Storage Area Network (Planned)
C
Museum Email
C C
C
Proxy Access Server
Chicago
New York
Florida
Development
Los Angeles
USHMM RISK- BASED NETWORK SECURITY OVERVIEW
Museum Web Presence
U
SH
M M
Internet
Oracle Database SQL Database Servers
File Server
Checkpoint Malware Server
Application Servers
Domain Controller
Kaspersky Malware Server
DNS
Redundant Dark Fiber Redundant Dark Fiber
Current Network Tools
1. Network Monitoring and Troubleshooting Tool ► Network Instrument - Observer
2. Network and Application Vulnerability and Penetration Testing Tool► Rapid 7 – Nexpose
3. Network Performance Monitoring Tool ► What’sUPGold
4. Network Log Management Tool ► Logrhythm Appliance
5. Network Access Control Tool ► Forescout CounterAct Appliance
HP Printers
HP Digital Senders
Network Copiers Network Plotter
Incident Database Server
MUSEUM
BACKBONE
Museum Google Mail
Local Museum Database copy
Hosted Museum Data
Museum Office of Finance
Print Server
MySQL Database Server
Finance Servers
Collections Application Server
Museum Office of Human Resource
Linthicum
Facilities
Museum Virtual FW
100MB 100 MB
Kaspersky End-Point
Management
HP Printers
Domain Controller
POS Terminals
PCI Environment
Portals West
IP:
Cisco 3850 Stack
Version 03.03.01.SE
Portals Core
IP
Cisco 3850 Stack
Version 03.03.01.SE
POWER
STATUS
ACCESS
POINT
STATUS
0 1 2 3 4 5 6 7
ACCESS
POINT
STATUS
G IG ABIT
LNK/
ACT
8 SERIAL
LNK/
ACT POE
LNK/
ACT POE
n e t w o r k s
Aruba 800 Controller
IP:
DPS
IP: 1
Cisco 3550
Verison 12.1(20)EA1
Ross 2
IP:
Cisco 3850 Stack
Version 03.03.01.SE
Ross 1
IP: 1
Cisco 3850 Stack
Version 03.03.01.SE
Ross mezz
IP:
Cisco 3850 Stack
Version 03.03.01.SE
Ross Building
Museum
Core
IP: 1
Cisco 6500
Version
12.2(17r)SX5
Museum
RossG
IP:
Cisco 3850 Stack
Version 03.03.01.SE
Mus5SW
IP: 1
Cisco 3850 Stack
Version 03.03.01.SE
CAHS
IP:
Cisco 3850 Stack
Version 03.03.01.SE
LC
IP:
Cisco 3850 Stack
Version 03.03.01.SE
LoadDock
IP:
Cisco 3850 Stack
Version 03.03.01.SE
B61
IP:
Cisco 3850 Stack
Version 03.03.01.SE
Concourse
IP:
Cisco 3850 Stack
Version 03.03.01.SE
Catalyst 3560 SERIES
SYST
MODE
SPEED
DUPLX
POE
STAT
RPS
1X
2X
PoE-24
1 2
1 2X
1 1X
11 121 2 3 4 5 6 7 8 9 10
14 X
13 X 2 3X
2 4X
13 14 15 16 17 18 19 20 21 22 23 24
Internet Switch
Cisco 3560G
Internet Router
Cisco 3945
Linthicum
New York
Chicago
Florida
LA
DCNET
2x 100Mbps Links
Comcast
100/20Mbps Link
Time Warner
22/5Mbps Link
Comcast
25/5Mbps Link
Interax
25Mbps Link
Cogent
100Mbps Link
Catalyst 3560 SERIES
SYST
MODE
SPEED
DUPLX
POE
STAT
RPS
1 X
18 X
1 7X
16 X2X
15 X 31X
32X 34 X
33 X 4 7X
4 8X
11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 481 2 3 4 5 6 7 8 9 10
PoE-48
2 4
Linthcore
IP: 1
Cisco 3550
Version: 12.1
WS-SUP720
SUPERVISOR 720 WITH INTEGRATED SWITCH FABRIC
S Y S T E M
S
TA
TU
S
A C T
IV
E
P W
R
M G M
T EJECT
DISK 0
EJECT
DISK 1
CONSOLE PORT 2
PORT 1
L
IN
K L
IN
K L
IN
K
R E S E T
WS-SUP720
SUPERVISOR 720 WITH INTEGRATED SWITCH FABRIC
S Y S T E M
S
TA
TU
S
A C T
IV
E
P W
R
M G M
T EJECT
DISK 0
EJECT
DISK 1
CONSOLE PORT 2
PORT 1
L
IN
K L
IN
K L
IN
K
R E S E T
STATUS PHONE
WS-X6548-GE-TX
2 5
4 8 P O R T
12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38
10/100/1000 BASE-T
ETHERNET
SWITCHING MO DULE
STATUS PHONE
WS-X6548-GE-TX
2 5
4 8 P O R T
12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38
10/100/1000 BASE-T
ETHERNET
SWITCHING MO DULE
STATUS PHONE
WS-X6548-GE-TX
2 5
4 8 P O R T
12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38
10/100/1000 BASE-T
ETHERNET
SWITCHING MO DULE
STATUS PHONE
WS-X6548-GE-TX
2 5
4 8 P O R T
12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38
10/100/1000 BASE-T
ETHERNET
SWITCHING MO DULE
STATUS PHONE
WS-X6548-GE-TX
2 5
4 8 P O R T
12119 107 85 63 41 2 242321 2219 2017 1815 1613 14 363533 3431 3229 3027 2825 26 484745 4643 4441 4239 4037 38
10/100/1000 BASE-T
ETHERNET
SWITCHING MO DULE
Portals
Linthicum Firewall
E:
I:
Chicago Firewall
E:
I:
New York Firewall
E:
I:
Florida Firewall
E:5
I:
LA Firewall
E:3
I:
Checkpoint Firewall
Light 2
Checkpoint Firewall
Light 1
Canobeam
Museum
Canobeam
Portals
Out-of-Band
DSL
Out-of-Band
Secondary link
ACCESS
POINT
STATUS
ACCESS
POINT
STATUS
LNK/
ACT
POE17 19 21 23
16 18 20 22
LNK/
ACT
POE9 11 13 15
8 10 12 14
ACCESS
POINT
STATUS
6POWER
STATUS
LNK/
ACT
POE1 3 5 7
0 2 4 6 molex molex
LNK/
ACT
LNK/
ACT
SERIAL25
POWER
STATUS
ACCESS
POINT
STATUS
0 1 2 3 4 5 6 7
ACCESS
POINT
STATUS
G IG ABIT
LNK/
ACT
8 SERIAL
LNK/
ACT POE
LNK/
ACT POE
n e t w o r k s
Aruba 3200 Controller
Aruba 800 Controller
1GB Link
Facilities Network Facilities Firewall
Facilities Network
Museum Shop th Floor Switch
Museum Shop
Concourse Switch
Museum Shop
Open Market
Open Market
DSL Router
Open Market
Distribution switch
Guest Services
DSL Router
Guest Services
Distribution Switch
Guest Services
Chicago ATT
DSL Router Internet WTI Console
WTI Console
WTI Console
| USHMM IT Security Diagram v5.1.pdf |
| Page-1� |
| Future Network 2016 mark 2_Redacted.pdf |
| Museum� |
| USHMM IT Security Diagram v5.1.pdf |
| Page-1� |
File details come from the government source that posted it. Updated .