RFP-9531-16-R-0400-RequirementsMatrix_ATTA.xlsx
XLSX spreadsheet 21 KB Posted
- Attached to
- Managed Security Service Provider Federal contract opportunity
- Solicitation number
- 9531-16-R-0400
- Issued by
- United States Holocaust Memorial Museum
About this file
This is a writable copy of the responsiveness requirements matrix that Offerors will need to submit as part of their proposals
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP-9351-16-R-0400_MSSP_Q A.pdf | ||
| RFP-9351-16-R-0400_MSSP.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1 This solicitation seeks proposals to provide the Museum with a Managed Security Services solution. Offerors should propose the most cost-efficient and manageable solution along with a timeline for project completion.
Offerors should submit a proposal that outlines technical and functional offerings along with evidence of meeting requirements that include:
| ITEM | EVIDENCE SOUGHT BY USHMM (RESPONSIVENESS DETERMINATION) | LOCATION IN PROPOSAL |
| Managed Security Services Requirements - Technical Brief (Offeror's methodology and strategy for implementing the solution) | ||
| 5.1(2)(i) | Protect - Describe your ability to: | |
| [1] | Provide centralized logging and audit trails, and aggregate and correlate all security event information. | |
| [2] | Monitor, detect and record activity from both in-bound and out-bound traffic that exhibits unusual or malicious behavior and identify attacks from known as well as unknown sources. | |
| [3] | Provide a secure customer portal for direct access to data and reporting. | |
| [4] | Provide a secure and encrypted channel for all monitoring activities. | |
| 5.1(2)(i) | Detect - Describe your ability to: | |
| [1] | Monitor and detect malicious activity on a 24x7 basis. | |
| [2] | Identify potential sources of data leakage. | |
| [3] | How do you manage false positives and tune signatures? What metrics do you offer to support the effectiveness of the IDS/IPS devices you manage? | |
| 5.1(2)(i) | Respond - Describe: | |
| [1] | Your ability to alert designated Museum staff of any suspicious activity that may lead to a security breach and/or provide rapid response to stop or prevent attacks while allowing acceptable traffic that supports Museum’s Internet-based business initiatives. | |
| [2] | The type of notification and communication included as part of your Managed Security Services. Please include the timing associated with each type of notification. | |
| [3] | The manner in which your company prioritizes client notification based on potential event impact. | |
| [4] | How you assure timely OS, firmware, patch, and signature upgrades/updates of all monitoring agents and devices under scope. What is your procedure for performing these changes? Include a description of quality assurance measures. | |
| [5] | Your ability to provide a scalable platform that allows for modification and additional integration with existing network architecture. | |
| 5.1(2)(i) | Recover - Describe: | |
| [1] | Your ability to provide prompt corrective recommendations during an event and assist in investigations and forensic analysis of data. | |
| [2] | Your ability to provide access to support engineers 24x7 with the option to request onsite resources should an incident not be resolvable remotely. | |
| [3] | Your ability to routinely test incident response capabilities and perform exercises with Museum staff to validate process and procedures. | |
| [4] | Your ability to retain log data for an extended time frame or a period mutually agreed upon by both the Museum and the provider. | |
| [5] | The lifecycle of a security event, from initial occurrence to closure. | |
| 5.1(2)(i) | Reporting | |
| 5.1(2)(i)(1) | Standard | |
| [A] | How frequently will we receive standard reports? | |
| [B] | Do you have web-based reporting capability? Provide samples reports and screen shots of web-based interface. | |
| [C] | Do you provide a dashboard with metrics related to the Managed Security Services? | |
| [D] | Do you provide a portal or web interface for processing alerts and notifications? | |
| 5.1(2)(i)(2) | Ad-hoc | |
| [A] | Can we create custom reports? | |
| [B] | Describe the process for requesting ad-hoc reports. | |
| [C] | Provide the timeframe for turnaround of ad-hoc reporting. | |
| 5.1(2)(i) | General Information | |
| [1] | A technical outline of Offeror's IDS/IPS platforms and expertise | |
| [2] | A technical outline of Offeror's SIEM products and services. | |
| [3] | A technical design document showing integration of Offeror's IDS/IPS and SIEM products. | |
| Company Profile (Corporate History & Capability) | ||
| 5.1(3)(a) | Number of years providing Managed Security Services, including details on how long each of Offeror's Managed Security Services have been provided to clients | |
| 5.1(3)(b) | Percentage of total revenues coming from clients who purchase only monitoring and security device management services | |
| 5.1(3)(c) | Quantity and size of existing federal clients | |
| 5.1(3)(d) | Quantity and size of existing non-federal clients | |
| 5.1(3)(e) | Quantity of Managed Security Services customers at the end of last calendar year, currently, and projected for the end of this calendar year (device management, security monitoring, SIEM, and log management only) | |
| 5.1(3)(f) | A description of Offeror's operation centers and sites | |
| 5.1(3)(g) | A description and evidence of industry accreditations and references specific to the Federal government sector | |
| 5.1(3)(h) | A description and evidence of internal security practices and procedures covering physical security of facilities, ownership and locations | |
| 5.1(3)(i) | A description and evidence of staff hiring and vetting procedures | |
| 5.1(3)(j) | A description and evidence of access and authorization controls | |
| 5.1(3)(k) | A description and evidence of third party audits and contingency planning | |
| 5.1(3)(l) | A description and evidence of other internal security practices and procedures not already specified above | |
| 5.1(3)(m) | A description and evidence of a successful defense of an attack | |
| Past Performance (Case Studies) | ||
| 5.1(4)(a)(i) | Describe how any of the top research firms (i.e. Gartner, Yankee, IDC, Forrester, Frost & Sullivan) have ranked your company in the MSSP market and any contract wards your company has won for Managed Security Services. | |
| 5.1(4)(a)(ii) | Have you had an independent review of your MSSP infrastructure and service? Please provide detail on this review including who executed it, when it was executed, scope of review, and type of testing, frequency of testing and summary results. If available, please provide the report. | |
| 5.1(4)(a)(iii) | How many full, dedicated security operations centers (SOCs) support your Managed Security Services? How many dedicated staff members perform the monitoring for the Managed Security Services provided? Where is your primary SOC located? Where are your secondary SOCs located? Describe the level of SOC redundancy and geographic diversity. | |
| 5.1(4)(a)(iv) | How long has your Managed Security Services organization been performing firewall management/monitoring? Do you have any management tool for supporting and monitoring multiple vendor firewalls? If yes, please provide the detail. Do you currently have a firewall configuration checkup procedure? And how often would you do this? | |
| 5.1(4)(a)(v) | Do you have special relationships with the product and platform vendors of the products you will deploy? | |
| 5.1(4)(a)(vi) | Describe how third-party intelligence sources are integrated into monitoring and who those third-party intelligence sources are. | |
| 5.1(4)(a)(vii) | Describe any service limitations or thresholds that we would be charged additional fees for exceeding. How many incidents can be escalated before additional fees are charged? | |
| 5.1(4)(a)(viii) | Provide examples of how threat research has been used to proactively protect customers. | |
| 5.1(4)(b) | References | |
| 5.1(4)(c) | Chronological List of Clients | |
| Account Support & Staffing Plan | ||
| 5.1(5)(a&b) | Key Personnel & resumes | |
| 5.1(5)(c) | General staffing | |
| 5.1(5)(d) | Subcontract management system |
USHMM RFP 9531-16-R-0400 page A&P of &N Managed Security Service Provider
File details come from the government source that posted it. Updated .