Attach L-17 - Tool App Questionnaire (A0005).docx
DOCX document 43 KB Posted
- Attached to
- MDA IT Operations & Engineering Solutions (MIOES) - CANCELED Federal contract opportunity
- Solicitation number
- HQ0857-MIOES-ZA
- Issued by
- DOD Missile Defense Agency
View the file
Other files for this federal contract opportunity
Show all 50
MDA IT Operations & Engineering Solutions (MIOES) - CANCELED has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment L-17
TOOL / APPLICATION QUESTIONNAIRE
A. TOOL / APPLICATION SPECIFICATIONS
What is the name of the proposed tool/application?
What is the high-level function of the proposed tool/application?
What is the classification of the proposed tool/application?
Is this application considered Government off-the-shelf (GOTS), Commercial off the shelf software (COTS), freeware, shareware, proprietary, or open-source?
Who will use the tool being proposed:
a. The general MDA population;
b. A small set of MDA users; or
c. Only accessed and operated by corporate personnel?
B. TOOL / APPLICATION DEVELOPER
1. What company develops the tool/application(s)?
Is the tool/application developer foreign, foreign affiliated or listed as an excluded party?
Is the application implemented in accordance with the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), or other industry security best practice?
Is the software currently supported and maintained (yes/no)?
Note: If the tool/application resides internal to a MDA facility skip Section C and continue to Section D.
C. REMOTE HOSTED TOOL / APPLICATION
1. Will the proposed tool/application reside in an external Defense Security Service (DSS) accredited facility (yes/no)?
If in a DSS accredited facility what organization serves as the host’s current Computer Network Defense Service Provider (CNDSP) / Cybersecurity Service Provider (CSSP)?
For an unclassified tool/application; will the tool/application reside in a controlled, unclassified facility?
If so, what physical and logical security controls are applied?
Is the host compliant with the Federal Information Security Management Act (FISMA); if yes, what FISMA security level?
Is the tool/application hosted in a Federally recognized commercial cloud (yes/no)?
Is the cloud a government private cloud (yes/no)?
Is the cloud authorized through the Federal Risk and Authorization Management Program (FedRAMP); if so, what is the name of the offering and the Impact Level?
Does that cloud only reside in the United States (yes/no)?
Is the tool/application accessible via mobile devices and/or mobile apps?
Does the host have the ability to remote wipe computer assets and mobile devices that have access to data residing in remotely or in a cloud in the event a device is lost or stolen (yes/no)?
Is the host compliant with the Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems?
For each proposed tool/application, provide the information contained in Enclosure 1: PPS and Software Dependencies, Tab 1 – Software. The spreadsheet should accompany this questionnaire and contain a single tool/application per submission.
If external tools/applications are required in order for the application to function/operate effectively, provide the information contained in Enclosure 1: PPS and Software Dependencies, Tab 2 – Software Dependencies. Multiple dependent software packages / versions can be included in the same spreadsheet tab.
What are the bandwidth requirements or limitations?
Is the tool/application directly accessible from the internet (yes/no)?
Is the tool/application PKI enabled (yes/no)?
1. If yes, will this be integrated with MDA’s current active directory or another authoritative directory?
Is the data encrypted in transit, at rest, or in mobile devices (yes/no)?
1) Is the encryption FIPS 140-2 compliant (yes/no)?
What ports, protocols, and services (PPS) must be enabled to allow for the proposed use case; provide the information contained in Enclosure 1: PPS and Software Dependencies, Tab 3 – PPS. Multiple ports, protocols, and services can be included in the same spreadsheet tab.
Note: If the tool/application resides external to a MDA facility skip Section D and continue with Section E.
D. LOCAL TOOL / APPLICATION REQUIREMENTS
1. Is additional hardware required to support the tool/application, or will this be installed on existing infrastructure?
Is the tool/application accessible via mobile devices and/or mobile apps?
1. Does the host have the ability to remote wipe computer assets and mobile devices that have access to data residing in remotely or in a cloud in the event a device is lost or stolen (yes/no)?
For each proposed tool/application, provide the information contained in Enclosure 1: PPS and Software Dependencies, Tab 1 – Software. The spreadsheet should accompany this questionnaire and contain a single tool/application per submission.
If external tools/applications are required in order for the application to function/operate effectively, provide the information contained in Enclosure 1: PPS and Software Dependencies, Tab 2 – Software Dependencies. Multiple dependent software packages / versions can be included in the same spreadsheet tab.
What are the bandwidth requirements or limitations of this tool/application?
Is the tool/application PKI enabled (yes/no)?
1. If yes, will this be integrated with MDA’s current active directory or another authoritative directory?
Is the data encrypted in transit, at rest, or in mobile devices (yes/no)?
1) Is the encryption FIPS 140-2 compliant (yes/no)?
What ports, protocols, and services (PPS) must be enabled to allow for the proposed use case; provide the information contained in Enclosure 1: PPS and Software Dependencies, Tab 3 – PPS. Multiple ports, protocols, and services can be included in the same spreadsheet tab.
E. TRAINING
1. Is training for the use and maintenance of the tool/application required (yes/no)?
1. What is the estimated time to complete the training?
F. RIGHTS IN TECHNICAL DATA AND COMPUTER SOFTWARE
1. Tool/application-generated data
1. Does the tool/application-generated data support import and export to common file formats (yes/no)?
1. What are the common file formats that the data can be saved to?
1. DFARS 252.227-7013 Rights in Technical Data—Noncommercial Items
a. Identify the specific technical data associated with the tool/application—including data generated by the tool/application—that will be delivered to the Government under the contract.
b. With what rights will the technical data be delivered?
c. Where are the costs associated with tool/application development, maintenance, and delivery proposed?
1. DFARS 252.227-7014 Rights in Noncommercial Computer Software and Noncommercial Computer Software Documentation and H-35 Incorporating Commercial and Open Source Software
a. Identify the specific computer software and computer software documentation associated with the tool/application that will be delivered to the Government under the contract.
b. With what rights will the software and software documentation be delivered?
c. Where are the costs associated with tool/application development, maintenance, and delivery proposed?
ENCLOSURES
Enclosures Note: Refer to IRES RFP, Attachment L-11 - EITS SOO Enclosure 7: Application Versions
Enclosure 1: PPS and Software Dependencies
SOURCE SELECTION INFORMATION – SEE FAR 2.101 AND 3.104
FOR OFFICIAL USE ONLY
PPS and Software Dependencies.xlsx Tab1 - Software software/software packages Manufacturer Version Matches to software and version within Attach L-11 - EITS SOO (A0001) Enclosure 7: Application Versions (yes or No)
Tab2 - Software Dependencies software/software packages Manufacturer Version Matches to software and version within Attach L-11 - EITS SOO (A0001) Enclosure 7: Application Versions (yes or No)
Tab3 - PPS
Port Protocals Service Description image1.emf
File details come from the government source that posted it. Updated .