Attachment 1 CBII PWS.docx

DOCX document 153 KB Posted

Attached to
Cloud Based Internet Isolation Service Federal contract opportunity
Solicitation number
HC108426R0005
Issued by
Defense Information Systems Agency

About this file

This is a Performance Work Statement (PWS) for a Cloud Based Internet Isolation (CBII) Managed Service contract that establishes requirements for maintaining and enhancing the Department of War's remote browsing isolation solution using Menlo Security, Inc.'s Cloud Browser (MSCB) technology. The service supports up to 3.4 million DoW users with secure, isolated internet browsing to protect against cyber threats, malware, and data loss. The contract period runs from April 15, 2026, through April 14, 2031, with a one-year base period and four one-year option periods, plus a potential six-month extension. The contractor must deliver a FedRAMP+ Level 2 compliant, unclassified cloud environment with capabilities including destination-based URL filtering, malware scanning, data loss prevention, detonation chambers, browsing session recording, and AI/ML-powered cyber defensive auto-mitigations through HEAT Shield enablement.

Core performance requirements span seven major task areas: Program Support (contract management, scheduling, documentation, and reporting), Production Environment Management (cloud service delivery and sustainment for 3.4 million users), Operational Service Support (24/7/365 tiered help desk with Tiers I-III, knowledge management portal, and incident/request fulfillment), Accreditation & Authorization (RMF compliance, security engineering, and system security planning), Migration and Sustainment (user migration support for existing systems), Training (classroom, hands-on, and online instruction for users and administrators), and Engineering Support (systems engineering, architecture design, network engineering, configuration management, testing, cybersecurity, and mobility integration). The contractor must comply with specific performance standards with Acceptable Quality Levels (AQLs) ranging from 90 to 100 percent depending on task, support IPv6 and dual-stack networking, integrate with DISA's Joint Infrastructure security tools, and maintain interoperability with DoD systems including mobile device management and enterprise identity management. Personnel require final Secret security clearance with NIPRNET/SIPRNet access, and the contractor must maintain facility and personnel security clearances, with approximately 30 percent of personnel requiring Secret clearance eligibility. Work may be performed remotely with occasional on-site support at DISA Fort Meade, Maryland.

View the file

Other files for this federal contract opportunity

Other files attached to Cloud Based Internet Isolation Service, newest first.
File Type Posted
RFP SF30 HC108426R0005_Amend 0005.pdf PDF
Attachment 3 CLIN Pricing Worksheet_Amend 0005.xlsx XLSX spreadsheet
Attachment 9 RFP Questions and Answers Template_Amend 0005.xlsx XLSX spreadsheet
RFP SF 30 HC108426R0005_Amend 0004.pdf PDF
Attachment 1 CBII PWS_Amend 0004.docx DOCX document
Attachment 9 RFP Questions and Answers Template_Amend 0004.xlsx XLSX spreadsheet
Attachment 3 CLIN Pricing Worksheet_Amend 0004.xlsx XLSX spreadsheet
Attachment 1 CBII PWS_Amend 0003.docx DOCX document
Attachment 9 RFP Questions and Answers Template_Amend 0003.xlsx XLSX spreadsheet
RFP SF 30 HC108426R0005_Amend 0003.pdf PDF
Attachment 3 CLIN Pricing Worksheet_Amend 0003.xlsx XLSX spreadsheet
Attachment 9 RFP Questions and Answers Template_Amend 0002.xlsx XLSX spreadsheet
RFP SF30 HC108426R0005_Amend 0002.pdf PDF
Attachment 3 CLIN Pricing Worksheet_Amend 0002.xlsx XLSX spreadsheet
RFP SF 30 HC108426R0005_Amend 0001.pdf PDF
Attachment 2 QASP_Amend 0001.docx DOCX document
Attachment 10_CUI_CBII JA_Redacted.pdf PDF
Attachment 9 RFP Questions and Answers Template_Amend 0001.xlsx XLSX spreadsheet
Attachment 1 CBII PWS_Amend 0001.docx DOCX document
Attachment 4 CDRLS_Exhibit A_Amend 0001.pdf PDF
Attachment 10 CUI_CBII JA_Redacted.pdf PDF
Attachment 7 GFP Attachment.xlsx XLSX spreadsheet
Attachment 6 Non-Disclosure Agreement.docx DOCX document
Attachment 3 CLIN Pricing Worksheet.xlsx XLSX spreadsheet
Attachment 2 QASP dated 2.23.2026.docx DOCX document
Attachment 9 RFP Questions and Answers Template.xlsx XLSX spreadsheet
Attachment 8 Subcontracting Plan Review Checklist.docx DOCX document
Attachment 4 CDRLS_Exhibit A.pdf PDF
RFP SF 1449 HC108426R0005.pdf PDF
Attachment 5 DD254.pdf PDF
Show all 30

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

Cloud Based Internet Isolation (CBII) Managed Service

Award/Mod Effective
Version Date

Award

Contract Number:
To be determined (TBD)
Task Order Number:
TBD
Contractor Name
TBD
Tracking Number:
HC108426R0005

Follow-on to Previous Production Other Transaction Authority (OTA) Agreements:

HC10842090006

1. Contracting Officer’s Representative (COR).

a. Primary COR. See DITCO Additional Text G1 - Points of Contact

b. Alternate COR. See DITCO Additional Text G1 - Points of Contact

c. Property Administrator. See DITCO Additional Text G1 - Points of Contact

2. Contract Title.

Cloud-Based Internet Isolation (CBII) Managed Service

3. Background.

Since 2020, the Department of War (DoW) has utilized CBII, leveraging Menlo Security, Inc.’s, Cloud Browser (MSCB) solution, via the production OTA agreement to protect DoW users from evolving cyber threats. This five-year deployment has continually adapted to mitigate increasingly sophisticated malicious tactics, techniques, and procedures.

CBII, utilizing the MSCB solution, provides significant value by transforming DoW’s web browsing experience, resulting in a safer, more efficient, and more resilient operation. By supporting major browsers (Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari), the MSCB offers increased flexibility, allowing organizations to leverage existing infrastructure, reduce training costs, and improve user productivity.

The MSCB solution for CBII significantly enhances DoW’s security posture by masking user browsing activity, hindering intelligence gathering by threat actors. It provides robust, multi-layered protection against web-based threats by isolating online plug-ins and screening downloads, preventing malicious code from compromising DoW computers and networks. It also blocks access to known malicious websites and restricts access to inappropriate content, improving compliance and minimizing distractions. Integration with DISA's DoW Mobile Unclassified Capability extends these protections to mobile devices. Browsing session recording provides insights for identifying potential insider threats and improving security protocols.

Beyond security, the MSCB enhances operational effectiveness and resilience. The expansion of MSCB to Google Cloud Platform alongside Amazon Web Services increases redundancy, improves load balancing, and ensures continuous availability of the CBII environment, even during outages, guaranteeing uninterrupted .com web browsing for DoW personnel worldwide. The CBII platform utilizing MSCB offers a comprehensive suite of advanced capabilities that proactively protect DoW networks and data from evolving web-based threats. These include:

· Destination-based whitelisting and blacklisting: Controlling access to trusted and untrusted websites.

· Web content filtering and site categorization: Preventing exposure to malicious or inappropriate content based on real-time risk assessments.

· Malware scanning and sandboxing: Identifying and neutralizing malicious code before it can reach DoW systems.

· DLP: Preventing unauthorized data exfiltration.

· Web isolation within a secured container: Ensuring compromised websites cannot impact the underlying network.

Menlo Security products have been crucial to DISA's mission, protecting millions of DoW users across major organizations, including the Office of the Secretary of War and the Defense Logistics Agency. As the DoW's remote browsing isolation solution for five years, the MSCB has prevented billions of cyber threats, offloaded hundreds of petabytes of data, and improved responsiveness. From January to March 2025, the system detected and mitigated on average 25 million threats monthly and offloaded over 4 petabytes of data each month, reinforcing its critical role in defending the DoW in cyberspace.

The CBII solution requires continuous operation within a secure, FedRAMP+ Level 2 compliant, unclassified Cloud Service Offering to protect DoW networks from online threats. This environment, supporting up to 3.4 million DoW users worldwide with 24/7 secure internet browsing, threat isolation, and bandwidth freeing, is already powered by Menlo Security, Inc. This follow-on effort focuses on maintaining and enhancing this system by continuing to utilize Menlo Security, Inc.'s cloud environment and adding smart, automated defenses (using artificial intelligence and machine learning (AI/ML)) to proactively block cyberattacks, ensuring a strong and reliable defense against web-based threats.

MSCB is currently deployed and integrated within the Department of Defense Information Network (DODIN) and DISA requires the ability to maintain current systems while meeting future system and network capacity and performance requirements. The CBII solution must be interoperable and compatible with the DISN Joint Infrastructure (DJI) security stack located at DISA’s ten global IAPs; must comply with DoW mandates for supporting IPv6 network traffic; and must adhere to risk management assessment and authorization requirements. The current capability, MSCB, complies with these requirements. Moreover, MSCB is interoperable with DISA’s advanced DJI security tools to include Web Content Filtering, Enterprise Break & Inspect, and Full Content Inspection and the accreditation by DISA’s Risk Management Executive security accessors is also feasible in this deployed state, highlighting the serious cyber protections that MCSB offer.

4. Objectives.

Utilizing MSCB, the objective is to maintain a secure browser isolation solution to be delivered as a managed service for the purpose of providing up to 3.4 million Department of War (DoW) users with safe and reliable access to web resources. The solution and managed service provider (MSP) is critical to mitigating cyber threats, enhancing information system security, and eliminating vulnerabilities in critical infrastructure that adversaries could exploit.

5. Scope.

The scope of this contract requires a managed service for the Government that provides a cloud environment utilizing MSCB. This solution includes all hardware, software, and infrastructure components required to deliver to the Government a secured, flexible, cloud environment that is readily available, scalable, globally accessible, and provides enhanced cyber security protections in an isolated, secured cloud environment.

Capabilities within the MSCB-engineered CBII platform will include but are not limited to destination-based whitelisting and blacklisting, web content filtering, site categorization and risk assessment, malware scanning and sandboxing, data loss prevention and web isolation within a secure container.

The managed service, an essential requirement of the contract, will provide managed services to include program support, a tiered service desk infrastructure, engineering, migration support, user and administrator training, and accreditation & authorization (A&A) support.

The Government may require surge support during the base or any option period, and surge modifications will be within the scope of the contract and provide increased support for the defined task areas of this PWS. Surge support over the life of the contract will not exceed 5% of the contractor’s total proposed cost/price for the base and all option periods, excluding any six-month extension of services pursuant to FAR 52.217-8.

6. Performance Requirements.

* All Deliverables and Contract Data Requirements Lists (CDRLs) are listed in Section 16.

6.1 Task 1 - Program Support

The contractor shall provide general support to include drafting agendas, memos, briefings and reports; and participation and facilitation of meetings. The contractor shall provide audio/video support and audio teleconferencing; web content editing and graphic support; financial management; provide program management support for all developed processes, documents, and products including configuration management (CM) and engineering review boards; and other associated administrative tasks necessary to support the program. The Contractor shall provide support for capabilities in both the lab (if a lab instance exists) and production environments. The Contractor shall provide support for the planning, set-up, execution, removal and any follow-on activities related to any production activities.

6.1.1 Subtask 1 – Contract Managed Services

The Contractor shall provide contract managed services to interface with the CORs regarding task delegation, daily tasks, deliverables, and contract management/scope of work, budget and all other daily requirements. The contract managed services shall be formalized and documented in the contractor-provided Contract Management Plan (CMP). The contractor shall be responsible for ensuring that all tasks from the COR are delegated correctly and there is an understanding of all tasks and their due dates. The contractor shall coordinate with the COR for acceptable deadlines for tasks. The contractor shall provide a POC to be the primary interface between the COR and the contractor team.

Plans of Actions & Milestones (POA&Ms) The Contractor shall document and track the remediation of identified security weaknesses and vulnerabilities related to the CBII system. The POA&Ms will outline the specific tasks required to correct deficiencies, the resources required to accomplish those tasks, the milestones to be met, and the scheduled completion dates for each milestone. POA&Ms will serve as a corrective action plan that facilitates a structured approach to mitigating risks.

6.1.2 Subtask 2 - Schedule Management

The Contractor shall provide key milestone and activity information via the provision of a Microsoft Project schedule to support the Integrated Master Schedule (IMS). The contractor shall be prepared to incorporate changes to the schedule based on changing events and/or on funding decisions that affect the activity of the program. The contractor shall analyze deviations from the schedule baseline once it is established, determine impacts to the overall program, and provide program documentation, reports or briefing documentation to the Government. In addition to master schedule support, the contractor shall maintain a detailed Work Breakdown Structure (WBS) for each task on the contract.

6.1.3 Subtask 3 - Weekly Activity Report (WAR)

The contractor shall provide a WAR detailing program activities performed by the contractor that describes progress/status for the week reported in support of this contract. The WAR will include identification of any issues that require Government intervention for resolution or may have an impact on agreed-upon delivery. With concurrence by the Government, the contractor provides a template showing the topic areas they will cover.

6.1.4 Subtask 4 - After Action Report

After each incident that caused CBII operational impact to customers, the contractor shall provide an After-Action Report, describing actions taken to resolve issues or complete required efforts, as well as any further action necessary to remedy unresolved issues. The report shall include further details relevant to the event, such as: users impacted, description of the impact, duration, incident start and end times, actions to be put in place to prevent a similar event in the future, and other event related information requested by the COR.

6.1.5 Subtask 5 – Program/Briefing Documentation Support

The contractor shall manage, maintain, and update present and future documentation. The contractor shall prepare and finalize all presentations/briefings to ensure compliance with Government standard template requirements. The contractor, with collaboration of the Government, shall review and approve the Documentation Management Plan to ensure documentation, repositories, and ownership are clearly understood. The contractor shall be expected to use and maintain on a weekly basis the DISA SharePoint and/or any other repository system the Government may choose in order to provide online access to program artifacts to include: test plans, implementation plans, diagrams, requirements, white papers, etc., in a format and accessible to the appropriate program stakeholders, authorized by the Government. The Government will provide oversight to the documentation housed on the site to ensure compliance with all security classifications.

6.1.6 Subtask 6 – Contract Management

Provide all managed services necessary to manage and oversee all aspects of the contract, monitor work performance, measure results, and ensure delivery of contracted product deliverables and solutions support management and decision-making and facilitate communications. Identify risks, resolve problems, and verify effectiveness of corrective actions. Institute and maintain a process that ensures problems and action items discussed with the Government are tracked through resolution and shall provide timely status reporting. Results of Contractor actions taken to improve performance shall be tracked, and lessons learned incorporated into applicable processes. Establish and maintain a documented set of disciplined, mature, and continuously improving processes for administering all contract efforts with an emphasis on cost-efficiency, schedule, performance, responsiveness, and consistently high-quality delivery. For the CBII environment, the Contractor shall provide a Monthly Service Utilization, Capacity, Outage, Upgrade Status, and Forecast Report.

Kick-Off/Post Award Meetings/Conferences

The contractor shall deliver presentation materials and meeting minutes from the initial kick-off meeting and all follow-on progress meetings. This deliverable must document the project management plan, key milestones, discussion points, and all assigned action items to ensure mutual understanding of the requirements.

6.2 Task 2 – Unclassified/NIPRNET Production Environment (engineered by Menlo Security, Inc.)

The Contractor, as a managed service, shall deliver, deploy, and sustain an unclassified Cloud Service Offering (CSO) that is engineered and developed by Menlo Security, Inc. (referred to as the MSCB) that enables the DoW to isolate Internet traffic, mitigate threats, and free up the bandwidth capacity, by redirecting Internet browsing from the end user’s desktop into a remote cloud-based server. The CSO shall meet all the FedRAMP+ Level 2 (Non-Controlled Unclassified Information) distinguishing requirements and characteristics. The Contractor shall adhere to the performance objectives identified within this section and subsection of this PWS and shall be required to perform testing activities/events (i.e., integration, acceptance, operational) in accordance with (IAW) the testing requirements, to verify the proper interoperability between the CSO and core integration points.

System-Wide: Core System-wide Requirements form the foundation of the CBII CSO (engineered by Menlo Security, Inc.) and provide the primary features and functions.

· The system shall provide the ability to send either all or a configurable portion of user Internet activity at the browser to a Cloud-based Contractor solution external to the DODIN.

a. Isolate all Internet code execution in the Contractor’s accredited cloud environment

b. Isolate each user’s session

c. Provide the ability to route Internet browsing activity of Android and iOS mobile devices, both connected and not connected to DODIN, via the solution.

· Provide access via a proxy for mobile users that are not connected to the DODIN

· Integrate with MDM solution (e.g. MobileIron or Menlo Security, Inc. mobile client.)

d. Support data encryption and encrypt the connection between the user endpoint and system host.

e. Browsing capability shall provide non-attribution such that no DoW metadata is visible to any third party.

f. Provide the ability to downgrade video and audio quality for streaming Internet media (configurable Quality of Service (QOS)).

· Further downgrade video quality in background or inactive tabs.

g. Provide compression to limit bandwidth utilized in delivering rendering of isolated Cloud session back to the client workstation.

h. Provide the ability to timeout connections on inactive tabs after a configurable time limit.

i. Provide the ability to deploy isolation via Proxy Auto Configuration (PAC) file.

· Support storage of the PAC file in a government-approved location

· Provide the ability to deploy isolation via Proxy Chaining methodology.

· Provide for multi-tenancy via a hierarchical model that allows web and configuration policies to be applied to and be modified by individual DoW components so that:

a. A master tenant can apply global policies that supersedes those of sub tenants.

b. Authentication attributes returned may be leveraged for policy-oriented decisions.

· Ability to apply policies over a specified timeframe. (e.g., Users cannot browse the internet between 8pm and 4am daily).

· Securely store and transmit data in a manner that ensures the confidentiality, integrity, availability, and source authenticity of the data.

· Provide information near real-time; support a page load time of no more than 5 seconds; offer a latency of no more than 100ms round trip between user endpoint and the system.

· Support 10 Gigabits per second throughput minimally

· Support browsing a minimum of 25 concurrent tabs without drop in configured QOS.

· Include content control software at the host location to:

a. Scan documents for malicious code/infection before transmitting them to the DODIN.

b. Provide intrusion protection for persistent document storage commensurate with protections in the National Institute of Standards and Technology Special Publication 800-122 required for storing personally identifiable information.

c. Allow blacklisting and whitelisting Uniform Resource Locator (URL)s by URL path, domain, category, geolocation, and uncategorized URL blocking:

· provide for updating ‘uncategorized’ URL with categorization provided by user within 0-1 hour; and

· provide the user the ability to update a blacklisted site to a whitelisted site if wrongly categorized within 0-1 hour; and

d. Allow and block file downloads/uploads by file type.

e. Allow to open downloaded files within the cloud session.

f. Apply a distinct set of policies to browser and non-browser traffic.

g. Provide background information used to determine the categorization of a URL.

· Log all web requests and tie the web request to specific users from authentication through session end.

a. Capture logs from content control software, blacklisting/whitelisting, data about downloaded files, logs based on source and destination geolocation.

b. Export log data to government-defined SIEM tools.

· Logs for all DoW tenants shall be exported/ingested into DISA’s SIEM tool.

· Additionally, logs for each DoW component shall be available for export/ingest to that component’s SIEM tool.

· Log data is owned and maintained by DISA

c. Log files are separated by hierarchical model and secured appropriately.

d. Log detonation chamber report details, log actions such as upload, download, application request or other type of action.

e. Log user inputs such as search engine queries, log both browser and non-browser web requests.

f. Log vulnerable services in use by destination web sites.

g. The system administration console shall allow exporting of all log data within a specified time frame.

· Ability to allow distinct groups to set thresholds for Internet usage on a per-client basis; send notification to the user if daily bandwidth threshold is within a configurable percentage of being met, has been met, has been exceeded; and send an automated e-mail to designated e-mail address(s) if threshold has been exceeded by a configurable amount.

· Provide non-repudiation of browser activity.

· Support all current and legacy web content technologies such as Java, Flash, Silverlight, Hypertext Markup Language (HTML), Windows 11, mobile devices running DISA/DoW-supported versions of Android and iOS, and common web browsers (i.e. Firefox, Chrome, Edge, Safari). Note* No requirement to support technologies that are no longer available in the major browsers.

· Support the ability to configure the user session inactivity timeout.

· The system shall support the ability to resume a session after time out.

· The system shall provide immediate response to user inputs in high latency conditions.

· The system shall allow searching functionality in documents that are viewed in the cloud.

· The system shall support creation of user groups for the purpose of applying policies.

· The system shall provide a customizable and configurable administration console.

· Provide a customizable report that returns the number of users that have accessed the system in a specified timeframe.

· Provide a customizable bandwidth reduction report for a specified timeframe.

· The system shall provide a latency metric that DoW admins can access seamlessly and in real-time.

· The system shall store session cookies for each user to minimize the number of logins necessary on websites.

· The Contractor shall submit to protocol analysis of the traffic between the service and client.

· The Contractor shall notify the government 30 days prior to implementing any changes that require configuration changes to the government network.

· The Contractor shall aid government administrators in developing policies and management planning recommendations.

· The Contractor shall aid in troubleshooting websites that are not properly isolating.

· The system shall isolate URLs that are opened from email.

a. Provide the ability to view email attachment files remotely in the isolation environment (Optional).

· Provide a detonation chamber capability to allow execution of suspicious code prior to download.

· Provide a capability that records a browsing session in detail.

· Encrypt and store browser recording data in a data impact level 2 enclave.

· Provide a controlled export function for files that are stored.

· Provide cyber defensive auto-mitigations that responds to cyber threats, attempted breaches, or other malicious threat vectors by utilizing CBII platform-enabled machine learning (ML) and artificial intelligence (AI) to identify, neutralize, and eliminate these cyber threats.

Cybersecurity: The government has outlined the following requirements related to how the Contractor must implement a secure service to ensure the DODIN is protected against malicious codes, attacks, and unauthorized access.

· Provide a capability to detect, prevent, respond, and report malicious code injection from the CBII Environment to the DODIN, to include deterring propagation of malware within the DODIN.

· Provide a capability that detects and responds to anomalous network behavior through signatures or advanced analytic techniques affecting the CBII Environment.

· Provide a capability that detects, prevents, responds to, and reports single and multiple node denial of service (DOS) attacks from the CBII Environment to the DODIN.

· Provide a capability that detects, prevents, responds to, and reports bidirectional traffic flows having unauthorized source and destination IP addresses, protocols, and TCP/UDP ports between the DODIN and CBII Environment.

· Provide a capability that detects, prevents, responds to, and reports attacks from the CBII Environment against the DODIN DNS.

· Provide a capability that detects, prevents, responds to, and reports IP Address Spoofing and IP Route Hijacking between the DODIN and CBII Environment.

· Provide a capability that detects, prevents, responds to, and reports unauthorized data interception between the DODIN and the CBII Environment.

· Provide an anti-virus capability and heuristic analysis within the cloud environment to block malware from being downloaded into the DoW environment.

· Provide a capability that detects, prevents, responds to, and reports passive and active network enumeration scanning originating from within the CBII Environment to the DODIN.

· Provide a capability that detects, prevents, identifies, responds to, and reports application session hijacking from the CBII Environment to the DODIN.

· Provide a capability that detects, prevents, identifies, and responds to, reports and correlates with DoW advanced persistent threats (APTs) against the CBII Environment.

· Provide a capability that detects, prevents, identifies, hunts, and responds to, reports and correlates with DoW APTs originating from within the CBII Environment to the DODIN.

· Provide information about the severity of a blocked site, such as known to be malicious, suspected malicious, etc.

· Ensure that, whenever possible, technology components can automatically reconfigure, optimize, self-defend, and recover with little to no human intervention. In addition, attempts made to reconfigure, self-defend, and recover must produce an incident audit trail.

· Provide a Data Loss Prevention (DLP) capability with reporting functions to review DLP policy violations and notifies the user when they violated DLP policies defined by the government and in accordance with DLP requirements identified in the CCSRG, CNSSI 1253, NIST SP 800-137, and the ISCM for Federal IS and Organizations.

· DLP capability shall be natively within the CBII solution, capture file uploads, user inputs to web forms, and capture the offending data for further analysis by the Government.

· Provide a controlled export function for files that are stored within the CBII environment.

· Route all user file downloads through a DoW-specified security stack (e.g., Joint Regional Security Stacks).

· Meet all applicable Information Assurance Vulnerability Alerts (IAVAs), Operation Orders (OPORDs), and Fragmentary Orders (FRAGOs).

· Provide cyber defensive auto-mitigations that responds to cyber threats, attempted breaches, or other malicious threat vectors by utilizing CBII platform-enabled machine learning (ML) and artificial intelligence (AI) capabilities that identifies, neutralizes, and eliminates these cyber threats.

Identity Management: Identity Management is the combination of technical systems, policies, and processes that create, define, and govern the utilization and safeguarding of identity information, as well as managing the relationship between an entity and the resources to which access is required. The Government has outlined the following requirements CBII must be able to support associated with creating, defining, and governing the utilization and safeguarding of identity information, as well as managing the relationship between an entity and the resources to which access is required.

· Store and manage identity attributes in accordance with policy (e.g., privacy laws) and standards (e.g., naming conventions, data formats).

· Support DoW PK-Enabled/PIV authentication either natively or via token from an authentication proxy.

· Process derived credentials for authentication, for users accessing CBII service using mobile devices without smart card readers.

· Utilize DoW-provided Directory service for user profiles; and provide a mechanism to associate authenticated users with the correct organizational tenant.

· Provide a PKI login for authorized government designated personnel to access the administration console.

· Check for certificate expiration, verify a trusted Certificate Authority (CA) issued the certificate, and confirm that the certificate has not been revoked.

· Support Role-Based Access Control (RBAC) and grant system administrators access to configure as required by the user role.

· Interoperable and must be able to integrate with identity credential and management (ICAM) features and technologies

Core Integration Points: The following subsections outline the core service support functions and integration points that provide technology services to DoW. The Contractor will be required to interoperate the CBII service with the outlined DoW supporting infrastructure and services. CBII must interoperate with these systems and must use the services exchanged to enable CBII to operate effectively in the DoW environment.

· Internet Access Point (IAP): allows users to access the Internet from the DODIN and allows users to access CBII services from the public Internet either as authenticated users via a CAC, or via a VPN from GFE, or as non-authenticated guest users.

· Traffic traversing the IAP will be subject to inspection.

· The Contractor will Interface with the IAP to enable CBII subscribers to access internal CBII resources from the Internet.

· CBII must be configurable to allow for additional cyber threat inspections (files and traffic) to include screening by the current and future DISN Joint Infrastructure (DJI) Security Stack Tools located at the IAPs – current DJI tools includes Web Content Filtering (WCF), Enterprise Break & Inspect (EBI), and Full Content Inspection (FCI) Service.

· DoW Network Transport/Routing & Hosting: The NIPRNet is the unclassified IP data service for DoW and mission partners and supports DoW applications such as email, web services, and file transfer.

· Natively support IPv6 IP addresses, for IPv6 websites and connection from IPv6 endpoints

· Must comply with DoW mandates for supporting both dual stack IPv4/IPv6 network traffic and IPv6 to IPv6 only network traffic

· Support connections to websites utilizing Secure Sockets Layer (SSL) 3.0 (and future SSL versions) and Transport Layer Security (TLS) 1.0-1.3 (and future TLS versions).

· Utilize the DoW authoritative DNS-over-TLS when available.

· Support Encrypted Server Name Indication (ESNI) when available.

Testing: In the event CBII is required to undergo future test events led by the Joint Interoperability Test Command (JITC), another DISA activity, or an external operational testing agency, the contractor will be required to support and validate the CBII service, as necessary. Future Developmental Testing (DT) could focus on performance, interoperability, availability, and cybersecurity requirements. Future Operational Testing (OT) could focus on operational effectiveness, suitability, and survivability/cybersecurity. The government, at its discretion, may require a robust cybersecurity T&E program to supplement the traditional Risk Management Framework authorizations. Artifacts created during FedRAMP approval process may be utilized for existing environments testing assessment, but not in lieu of rigorous cybersecurity testing.

· Provide a Contractor-engineered test environment to simulate the operational environment configuration.

· Test CBII service and components in accordance with the DoW Enterprise Service Management Framework (DESMF).

· Provide a failure reporting, analysis, and corrective action system (FRACAS) to capture, track, and resolve integration and test defects.

· Allow government oversight of contractor conducted testing activities in the CBII environment.

· Provide access to patch release notes.

· Perform functional testing to identify issues and defects using contractor provided methods to test the CSO components, functions, interfaces and integration points.

· Conduct load, latency, and stress performance tests to demonstrate rapid elasticity and on demand allocation of resources within the representative CBII test environment.

· Support government DT&E, OT&E and IOP, to include cybersecurity testing in accordance with the DoW Cybersecurity T&E Guidebook process outlined at: https://www.acq.osd.mil/dte-trmc/docs/CSTE%20Guidebook%202.0_FINAL%20(25APR2018).pdf

· Ensure fixes, patches, and upgrades are first deployed and demonstrated in the CBII T&E environment prior to deploying to the operational environment.

· Grant Government designated personnel access to system logs, network packet captures, and other diagnostic information to support problem diagnosis and resolution in near real-time.

· Delineate the measurable conditions that determine the state of the feature, such as “UP”, “DEGRADED”, or “DOWN” provided by CBII.

· Provide a performance monitoring system that supports root cause analysis for problems experienced with the CBII service.

Mobility: DoW Mobility provides enterprise-level unclassified mobile communication services that ensure interoperability, increased security, access to information and reliable service to the mobile workforce. These service offerings are composed of secure networking and gateway infrastructure that extend enterprise services (e.g., email) to mobile devices; an enterprise Mobile Device Management (MDM) system that provides application layer confidentiality, integrity, and authenticity; and an enterprise Mobile Application Store (MAS) that hosts mobile applications. Within this PWS, mobility devices refer to any DoW-Approved portable computing device, such as a smartphone or tablet computer, running Blackberry OS, Apple IOS, or Android. The Government has outlined the following requirements to ensure the CBII service can be leveraged via a mobile device:

· Interface with the DoW Mobility Gateways to enable mobile subscribers to access internal service resources.

· Ensure that the appropriate ports and protocols are enabled through the Mobility Gateways to allow appropriate access to the services.

· Support DoW PKI derived credentials and single sign-on (SSO) procedures for mobile devices as specified in the DoD Cyber Exchange (https://cyber.mil/pki-pke/purebred), or other National Institute of Standards & Technology (NIST)-compliant Personal Identity Verification (PIV)/PKI implementations adopted by other federal departments and agencies.

· Support Kerberos Constrained Delegation (KCD) for Enterprise Mobility Management (EMM) or other DoW accredited equivalents.

· Interoperate with DoW-approved mobile credentialing systems relating to the management encryption and security of traffic between mobile devices and the enterprise; support configuration to utilize delegation of authentication to multiple services.

· Support industry standards such as ActiveSync, S/MIME and client authenticated TLS using DoW PKI or other DoW approved credentials.

· Integrate with existing DoW MDM solutions and ensure integration is not affected as existing mobility devices are updated, and when subsequent MDM solutions are added.

· Register the ports and protocols required to access from mobile devices with the Ports, Protocols, and Services Management (PPSM) as directed by DOD Instruction 8551.01.

Event Management: Event management refers to the identification, prioritization and response to IT infrastructure incidents, or events. Events are detectable or discernible occurrences that affect the management of the infrastructure or the delivery of the service. Events require an impact evaluation to minimize service impairment. Events are typically delivered as notifications created by a Configuration Item (CI), or monitoring tool. Event management includes occurrence or action that affects the ability to provide services, and as a subset of the service management framework, enables the day-to-day normal operations, detects and investigates incidents, determines the correct control action, and escalates exception conditions in the form of warnings or exceptions. Events are used to automate many routine activities to simplify the sustainment of the system and can be applied to numerous aspects of the service management framework. This section outlines the dependencies needed to ensure end-to-end monitoring that maximizes availability, using key performance indicators (KPIs) as a benchmark metric for services.

· Allow customizable operational systems monitoring views, based on specific organization monitoring requirements.

· Make event notifications available through other government approved communication means (e.g., different from email). Notifications do not have to be a "push" alert and can be passive.

· Provide an alert mechanism to notify the appropriate government designated personnel when system capacity, resource utilization, service failures, or service degradation thresholds have been exceeded. The thresholds must be configurable by authorized government designated personnel based on operational needs.

· Identify system trends (i.e., predictive analytics), conduct incident analysis, and identify emerging threats to the health and welfare of the system as needed.

· Provide access to government designated personnel to performance data through a web browser with the ability to generate reports. Government to coordinate with contractor to create custom reports from the admin console or Dashboard (e.g. bandwidth savings, background information used to determine categorization of a URL, latency metric, provide information about the severity of a blocked site, configurable dashboard views.)

· Provide a web-based dashboard for authenticated and authorized government designated personnel to monitor resource utilization, service failures, and degraded service.

· Collect system performance data every N second on a continuous basis. The value N must be configurable and have a default value of 300.

Incident Management: Incident management is the process of ensuring reliable, secure and uninterrupted availability of the ecosystem infrastructure and all its dependencies. The purpose of incident management is to restore normal service operations as quickly as possible and minimize the adverse impact on operations, thus ensuring that the best possible levels of service quality, security, and availability are maintained. The focus is on reducing the duration and consequences of service outages. The scope includes any disruption or potential disruption of service, and categorizes incidents as Normal, Major, or Security related. Incidents that have the highest impacts and are most disruptive to the service components must be defined as major incidents. Managing major incidents is the most important aspect of the incident management process. Security incidents result from activities intended to disrupt or degrade services, rather than due to human error or component failures. Security incidents have different reporting criteria and must follow the requirements outlined in the Cybersecurity section of this document. All other incidents are considered normal. In addition, incident management must account for maintenance, version management, patch control, and configuration management that guarantees the survivability of resources.

· Provide an incident management capability via a web browser to government designated personnel.

· Notify the CBII PMO and other government designated personnel within 60 minutes of detecting an outage.

· Notify the CBII PMO and other government designated personnel within 60 minutes of detecting a data breach or data loss.

· Offer a service dashboard, accessible via a web browser, which provides visibility into current usage and infrastructure status.

· Comply with the DOD Cloud Computing (CC) Security Requirements Guide (SRG) v1.3 defined control System Development Life Cycle (SA-3).

· Support operations necessary to address and escalate incidents, resolve root-causes of problems, fulfill requests, and proactively and reactively identify events.

· Support the necessary operations to control, identify, record, and report on all components associated with providing secure and reliable services to mission partners.

· Comply with Section 5.3.2 “Change Control” of the DOD Cloud Computing (CC) Security Requirements Guide (SRG) as well as the Configuration Management (CFM) control family defined in NIST 800-53 rev4.

· Execute effective measures to protect all CSO equipment and data from potential environmental threats.

· Provide a process for informing users a minimum of 21 business days in advance of Authorized Service Interruption (ASI) and planned or scheduled major outages and infrastructure changes.

· Provide root-cause reports and fixes for major outage occurrence resulting in greater than 1-hour of unscheduled downtime.

Request Fulfillment: Request Fulfillment addresses service demands originated from government designated personnel, a mission partner by direct communication or automated system.

· Provide a web-based capability for authenticated and authorized government designated personnel to order, amend, or discontinue services for subscribers.

· Allow government designated personnel to generate reports on the number of licenses being used, to enable monthly reconciliation between the number and types of licenses assigned to subscribers on the system.

· Provide the ability to track the number of subscriber licenses, by type/category/tier, allocated to each organization.

Private Commercial Root Certificate

The contractor shall provide a private root commercial certificate that provides robust security and authentication to the MSCB for the DoW. The private commercial root certificate will be installed on the trusted root certificate store on all relevant mission partners’ administrator consoles.

6.2.1 Subtask 1 – Unclassified/NIPRNet Production Environment (engineered by Menlo Security, Inc.)

The managed service Contractor shall propose an enterprise user license agreement (EULA) subscription based pricing, and corresponding licensing model for up to 3.4M DoW users that provides the Government with an unclassified CSO that encompasses the infrastructure, platform, software (i.e., operating systems and applications) storage, networks, and other fundamental computing resources required to deliver the service.

Life Cycle Sustainment Plan (LCSP)

The contractor shall develop and maintain a Life Cycle Sustainment Plan outlining the strategy for ensuring the system's long-term supportability and availability. This plan must address all relevant elements to ensure the system meets operational requirements throughout its life cycle.

6.2.2 Subtask 2 – Highly Evasive Adaptive Threat (HEAT) Shield Enablement As an enhancement, enable HEAT Shield protections in the CBII environment to provide cyber defensive auto-mitigations that responds to cyber threats, attempted breaches, or other malicious threat vectors by utilizing CBII platform-enabled machine learning (ML) and artificial intelligence (AI) capabilities that identifies, neutralizes, and eliminates these cyber threats.

6.3 Task 3 – Operational Service Support

The Operational Service Support/Management function intended to meet the communication needs of end users and IT staff when encountering service incidents or making service requests. Service desks allow enterprises to implement strong and effective workflows for support departments, both internal and customer-facing. Trouble ticket systems are the focal point for reporting incidents (i.e., disruptions or potential disruptions in service availability or quality), and for users to make service requests (i.e., feature add-ons, or changes).

The Contractor, as a managed service, will provide operational support in accordance with the DESMF. DoW uses the DESMF to improve Information Technology (IT) Service Management (ITSM) capabilities across the Department. By using DESMF, the Contractor will aim to identify and eliminate redundancies, inefficiencies, and service quality deficiencies. DESMF provides service management guidance, best practices and improved efficiencies to plan, implement, monitor, and improve IT service management across DoW. The Contractor will:

· Submit monthly recurring reports on the number of trouble tickets, time to resolve, and the resolution status of tickets to include at a minimum:

a) Service desk requests received

b) Number of trouble tickets opened

c) Number of trouble tickets closed

d) Average mean and median time to answer/respond to trouble tickets (e.g., time to answer a phone call, time between trouble ticket opened and the first contact with customer)

e) Average mean time to resolve trouble ticket

f) Number of CBII service desk calls abandoned or dropped (e.g., user hangs up before submitting a ticket)

g) Trouble ticket(s) trend analysis

· Allow government designated personnel to update and check the status of trouble tickets associated with their subscribers.

· Grant government designated personnel the ability to generate trouble ticket reports upon request based on the following selectable characteristics: priority, time of day, network, node, time generated, service/capability and status (open or closed).

· Allow multiple government designated personnel to view their subscriber’s trouble tickets at the same time.

· Grant government designated personnel the ability to change the priority of trouble tickets in accordance with the published Service Management Plan.

· Specify a mechanism for customers to rate the performance of the service desk in resolving their issues, and provide monthly reports to government designated personnel, based on the aggregate results of these surveys.

· Offer the capability to accurately log, group, and categorize incidents.

· Display within the ticketing system the number of incidents, and the average resolution time per known problem(s).

· Provide an alternate means of communication outside of the CBII solution, in the event of a service outage.

· Address incidents within the same classification level (e.g., NIPR incidents stay on NIPR).

· Respond within 15 minutes for catastrophic incidents; within 1 hour for critical incidents; within 4 hours for major incidents; and within 2 business days for normal incidents.

· Offer a service health dashboard accessible via the web.

· Support dynamic assignment, routing, escalation, and de-escalation of trouble tickets from the contractor’s trouble ticket system to the government’s trouble ticket system.

· Use the following attributes for dynamic ticket assignments: Tenant, Contact Name, Summary, Impact, Urgency, Incident Type, Reported Source, Assigned Group, Status, Company, Support Tier (e.g., Tier 3).

Service Management Plan

The contractor shall provide a comprehensive Service Management Plan that details the procedures for all IT operations. The plan must address Access Management, Event Management, System Monitoring, Incident Management, Request Fulfillment, Service Desk Support, and Network Operations (NetOps) to ensure service levels are maintained.

Service Operations Annex (SOX)

The contractor shall provide a Service Operations Annex that serves as a detailed operational guide for the day-to-day execution of services. This document will supplement the main Service Management Plan by providing specific tactical procedures, contact lists, and escalation paths for all operational teams.

6.3.1 Subtask 1 – Tier 0: Knowledge Management (KM) Based Portal The Contractor shall define, develop, and deliver a web-based, self-service, online knowledge base portal (i.e., Tier 0) for assisting subscribers with known issues without the need to open a ticket. The web-based portal will involve self-service functionality to allow DoW end-users to find solutions themselves. The portal will be required to support DoW PK-Enabled/PIV authentication for all users accessing the information posted on the portal. The Contractor shall ensure the Tier 0 knowledge base portal has 99.9% availability. Propose a metric collection mechanism (e.g., form, survey) for the Tier 0 knowledge base portal, based on feedback from users. Metrics are to account for subjective time saved, as well as number of users that found resolution within the portal without the need to open a support ticket, at a minimum. The Contractor shall develop artifacts to include Standard Operating Procedures (SOPs), Tactics, Techniques and Procedures (TTPs), and online documentation to train users and administrators on the service.

6.3.2 Subtask 2 – Tier I: Contractor Provided Infrastructure Support The Contractor shall provide on-call service desk support 24x7x365 Tier I level for the CBII services that have been fielded to a DoW end-user. The Contractor will perform problem recognition, research, isolation, resolution, and follow-up steps required. The Contractor shall:

· Maintain documentation and files on all help desk actions to determine metrics and other reportable actions

· Maintain problem management database and help desk system

· Create help desk tickets in the designated ticket tracking system, provide an initial acknowledgement to the end user validating receipt of the ticket

· If possible, resolve ticket, communicate resolution to the end user and obtain customer sign-off before closing ticket

· If unable to resolve, thoroughly document ticket with actions taken to resolve and escalate ticket in accordance with applicable processes

· Receive, triage and route tickets to Tier II help desk; accordingly, analyze, log and track issue and problem tickets

· Compile and organizes data for monthly status reports; provide trend analysis and metrics to the CBII PMO based on gathered data and monthly status reports

· Provide daily situational awareness via written and executed documentation improvement

· Ensure compliance with security procedures for data handling, participate in planning sessions for process improvement

· Provide recommendation to the CBII PMO on issues/problems identified and reported in trend analysis

· Provide daily supervision and direction to help desk staff that are responsible for phone and in-person support to users The Service Desk will be located at either the Government facility or a contractor off-site facility for Tier I. The Contractor shall include a detailed account of Service Desk activities in the Activity Report. The Contractor shall maintain the Service Desk Activity Report logs daily for Tier I calls regarding any customer. The Service Desk Activity Report will be included in the metric status report (MSR). The report shall include a detailed account of each help-desk call problems, resolution, and ticket number as well as Tier I-III actions and time spent.

The Contractor shall use existing escalation procedures for Service Desk support and provide updates appropriate stakeholders. These escalation procedures include immediate notification of the Government site team lead, and the Contractor Officer Representative/ Alternate Contractor Officer Representative (COR/ACOR) when a supported site experiences a…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .