Attachment 1 - CISA IDIQ - PWS as of 2-13-2025.pdf

PDF 552 KB Posted

Attached to
CISA Indefinite Delivery Indefinite Quantity Contract Federal contract opportunity
Solicitation number
47QFRA25K0003
Issued by
General Services Administration Federal Acquisition Service Assisted Acquisition Services Region 8

About this file

This is a Performance Work Statement (PWS) for a CISA Indefinite Delivery Indefinite Quantity (IDIQ) contract that outlines requirements for enhancing cybersecurity posture of Federal Civilian Executive Branch (FCEB) agencies through configuration and deployment of cybersecurity solutions. The contract will support CISA's Capacity Building (CB) division, with initial focus on the Continuous Diagnostics and Mitigation (CDM) Program within the Cybersecurity Capability Implementation Branch.

The PWS defines five service areas and one product area: 1) Order Project Management Support, 2) Requirements Management, 3) Capability Implementation, 4) Solution Operations/Sustainment/Ancillary Support, 5) Solution Development, and 6) COTS Cyber/IT Products and Tools. Key tasks include managing agency requirements, assessing agency readiness, planning/deploying capabilities, providing training, offering reach-back support, and delivering cybersecurity services like A&A support, governance support, and incident response. The COTS product area is divided into four catalogs covering cybersecurity/IT software, cloud/infrastructure, development/multimedia tools, and miscellaneous support items. Labor categories are defined as Associate (<5 years experience), Intermediate (5+ years), Senior (10+ years), and Subject Matter Experts, aligned with the NICE framework. The contract will serve FCEB agencies and may be extended to state/local governments and critical infrastructure entities through the Cooperative Purchasing Program.

View the file

Other files for this federal contract opportunity

Other files attached to CISA Indefinite Delivery Indefinite Quantity Contract, newest first.
File Type Posted
RFI Question and Answer Document 02-28-2025.pdf PDF
RFI Revised - CISA IDIQ_02-28-2025 .pdf PDF
Attachment 2 - RFI for Cyber Training Program 02-13-2025.pdf PDF
Attachment 3 - Capacity Building Training Program Capabilities and Requirements.pdf PDF
RFI - CISA IDIQ_47QFRA25K0003_02-13-2025 .pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 1

Indefinite Quantity Indefinite Delivery (IDIQ) Contract in support of:

Cybersecurity and Infrastructure Security Agency (CISA)

1.0 Background

The United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) leads the national effort to understand, manage, and reduce risk to the cyber and physical infrastructure that Americans rely on every hour of every day. In its role as the nation’s cyber defense agency and the national coordinator for critical infrastructure security, CISA works with critical infrastructure partners every day to address the evolving threat landscape, and to provide tools and services to mitigate risks. The risks faced by U.S. critical infrastructure are complex and geographically dispersed, and they affect a diverse array of stakeholders, including Federal Civilian Executive Branch (FCEB) agencies; private sector companies; State, local, tribal, and territorial (SLTT) governments, and critical infrastructure (CI) sectors. CISA spearheads a national effort to ensure the defense and resilience of cyberspace. It is building the national capacity to defend against and recover from cyberattacks.

It works with federal partners to bolster their cybersecurity and incident response postures and safeguard the FCEB networks that support the nation’s essential operations and secure and store information related to national security, the economy, and public health issues. CISA partners with these entities and the private sector and others on a daily basis to detect and mitigate cyber threats and vulnerabilities before they become incidents.

The federal enterprise depends on information technology (IT) systems and computer networks for essential operations. CISA, through its Cybersecurity Division (CSD), works with each FCEB agency to promote the adoption of common policies and best practices that are risk-based and able to effectively respond to the pace of ever-changing threats.

CSD leads efforts to protect the federal.gov domain of civilian government networks and to collaborate with the private sector to increase the security of critical networks. The CSD mission is to understand evolving threat activity as it affects critical functions at the national level and high-value assets, ensuring stakeholder access to essential data on the risk posture of key information systems.

Within CSD, Capacity Building (CB) serves as CISA’s enterprise cybersecurity services management arm for national stakeholders and the lead for federal enterprise cybersecurity governance. CB enables its customers to manage cybersecurity risk by building their capacity to implement effective cybersecurity policies, tools, and procedures. CB helps stakeholders better manage cybersecurity risk by defining expectations for stakeholder cybersecurity; leading implementation and enforcement of cybersecurity requirements; managing CISA’s cybersecurity services portfolio; building capacity; and enhancing collective defense and readiness.

CB is comprised of multiple branches that execute specific programs. The CB branches include Cybersecurity Capability Implementation, Cybersecurity Education and Training, Cybersecurity Oversight and Enablement, Cybersecurity Shared Services, Cybersecurity Mission Enablement.

This IDIQ directly supports all CB efforts and could be extended to CSD efforts if the need arises.

It is envisioned at the time of award (TOA) that CB’s largest program, the Continuous Diagnostics and Mitigation (CDM) Program within the Cybersecurity Capability Implementation Branch will initially make up the preponderance of orders against the IDIQ. The CDM program is further defined in the following section.

1.1 Continuous Diagnostics and Mitigation Program

Established in 2012 and within the CB Capability Implementation Branch, the CDM Program is a dynamic approach to fortifying the cybersecurity of Government networks and systems. The CDM Program provides cybersecurity tools, integration services, and dashboards to participating agencies (Chief Financial Officers [CFO] Act agencies and non-CFO Act agencies (see Section 11.0, Attachment F) to support them in improving their respective security postures by delivering better visibility and awareness of their networks and supporting decision-making in defending against cyber adversaries. In supporting CISA’s mission, CDM works closely with agencies to deploy capabilities that help agencies protect their hardware and software assets, networks, and the data they contain.

Currently, the Government maintains dozens of separate, tailored CDM solutions across the FCEB agencies. The CDM solution architecture, shown below in Figure 1: CDM Logical Architecture, illustrates the solution implementation supported at CDM-participating agencies:

1. Layer A is composed of tools and sensors that, together, provide the coverage of the CDM capabilities. The current Layer A tools vary by agency,

2. Layer B is the integration layer, which aggregates data from agency Layer A tools, performs data normalization, and then transforms and conforms records. Layer B is often tailored to individual agency environments and is an agency and CDM shared responsibility. A standardization data integration solution will be implemented via the CDM Data Services contract.

3. Layer C is the Agency Dashboard, which ingests data from Layer B and presents it to agency users in operationally relevant ways to promote the reduction of cybersecurity risk. The Agency Dashboard is standardized for participating agencies.

4. Layer D, also known as the Federal Dashboard, presents a unified view of the cybersecurity posture of the entire FCEB enterprise. The Federal Dashboard is standardized for use by CISA analysts.

Figure 1: CDM Logical Architecture (Current State)

The CDM program maintains Attachment A - Capability Implementation Plan, which provides a roadmap of planned implementations at agencies. This plan is continually updated as the forecast changes.

2.0 Purpose

The purpose of this IDIQ is to enhance the cybersecurity posture of FCEB agencies through the configuration and deployment of solutions that meet CISA capability requirements, other federal mandates, and the need for security solutions that involve use of industry standards and best practices.

The Government requires a flexible approach to support the implementation of evolving technical capabilities in a rapidly changing cybersecurity environment during the entire life of the IDIQ. The approach also will reflect the need for nimble project design and execution and leverage industry investment in technology development to ensure these requirements are incorporated into current solutions and future technologies and products.

Solutions are typically commercial off-the-shelf (COTS) products. This IDIQ shall provide the services to ensure that solutions are planned, configured, and implemented for agencies requiring support. The cadence of solution deployment to agencies will be iterative and continual throughout the period of performance.

The high-level performance objectives of this IDIQ include:

Provide multiple service options that support implementation of a comprehensive yet flexible security plan, tailored to meet agency needs, existing or new mandates for performance and plan implementation

1. Implement measurable and achievable outcomes to reduce program risk, continuously acquire rapidly changing tools and technology and enable flexibility to support scalable solutions

2. Leverage/encourage depth and breadth of maximum partnerships to deliver the best solutions.

3. Employ agile approaches to effectively address agency rapidly evolving needs promoting speed, agility while streamlining means to procure services, providing flexibility of options to fill security gaps and continually improve overall security posture with out having to initiate new acquisition activity,

4. Identify and implement cost savings to CISA and agencies without affecting quality.

5. Provide a methodical approach to assess agency readiness and develop and maintain plans for capability deployment.

6. Coordinate effectively with entities on design activities, technology implementation componentry, data integration, and procurement administration. Coordination will span across Government stakeholders and other contractors.

7. Deploy, configure and test deployed solutions at agencies, while leveraging original equipment manufacturer (OEM) professional services when available.

8. Successfully verify the agency’s deployed solutions and support validation of the system’s related operational requirements, as needed.

9. Provide ancillary support to meet capacity building solution(s) development and sustainment needs. (This is not limited to the CDM solution)

10. Develop better cyber tool buying approaches and execute strategic and tactical transactions for CISA and Federal Agencies.

3.0 Scope

The scope of this IDIQ and issued Orders is to implement cybersecurity solutions to FCEB agencies (including CFO Act and non-CFO Act agencies). The contractor shall provide an in-depth approach to requirements management that allows for the intake of agency requests, assessments of agency readiness, and then provides implementation planning to prepare for execution.

The contractor shall plan, deploy, and configure solutions to meet capability requirements at a receiving agency. The contractor shall test the capability before transitioning the operation of the capability to an agency’s designated operations team. The contractor is expected to utilize professional service teams from OEMs, to the maximum extent possible, to enhance deployment effectiveness.

The contractor shall sustain CB solutions in operation while providing ancillary support services to those solutions, included assessment and authorization support (A&A), governance support, and critical incident response support.

The scope of this IDIQ is inclusive of solution/tool development, and all services associated with software development, to support enterprise CB requirements.

The contractor shall provide ancillary support to ensure the effective execution of the Order(s) and supported agencies, including project management support, project progress reporting, and reach back support for any agency deployments.

At the time of award, the immediate focus of support will be to FCEB entities for the execution of CDM priorities. As the period of performance progresses, additional CISA and/or Agency program offices may elect to utilize this IDIQ.

Finally, in its overall cyber risk reduction role, CISA has the strategic goal of making these services available for use by state, local, tribal, and territorial governments, as well as CI entities.

This IDIQ, through the Cooperative Purchasing Program (CPP), will allow these local entities to benefit from the same consistency, pricing, and speed of procurement for CISA as will be available to Federal entities under this acquisition.

4.0 Service Areas

The contractor shall provide all services as set forth in the service and cyber technology product areas identified below:

● Service Area 1: Provide Order Project Management Support

● Service Area 2: Provide Requirements Management

● Service Area 3: Provide Capability Implementation

● Service Area 4: Provide Solution Operations, Sustainment and Ancillary Support

● Service Area 5: Provide Solution Development

● Product Area 1: Commercial Off the Shelf (COTS) Cybersecurity Products and Tools

Task Orders may consist of one or more services areas.

4.1 Service Area 1 – Provide Order Project Management Support

The contractor shall deliver project management services under this IDIQ to support the successful execution of all work on an order. The contractor shall provide all necessary personnel, administrative, financial, and managerial resources necessary for the support of order accomplishment. This includes the management and oversight of its performance of the order under the IDIQ and work performed by contractor personnel, including subcontractors and teaming arrangements/partners, to satisfy the requirements identified in the orders. The contractor shall provide this support in accordance with the terms and requirements of this IDIQ and the specific requirements of the order.

Objectives for the project management support shall include, but are not limited to:

1. Performing all management functions necessary to facilitating successful order execution.

2. Conduct project kickoff meeting.

a. Multiple meetings will likely be required with CISA stakeholders who have direct management oversight, as well as with customer agencies who are anticipated to receive services via the IDIQ.

3. Provide financial tracking and reporting, for all aspects of the project, including:

a. Expended, anticipated, incurred, and remaining funds.

b. Planned versus expended actuals by month and cumulative.

c. Monthly and cumulative invoiced amounts.

d. Costs broken out by capability and by agency.

4. Tracking tools and other direct costs (ODCs).

5. Develop and maintain a project schedule that captures work necessary across the order— including major tasks, milestones, and deliverables and the planned and actual start and completion dates for each task, subtask, and work package. The project schedule may require compliance with compliance documents and/or other data governance directives or guidance.

6. Submitting a monthly report that captures:

a. Activities that occurred during a reporting period.

b. Milestone planning and tracking.

c. Financial management aspects, including funding and all incurred costs.

d. Significant project concerns, risks, and issues and potential mitigations.

7. Manage contractor personnel assigned to the order and support CISA Contractor Workforce Management System (CWMS) initiatives.

8. Coordinate and complete SELC gate reviews.

9. Execute risk management activities, including maintaining a risk register

10. Provide knowledge management support, utilizing any Government identified repository for project documentation when noted.

11. Support ad hoc meeting requests with government stakeholders as needed.

12. Execute a seamless transition-in that is informed through direct coordination with relevant incumbent contractors, to include clear relatability to the incumbent’s own transition-out activities, where appropriate.

13. Execute the steps necessary to ensure a seamless transition from the contractor awarded this order to relevant incoming contractor/Government personnel at the expiration of any effort.

14. Notify the Contracting Officer (CO) and the Contracting Officer Representative (COR) of any technical, financial, personnel, or general managerial problems encountered on individual orders.

Deliverables associated with the project management service area include but are not limited to:

1. Project Management Plan

2. Financial Status Reporting

3. Contractor Financial Data Collection

4. Procurement Reporting

5. Monthly Status Reporting at order levels

6. Trip Reports

7. Problem Notification Reports

8. Transition-In Plan

9. Transition-Out Plan.

4.2 Service Area 2 – Provide Requirements Management

The Government has a significant number of stakeholders that are anticipated to utilize the services of this IDIQ. The contractor shall manage the execution of the capability implementation via a comprehensive requirements management process that provides accurate insight into agency requests, assessments of those requests, and supports and documents implementation planning.

The requirements management process shall seek to engage agency customers on support needs, by capturing all agency needs and requirements that are anticipated to be critical throughout the lifecycle of deployment activities. This engagement shall include verification of agencies desired level of testing and validation of solution delivery. It will include a process that ensures agency readiness before execution of design and deployments of capabilities. This requirements process shall also ensure that federal or CISA mandatory security and reporting requirements (e.g., Office of Management and Budget (OMB) M-memoranda, CISA Binding Operational Directives (BOD), etc.) are collected and integrated into the readiness process.

4.2.1 Task 2.1 – Intake Agency Requests

The contractor shall assist in the capture, vetting, and validation of requirements requests from agency stakeholders, and subsequently track requirements achievement through potential execution. The requirements management process may be managed via a Government defined solution in some instances, and shall be continually refined throughout project execution.

The contractor shall ensure that the requirements management process is effectively monitored with activity logging and traceability between agency requests, approval of requests, deployment, and acceptance of a deployment. The contractor shall ensure that the requirements request process provides an automated request intake mechanism to facilitate stakeholder outreach.

The contractor shall continually review and refine submitted requests with relevant stakeholders to ensure the continued accuracy and relevancy of the request.

4.2.2 Task 2.2 – Assess Agency Readiness

The contractor shall assess target agencies’ readiness for a requested capability, as documented and maintained in the requirements management process. Throughout project execution, the contractor shall ensure that agency readiness assessments are present and accurate in the requirements management process. The intent of the agency readiness assessment is to ensure the prudent use of Government resources by ensuring implementation of a capability, or other support at a target agency is likely to be successful.

The contractor shall standardize its approach to conducting an agency readiness assessment, producing clear, effective, and succinct results that maximize accurate outcomes of potential implementations. When directed by CISA to assess the suitability of an agency (or agencies) to receive a particular capability implementation or support, the contractor shall conduct the assessment and then deliver an agency readiness assessment report.

Assessment activities are intended to be ongoing throughout the IDIQ Period of Performance (POP). The contractor shall facilitate and lead regular touchpoints with stakeholders to review new, in-progress, stalled, and recently completed agency readiness assessments. The contractor shall consistently provide recommendations and accompanying justifications for the government to consider related to assessments.

4.2.3 Task 2.3 – Plan for Agency Implementations

The contractor shall plan for agency implementations that utilize a standardized methodology and that provides timelines necessary to deploy a specific capability or stand-up support for an agency. This planning may include the delivery of an implementation plan, which is intended to provide a comprehensive consumable vision of support for target agencies. The Implementation Plan is a living document that shall be updated and refined as additional agencies are approved to receive capabilities throughout this IDIQ. Implementation planning shall be linked with the outcomes of agency readiness assessments and shall be visible via the requirements management solution.

4.3 Service Area 3 – Provide Capability Implementation

The government will identify situations and conditions that require immediate action for implementation of a specific capability or set of capabilities.

The contractor shall design, procure (when directed), deploy, and configure the capability for the receiving agency. The contractor shall thoroughly test the capability before transitioning the operation of the capability to a designated operations team. The contractor shall offer relevant training to ensure that the agency is capable of full utilization of the implemented capability prior to transition.

4.3.1 Task 3.1 – Perform Technical Planning for Capability Implementation The contractor shall provide technical planning for capability implementation, with the intent of providing key Government stakeholders with a common understanding of the foundational solution design and architecture to accomplish requirements.

Specific technical planning activities to meet the intent stated above shall include, but are not limited to the following:

1. A kickoff meeting with relevant agency and CISA stakeholders to cover the following information: introduction of key Government and contractor personnel; overview of project scope and schedule; roles and responsibilities; and significant project dependencies and risks. This list does not limit other information that should be discussed regarding agency-specific requirements.

2. Identify and obtain agency-specific Government-furnished equipment (GFE) – such as laptops and personal identity verification (PIV) cards – and relevant system and/or tool access, as applicable, necessary for the contractor to successfully implement a capability within an agency’s environment.

3. Perform agency discovery and identify scope of deployment activities. At the end of this activity, the contractor shall identify discrepancies discovered between the information provided by the Government and the existing agency environments.

4. Develop in-depth agency policy architecture to include logical diagram(s), identifying any external platform integration requirements and agency policy-based configuration deviations.

5. Coordinate with other contractors as applicable to align respective schedules where overlapping and interfacing is required. This shall include determining the level of coordination and or technical direction they will need to determine data integration and or reference designs/directives from the Government.

6. Assist in completing Security Impact Assessments at agencies by providing information pertinent to the introduction of a capability into an agency’s environment.

7. Complete relevant DHS Systems Engineering Life Cycle (SELC) requirements associated with technical planning, including delivery of all corresponding artifacts and deliverables of a relevant SELC gate as defined in the DHS SELC Process Requirements (Section XX, Attachment X).

8. Provide support to internal agency processes to obtain Authority to Operate (ATO) for new tools introduced to the agency environment in support of deployment of a capability.

Including:

a. Provide documentation and schedule to transfer ATO maintenance responsibility to agency resources, including responsibility for tracking system plan of action and milestones (POA&Ms).

b. In the event that a POA&M is related to a tool configuration necessary for a functional, operational, and/or data requirements, continued support may be required.

c. Support of internal agency processes is limited for deployment activities that are directly related to tools required to implement the capability. Support is targeted for actual deployment only.

4.3.2 Task 3.2 – Deploy, Configure, and Test Capability within Agency Environment The contractor shall install, configure, and test the capability for the specific capability implemented within the agency’s environment. The contractor shall undertake deployment and configuration activities at an agency to include, but not limited to the following:

1. Configure deployment in accordance with the to-be solution architecture or approved technical plan.

2. Ensure that the new capability has minimal network performance impacts in the agency environments.

3. Coordinate and communicate capability change requests based on agency-specific Change Control processes, as applicable.

4. Conduct performance and functional analysis to identify anticipated impact on agency resources from capability implementation and make recommendations accordingly.

5. Leverage OEM professional services as much as possible.

6. Ensure the new capability is compliant with applicable agency privacy requirements.

7. Ensure the new capability is compliant with applicable NIST 800-53 controls.

8. Ensure successful integration with any identified data integration solutions.

9. Ensure the new capability is compliant with applicable Federal and agency security technical implementation guidance. Provide a Supply Chain Risk Management (SCRM) Impact statement to the agency that includes all new tools that make up the CDM capability, based on the guidance provided in NIST Supply Chain Security Guidance Under Executive Order 14028 Section 4e.

10. Complete relevant DHS SELC requirements associated with deployment, configuration and testing, including delivery of all corresponding artifacts and deliverables of a relevant SELC gate as defined in the DHS SELC Process Requirements (Section XX, Attachment X).

11. Assess the capability following deployment that provides a validation that the capability is complete for an agency, and if not, identify any gap associated with the capability.

Conduct tailored testing and document results as applicable.

4.3.3 Task 3.3 – Support Agency Stakeholder Training

The contractor shall ensure agency stakeholders have access to OEM tools training. The government desires that agency have easy access to utilize OEM developed training. The Government does not desire the contractor recreate training for each deployed capability.

The contractor shall support agency training by providing the following:

1. Access to OEM tool training for agencies.

a. Access may be centralized in some instances, and in those instances the contractor shall track and monitor its utilization.

2. Assist agencies in understanding deployed capabilities align with tools/technologies and how they relate to federal mandates when applicable. The contractor shall ensure the agencies understand how the deployed capabilities support any CISA/OMB requirements.

4.3.4 Task 3.4 – Provide Reach-Back Support

The contractor shall provide reach-back support for agencies that have executed deployments through this IDIQ. Actual operation and maintenance of tools is the responsibility of the receiving agency or CISA. The contractor’s support shall include, but is not limited to the following:

1. Coordinate and resolve issues with deployed solution tool OEMs.

2. Track issues to resolution from tool OEMs.

3. Identify and provide metric reporting on issues at agencies and use of a centralized repository to track systemic issues that may impact other deployments.

4. Provide specialized knowledge of a deployed solutions configuration to assist with data quality issue triage, troubleshooting, and remediation.

5. Coordinate and resolve issues with deployed solution tool OEMs.

The contractor shall be available to resolve escalated issues outside normal working hours as determined by the CISA COR. The contractor is not required to establish a help desk, but is required to utilize the CISA identified help desk.

4.4 Service Area 4 – Provide Solution Sustainment and Ancillary Support

CB solutions and agencies receiving support through this IDIQ require the ability to sustain solutions deployed, as well as having the ability to obtain certain cyber relevant services to support deployed capabilities and integrate those capabilities effectively into programs at agencies.

4.4.1 Task 4.1 – Provide Solution Sustainment

The contractor shall support the continued sustainment of solutions. In some instances, the contractor shall operate a particular solution, ensuring that the solution is available during defined operational hours, in some instances 24 hours per day, 7 days per week (24 x 7).

Sustainment activities include, but are not limited to, the following:

1. Provide all administrative and management responsibilities for the operational solution.

2. Provide administrative access to all technical components for select government personnel.

3. Provide Security Operations Center services and configuration support with integrated alerting and monitoring IAW DHS policy (e.g., DHS Policy Directive 4300A).

4. 24x7 Security Operations Center Services monitoring for all connections.

5. 24x7 Security Operations Center Services incident notifications such as up/down status.

6. Distributed Denial of Service and Availability Monitoring.

7. Integration of Security Information and Event Management (SIEM) or SIEM equivalent capabilities to monitor environment in “real time” for active threats.

8. Triaging events to determine if an incident has occurred.

9. Implement updates to the solution (e.g., hot-fixes, customizations) as needed for continued secure operation. Perform all planned maintenance that would cause service outages outside of normal working hours, unless explicitly approved in advance by the government in writing.

10. Provide specialized knowledge of any solution for data quality issue triage, troubleshooting, and remediation.

11. Provide (24x7 365 days) engineering support to remedy operational issues or incidents related to a solution.

12. Provide a help desk capability that is available to stakeholders.

13. Track useful performance metrics and trends for the solution (e.g., performance load) and make them available programmatically through weekly and monthly Operational Reports.

14. Conduct weekly operations status reviews with government stakeholders.

15. Implement configuration management controls and follow government change management processes to ensure that system changes are properly documented and approved.

4.4.2 Task 4.2 – Provide Assessment and Authorization (A&A) Support The contractor shall provide support for ongoing A&A activities for solutions. The intent of this support is to ensure the appropriate operational security posture is maintained for a system or solution. The contractor shall provide support in alignment to the Risk Management Framework.

Support shall include, but is not limited to:

1. Assist system owners with understanding and meeting A&A requirements.

2. Assist with the development and maintenance of the security documentation, including the system security plan (SSP), security assessment plan/report, POA&Ms.

3. Conduct various security controls assessments (automated and manual) at different frequencies specific to a system and based on an established core control assessment schedule, and provide results to include control gaps or weaknesses, risk level, cost-benefit analysis, and impact to a system or solution.

4. Support the development and updates to the systems Privacy Impact Assessments (PIA), interconnection security agreement, incident response plan, contingency plan, risk assessments, configuration management plan, security impact assessments, and standard operating procedures and guides as necessary.

5. Review and analyze all system artifacts for accuracy, completeness, in support of the Authority to Operate (ATO) requests.

6. Assist with the creation and/or review ATO packages prior to submission.

o Assist the Government in completing the Security Authorization process. This may include activities and assessment such as:

o Conducting Independent assessments to validate security and privacy controls are in place for information system(s) to support of agency specific Security Authorization processes o Periodic or independent Security Reviews to ensure controls and requirements are being implemented and enforced o Assist with Federal Reporting and Continuous Monitoring requirements o Assist with or conduct vulnerability assessments of solutions to document critical and/or high vulnerabilities o Maintain compliance or traceability to Authorization POA&M requirements

7. Continuously conduct vulnerability assessments of the solution and inform stakeholders, including agencies and CISA (as appropriate), in writing, of the remediation of default risk critical/high vulnerabilities.

o Perform operating system, network, web application, and database application vulnerability scans.

o Document and report any threats and vulnerabilities discovered, and ensure that they are promptly remediated.

4.4.3 Task 4.3 – Provide Cybersecurity Governance, Risk, and Compliance Support Agencies are responsible for managing and maintaining cybersecurity specific controls by linking technologies with effective policies and procedures in order to comply with Office of Management and Budget (OMB) guidelines; often described as an Agency’s Information Security Continuous Monitoring (ISCM) program. The contractor shall assist agencies in incorporating capabilities into each agency’s specific cybersecurity or ISCM program, relevant to the tools and technologies. Support shall include, but is not limited to the following:

1. Develop governance documentation, including SOPs, policy documentation, procedures, and directives.

2. Support enterprise risk management by maintaining visibility and comprehensive situational awareness of the cyber threat landscape.

o provide risk management support, including program, implementation, and management support for Enterprise-Level Cyber Risk Management initiatives

3. Provide procedures/approaches to implement efficient risk-reduction (also described as defect reduction).

4. Assist stakeholders with improved definitions of, or criteria related to, agency risk-thresholds relative to the agency’s architecture and any extant agency policies or plans related to ISCM.

5. Assist with the reduction of cost by reviewing an agency’s(ies) enterprise environment and identify areas for the optimization of agency cybersecurity posture through complexity reduction, reciprocity, and increased automation.

6. Support the development and coordination of strategic initiatives into established operations or programs.

7. Ensure continuous compliance with ISCM policies and process and procedures improvement of alignment with regulatory and other Federal mandates.

4.4.4 Task 4.4 – Provide Cybersecurity Training Support

The contractor may be required to operate and maintain the existing cybersecurity training portfolio as well as provide for new development of cybersecurity training. CISAs cybersecurity training program(s) address(es) critical skill gaps by offering entry-level, intermediate, and advanced cyber security training, leveraging interactive, hands-on labs, and developing innovative solutions to prepare the workforce for emerging threats. The challenge is to scale these efforts efficiently while ensuring compliance, adaptability, and seamless integration across multiple stakeholders, systems, and environments. This includes but is not limited to (Example Topics are provided in separate attachment):

1. Provide life-cycle training support to assist the government in planning, analysis, design, development, implementation, evaluation.

2. Provide instructional design and training delivery support.

3. Synchronous and asynchronous awareness and training for securing systems, what we refer to as the “left of boom” cybersecurity requirements. These topics include asynchronous instructor-led training, which is offered both in-person and virtual in-person.

4. Synchronous and asynchronous awareness and training for incident response, what we refer to as the “right of boom” cybersecurity requirements. These topics include asynchronous instructor-led training, which is offered both in-person and virtual in-person.

5. Research training resources (e.g., FedVTE, CISA Learn, and/or open government-wide sources) to identify courses available to meet identified training gaps and develop and maintain a roster of these courses.

6. Promote the Enterprise implementation of the CSAT Program.

7. Deliver Enterprise training on cybersecurity legislation, policies, orders, and directives using appropriate delivery mechanisms and media.

8. Participate in Federal and Departmental cybersecurity training working groups.

9. Conduct an end user surveys of training and trainings materials provided. Survey data shall be used to improve subsequent trainings and training materials. Survey data shall be provided to the Government in a quantitative tool.

10. Solicit input from senior information security and privacy officials and consult with DE stakeholders to generate consensus training strategies and plans.

11. Identify cybersecurity trends and cyber events and analyze their potential impact on various Training Programs.

4.4.5 Task 4.5 – Provide Cybersecurity Critical Incident Support The Government anticipates surge support will be required on a case-by-case basis when agencies supported are impacted by cyber-attacks, in need of penetration testing, or require cyber risk assessment and mitigation activities. Services would need to be quickly planned and executed to meet any urgent needs. The scope of the response shall consist of conducting an initial assessment of the attack, identifying a plan of action, and implementing the Government-approved response.

Once a cyber-attack response has ended, the contractor shall proceed with an orderly and efficient transition-out period. During the transition-out period, the contractor shall fully cooperate with, and assist the Government with, activities closing out the matter, developing required documentation, and transferring knowledge, training, and lessons learned.

4.4.6 Task 4.6 – Provide Support to Enterprise and Federal Cybersecurity Initiatives The Contractor may be required to provide support for various cybersecurity initiatives, including FedRAMP, Secure DNS (DNSSEC), Cyber Supply Chain Risk Management (C-SCRM), Continuous Monitoring, High Value Asset (HVA), Artificial Intelligence, Quantum Computing, and any others that launch during the period of performance. This support may include the following requirements:

1. Identify changes in Federal legislation, Federal/Agency policies, and initiatives and analyze the operational impact on the information and communications technology (ICT) SCRM, HVA, and other Cyber Program(s)

2. Provide research reports and briefings to risk owners.

3. Perform risk assessments on HVAs, considering not only risk to the organization but also possible risk to other agencies, the Federal Government, and the American public o Rank HVA systems in terms of risk, considering threat, vulnerability, and consequence.

4.4.7 Task 4.7 – Provide Enterprise-level and Program specific Cybersecurity Operations Support The government requires technical and operational support for Enterprise-level Cybersecurity Operations as oversight to CISA and its various Divisions and Sub-divisions. This effort will be focused on the coordination and reporting on ongoing monitoring of Cybersecurity Operations, and Operational support to various cyber programs and solutions throughout the organization. Support services may include:

1. Identify and recommend points of automation in data collection and analytic workflows, and, pending available resources, implement workflow automation.

2. Assist in the installation of cybersecurity sensors both inside and outside discrete networks, improving the automation of data collection.

3. Monitor network activity to identify potential threats and respond with the correct mitigation strategies and problem management processes.

4. Provide tiered cybersecurity service desk call center support.

5. Collaborate with the intelligence community for information that reveals potential vulnerabilities within an organization, and scan networks sensor information to identify potential matches.

6. Provide analysis of malware, network, and host forensics to include forensic analysis and forensic protection of suspect system for turnover to intelligence and/or law enforcement entities.

7. Provide cybersecurity compliance site inspections, tracking of remediation, and associated reporting to include unclassified, ISC//OT systems.

8. Provide management of data loss prevention to include implementation of hardware, software, data collection and reporting.

9. Provide specific ICS/SCADA/OT cybersecurity expertise.

4.4.8 Task 4.8 – Provide Infrastructure Support Services for CISA Applications, Programs and Systems The Contractor may be required to provide solutions to provide and/or support solutions capable of supporting physical and virtual servers for CISAs application and data storage needs, to potentially include as-a-Service, Shared Services and authorized commercial cloud capabilities.

In providing this solution, the Contractor shall perform the following requirements:

1. Ensure the solution can scale compute capabilities appropriately in terms of central processing unit (CPU) processing power, available memory, and available storage space, in order to accommodate surges in usage or data.

2. Support management at the Operating System (OS), and virtualization/hypervisor layer. This includes configuration, maintenance, upgrades and administration for on-prem and cloud implementations.

3. Develop, implement and integrate target infrastructures for technology stacks and solutions. This includes architecture and engineering support to develop and plan orchestration, technology integrations, and virtualization to support new or existing systems.

4. Identify or develop tools that optimize the use of the virtual environment to make the cyber range more accessible and scalable.

5. Automate the provision of virtual machines and the management of server reset or upgrades to ensure efficient and correct setups of virtual machines and applications.

4.4.9 Task 4.9 – Provide Strategic Cybersecurity Acquisition and Buying Support Services CISA seeks to expand its buying power for its various programs. This involves both strategic and tactical procurement approaches for a dynamic cyber capability and requirement set and large CISA customer base (ie, the FCEB). CISA requires specialized strategic cybersecurity product procurement support to enable the capability deployment and implementation activity for CDM and the broader set of projects across the enterprise. Today, Capacity Building and CDM conducts over 500 procurements each year at a dollar value of over $300M across all the DEFEND buying groups (ie, CFO ACT Agencies and Small and micro Agencies participating in the Shared Service Program). The Contactor may perform Direct Materials purchasing on behalf of the Government (in other words, direct purchasing of Cyber-IT-related equipment / hardware / software licenses which would be the primary purpose of an Order) in support of Federal enterprise activities.

This will require the Contractor to implement an efficient procurement management process with the capability to support, at minimum a $300mm cyber SW procurement footprint.

That contractor shall serve as the enterprise procurement consulting and executing agent.

1. Strategic Procurement Consulting Support. Identify and execute efficient buying methodologies on procurement strategies for CISA and its programs. This support includes, but is not limited to, analyzing historical and recurring CISA/Agency funded tool procurements and aligning the various CB program (CDM, CSSO, etc) cyber capability needs with better buying approaches. It is not expected that a one-size-fits-all methodology meets the government need but identify efficiencies and means to streamline and reduce level of effort (LOE).

2. Develop single or multiple ELAs, agreements or transactional approaches that efficiently align to CB’s cyber capability and service areas. This strategic support must ultimately enable the more tactical and transactional requirements.

3. Execute procurements for commercial cybersecurity and IT products and any associated cloud infrastructure or support software.

4. Create and/or manage a product licensing tracking and metrics platform. This can be out of the box or customized to support the administration, execution, forecasting, and metrics tracking activities associated with managing a program of this size.

5. Innovative acquisition subject matter expertise to think out of the box and strategically procure cybersecurity tools in an environment where priorities and tools evolve rapidly.

This support would help CB build in agility and flexibility into cyber procurement approaches while keeping pace with threats and being good stewards of taxpayer dollars.

6. Provide automated software detection and license monitoring services for all software.

7. Create and/or manage a product licensing tracking and metrics platform. This can be out of the box or customized to support the administration, execution, forecasting, and metrics tracking activities associated with managing a program of this size.

8. Perform software lifecycle management, including monitoring for end of life/outdated software, purchasing, license inventory management, license and support acquisition and renewal, requirements gathering, systems analysis, manual and automated distribution, patch and update management, removal, and auditing activities for compliance and performance optimization.

The Contractor’s processes and procedures will ensure the selection of competent suppliers, recommend unbiased purchase decisions, establish compliant contracts, and negotiate competitive prices for goods and services as authorized by the Government in a cost-effective manner and in accordance with public law and applicable regulations. The Contractor may be required to coordinate with vendors on Government commercial terms and conditions. End User License Agreements (EULAs) will only be considered on a case-by-case basis when the Government’s commercial terms and conditions do not address a situation that has been documented and presented to the Government for review.

4.5 Service Area 5 – Provide Solution Development

The contractor shall support enterprise solution and/or tool development for Capacity Building.

This support includes the planning, requirements gathering and use case/CONOPS development prior to solution building, testing, and implementation. These solutions and/or tools may be oriented around automation of organizational and programmatic processes embedded in existing enterprise tools, providing insight into solutions for agency needs and ensuring offerings are represented in a simplified manner. Enterprise tools include but are not limited to JIRA, Confluence, ServiceNow, Tableau and the suite of Microsoft tools.

4.5.1 Task 5.1 – Solution/Tool Management and Planning

The contractor shall provide technical planning for CB tools and solutions, including developing product roadmaps, developing and maintaining product backlogs, with the intent of providing key Government stakeholders with a common understanding and vision of the solution and tools.

Specific activities include, but are not limited to:

1. Work with the Government to establish software and IT requirements.

2. Collaborate and communicate requirements in an Agile development environment.

3. Establish project baselines and priorities.

4. Develop use cases and other requirements documents.

5. Manage configuration of software items.

6. Create and execute test plans.

7. Manage risks to include identifying, analyzing, tracking, and mitigating risks.

4.5.2 Task 5.2 – Perform Iterative Development, Testing, and Implementation The contractor shall provide agile software development services to deliver functioning code, design artifacts, and other product documentation to help CISA achieve various mission end states through secure customization and design.

The services to be provided shall include all aspects of software development, including ongoing planning, user research, human-centered design, prototyping, development and coding, documentation, testing, configuration, deployment, and operations support. Subject matter experts shall expect to integrate application security principles and practices into software development and operations, to deliver new software and services at agile speed. Specific activities include, but are not limited to:

1. Design, develop, test, debug, build, and coordinate the upgrade, conversion, and/or integration of products.

2. Design and develop new software products or major enhancements.

3. Participate in Agile development methodologies and proactively identify day-to-day project work and responsibility for its completion.

4. Execute work mapping to a repeatable SELC framework with Agile methodologies.

5. Develop design artifacts, software user manuals, and training materials.

6. Assist with planning and configuring of existing architecture.

7. Assist application owners with their compliance activities related to application software artifacts such as system diagrams, software architecture, and network diagrams.

4.5.3 Task 5.3 – Cybersecurity Automation Support

Cybersecurity Automation Support The Contractor may be required to provide support in procuring, developing, and maintaining solutions to automate necessary cybersecurity processes. The support may include:

1. Plan and design new cybersecurity automation capabilities.

2. Perform automation readiness assessments for current cybersecurity infrastructure.

3. Identify requirements and develop an Automation Capability Project Plan, including tasks and schedule for the implementation of the automation capability.

4. Develop or procure and implement new cybersecurity automation capabilities.

5. Identify costs such as for the application, services, and deployment.

6. Develop, test, prototype and rollout the automation capability according to the approved plan

7. Develop a Migration Project Plan, including tasks and schedule for migration from the current processes to the automated processes

4.5.4 Task 5.4 – Provide Software Development and Maintenance Support The Contractor may be required to develop new software or provide maintenance programming support for existing software and/or future applications, including:

1. Elicit, analyze, and document software requirements.

2. Design software solutions to meet requirements or modify existing software designs to incorporate new requirements.

3. Code software in conformance with design specifications and standards or modify existing software to meet business and design requirements.

4. Perform unit, system, and integration testing of software to ensure that all software meets all applicable business and technical requirements.

5. Create and/or update…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .