Attachment 1 - Statement of Work_WING Penetration Test.pdf
PDF 133 KB Posted
- Attached to
- WINGS Penetration Test - AMENDMENT 0001 Federal contract opportunity
- Solicitation number
- FA330022Q0029
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 0001_Combined Synopsis Solicitation - WINGS Penetration Test_10 June 2022.pdf | ||
| Copy of Copy of Copy of Questions and Answers_10 June 2022(2).xlsx | XLSX spreadsheet | |
| WINGS Penetration Test_Statement of Work_10 June 2022.pdf | ||
| Combined Synopsis Solicitation - WINGS Penetration Test.pdf | ||
| Attachment 2 - Clauses and Provisions.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
May 27, 2022
Statement of Work
(SOW)
Web Intensive New Gain System (WINGS)
Web Application Penetration Test
MAXWELL AFB,
ALABAMA
Introduction
As part of WINGS (Web Intensive New Gain System) AETC ATO (Authority to Operate), we are required to have Web Application Penetration Test performed yearly. Web application security testing is focused on evaluating the security of a web application. The process involves an active analysis and exploitation of the web application for any weaknesses, technical flaws, or vulnerabilities. All external facing WINGS Web Applications require a WINGS Annual Authorization penetration test. Listed below are the requirement for the Penetration Test.
Purpose:
1. Remotely perform standard external penetration test (Pen Test) on USAF WINGS (Web Intensive New Gain System) and provide a report with vulnerabilities.
Requirements:
1. Perform Pen Test on four external facing WINGS websites.
2. Access to websites is through external web interface.
3. External Pen Test only – no infrastructure or internal Pen Test.
4. Pen Test is to be performed remotely with no on site work required.
5. Pen testing execution using standard technical guidelines (PTES Technical Guidelines) in accordance with the OWASP Testing Guide 4.1.
6. Pen testing shall utilize OWASP’s Top 10 and performed on the external facing WINGS sites.
7. The Pen Test is Grey Box.
8. Experience performing DoD Pen Tests (preferably USAF) using Risk Management Framework
(RMF).
9. Testing will be performed with unauthenticated and self-authenticated student access.
10. Pen Test phases should be Planning, Execution, Analysis, Report, and Acceptance.
11. Pen Test must be complete within 30 days of execution of plan.
12. Pen Test report must include tests performed, analysis, and vulnerabilities with severity level.
13. Vendor will not be required to perform any additional testing to verify vulnerabilities are remediated.
14. If access is gained to PII other than the tested user, the testing must HALT and POC notified.
15. Pen Test can be performed after hours if POC is notified.
16. Access to WINGS Staff will be provided for planning.
17. The Pen Test must be performed and results received between 10 June and 31 July as agreed to by both parties.
Additional Information:
1. External Websites will be provided.
2. Test accounts will be provided.
3. If requested, a Pen Test report example will be provided.
4. Hardware is currently located on a secure USAF Data Center.
5. WINGS is currently on a commercial ISP – closed network.
6. WINGS POC will be provided for the Pen Test.
7. Access to WINGS Staff will be provided for planning via phone, MS Teams, or other remote tool.
Author:
Donnie Moore WINGS Program Manager Holm Center/SDC 130 West Maxwell Blvd Maxwell, AFB AL 36112-6106 Comm: (334)953-4436
| Statement of Work (SOW) |
| MAXWELL AFB, ALABAMA |
File details come from the government source that posted it. Updated .