Attachment 2 - PROTECTS PWS.docx

DOCX document 213 KB Posted

Attached to
DRAFT RFQ PROTECTS Federal contract opportunity
Solicitation number
2032H5-24-Q-00009
Issued by
Department of the Treasury Internal Revenue Service

About this file

This is a draft request for quote (RFQ) from the Department of the Treasury seeking feedback from capable vendors on providing Treasury Enterprise Cybersecurity Technology and Services (PROTECTS). The RFQ solicits feedback on attachments including a price template, performance work statement, provisions and clauses, questions and answers template, resume template, labor category descriptions, demonstrated corporate experience mock scenario, and ordering guide. Responses to the draft RFQ are due through eBuy by February 2, 2024 at 10:00 AM EST and will be reviewed and considered by Treasury. No quotes or proposals are being accepted currently. The feedback requested relates to the draft RFQ and its attachments.

View the file

Other files for this federal contract opportunity

Other files attached to DRAFT RFQ PROTECTS, newest first.
File Type Posted
Attachment 4 - Questions and Answers Template.xlsx XLSX spreadsheet
Attachment 1 - Price Template.xlsx XLSX spreadsheet
Attachment 1 MSS Template.docx DOCX document
Attachment 3 - PROTECTS Provisions and Contract Clauses.docx DOCX document
Attachment 8 - Mock Scenario.docx DOCX document
PROTECTS RFQ 24-Q-00009.docx DOCX document
Attachment 5 - PROTECTS Resume Template.docx DOCX document
Attachment 6 - PROTECTS Labor Category Descriptions.xlsx XLSX spreadsheet
Attachment 7 - PROTECTS Demonstrated Corporate Experience.xlsx XLSX spreadsheet
Attachment 9 - Ordering Guide.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS) Providing Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) Highly Adaptive Cybersecurity Services (HACS)

Department of Treasury, Performance Work Statement

PROTECTS HACS

December 20th, 2023

Table of Contents

1Introduction4
1.1Background4
1.2Purpose5
1.3Ordering Period6
1.4Task Execution Models and Place of Performance7
1.4.1On-Premises, Government Provided Solutions7
1.4.2Managed Security Services Provider (MSSP)7
1.4.3Travel Requirements7
1.5Key Personnel8
1.6Applicable Documents8
2Scope of Work10
2.1Core Operational Framework10
2.2Functional Area 1: Management and Control12
2.2.1Program Management12
2.2.2SOC Operations Management12
2.2.3Transition Planning and Management13
2.2.3.1Contractor Level Transition13
2.2.3.2Task Order Level Transition14
2.2.3.3Outgoing Transition14
2.2.4Task Order Management15
2.2.5SOC Services Delivery Management15
2.2.5.1SOC Performance and Investment Metrics15
2.2.5.2Managed SOC Services Delivery Processes and Procedures16
2.3Functional Area 2: Information Security Incident Management16
2.3.1Real-Time Alert Monitoring and Triage17
2.3.2Incident Report Acceptance and Coordination17
2.3.3Incident Analysis18
2.3.4Forensic Artifact Analysis and Malware Analysis18
2.3.5Containment, Eradication, and Recovery19
2.3.6Fly-Away Incident Response19
2.3.7Continuity of Operations (COOP)19
2.4Functional Area 3: Vulnerability Management20
2.4.1Asset Mapping20
2.4.2Vulnerability Scanning20
2.4.3Vulnerability Assessments20
2.4.3.1Phishing Assessment21
2.4.3.2Wireless Assessment21
2.4.3.3Web Application Assessment21
2.4.3.4Operating System Security Assessment (OSSA)21
2.4.3.5Database Assessment21
2.4.4Vulnerability Report Intake and Analysis21
2.5Functional Area 4: Adversary and Advanced Operations22
2.5.1Cyber Threat Intelligence (CTI) Collection and Processing22
2.5.2Cyber Threat Intelligence (CTI) Sharing and Distribution23
2.5.3Threat Hunting24
2.5.4Insider Threat Hunting24
2.5.5Adversary Emulation24
2.6Functional Area 5: SOC Architecture, Engineering, Deployment and Management25
2.6.1SOC Architecture and Strategy25
2.6.2Security Architecture Review (SAR)25
2.6.3SOC Research and Engineering26
2.6.4Information System Security Engineering26
2.6.5Network Security Capability Deployment and Management27
2.6.6Endpoint Security Capability Deployment and Management27
2.6.7Cloud Security Capability Deployment and Management28
2.6.8SOC Tool and Enclave Deployment and Management29
2.6.9Sensor and Analytics Tuning29
2.6.10Custom Analytics and Detection Creation30
2.6.11SOC Custom Capability Development30
2.7Functional Area 6: SOC Capability Improvement Activities31
2.7.1Knowledge Transfer31
2.7.2Cyber Range31
2.7.3Content Management / Knowledge Management31
2.7.4Future Requirements32
3Deliverables, Performance Thresholds and Acceptance32
3.1Deliverables32
3.2Services Delivery Summary (SDS)38
3.3Acceptance Criteria41
4Performance Monitoring/Acceptance Criteria42
5Government Furnished Property43
6Security Categorization43
6.1General Security44
6.2Task Order Security Requirements47
7Homeland Security Presidential Directive (HSPD -12) Requirement47
8Supply Chain Considerations47
Appendix AList of Acronyms and Abbreviations49
Appendix BEstimated Workload – Quantifying Treasury Enterprise Scope54
Appendix CApplicable Documents58

Introduction The United States Department of the Treasury is the executive agency responsible for promoting economic prosperity and ensuring the financial security of the United States. Treasury is responsible for a wide range of activities such as advising the President on economic and financial issues, encouraging sustainable economic growth, and fostering improved governance in financial institutions. Treasury operates and maintains systems that are critical to the nation's financial infrastructure, such as the production of coin and currency, the disbursement of payments to the American public, revenue collection, and the borrowing of funds necessary to run the federal government.

Treasury and its Bureaus and Departmental Offices (DO) operate Security Operations Centers (SOCs) and perform enterprise Security Operations (SecOps) services on both an individual Bureau and shared services basis. Hereby collectively referred to as SOCs within this document, these capabilities provide the means to monitor, detect, and respond to cybersecurity threats to their networks, information processing systems, and sensitive data. Treasury and its Bureaus/DO rely upon contracted personnel and other organic IT resources to staff and operate select SOC functions.

The PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) program serves as a framework and solution set to standardize solutions and operating models in providing cybersecurity services across the enterprise both within individual Bureaus and DO and at an enterprise level. PROTECTS helps furnish the best cybersecurity services possible to Treasury, Treasury Bureaus and those federal government agencies who depend on Treasury for their financial management.

Background The Treasury is the national treasury of the federal government of the United States, serving as an executive Cabinet department. The Treasury collects all federal taxes; manages U.S. government debt instruments; licenses and supervises banks and thrift institutions; advises the legislative and executive branches on matters of fiscal policy; oversees the printing and circulation of all paper currency and coins in the domestic fiscal system. The Treasury is unique that it is not only a federal agency, but it is also a large financial institution.

Established by an Act of Congress in 1789 to manage government revenue, the first secretary of the Treasury was Alexander Hamilton, sworn into office on September 11, 1789. The Treasury has grown from its offices at 1500 Pennsylvania Ave N.W. to a diverse worldwide organization of 120,000 employees with offices in every State and Territory and operational presence in Africa, Asia, Europe, and Latin America.

Treasury is organized into two major components: the DO and the operating bureaus. DO is primarily responsible for the formulation of policy and management of the Treasury as a whole, while the operating bureaus carry out the specific Treasury mission operations.

The Office of the Chief Information Officer (OCIO) resides within the Treasury’s DO. The OCIO provides leadership to the Treasury and its Bureaus in all areas of information and technology management and supports Treasury's mission by implementing strategies that improve the efficiency and performance of Treasury information technology (IT) systems and business processes. OCIO has Treasury-wide responsibility for the direction and development of Treasury’s IT strategy, management of IT investments, and leadership of key technology initiatives. As a pillar of Treasury OCIO, the Associate Chief Information Officer for Cybersecurity (ACIO/CS) is a service provider of cybersecurity solutions through shared and scalable products, platforms, and services. ACIO/CS offers all Treasury Bureaus, Offices, and leadership with a variety of cybersecurity services and solutions for securing and protecting Treasury systems and associated sensitive business data. ACIO/CS works in collaboration with the various programs of the Treasury to ensure the cybersecurity of the Treasury networks, information, and information systems used in performance of Treasury’s mission. ACIO/CS operates and maintains several security applications and platforms with which it fulfills its mission of protecting the Treasury IT Infrastructure/Network. This mission not only supports the need for operation of services but also ensures the safe and effective processing of transactions and data of one of the world’s largest financial institutions. Implementation of advanced and comprehensive cybersecurity protections around the clock are required to stop the evolving threats and malicious activities in cyberspace. The PROTECTS program serves as tool to meet Treasury’s needs and ensure that the Treasury bureaus and those Federal Government agencies who depend on Treasury for its financial management have the best cybersecurity services possible. The purpose of Treasury’s PROTECTS SOC Blanket Purchase Agreement (BPA) under the General Services Administration (GSA) Highly Adaptive Cybersecurity Services (HACS) Special Item Number (SIN) is to provide enterprise -wide cybersecurity services while meeting the specific – and sometimes unique – cybersecurity needs of DO and the individual Treasury Bureaus.

The intent of PROTECTS BPA is to adapt and transform cyber service operations and operating models across Treasury and its Bureaus to improve capabilities, consistency, and economies of scale across the Treasury enterprise cybersecurity and SOC functions while reducing enterprise cybersecurity risks including new, emerging, or evolving cyber threats.

Purpose The purpose of this Performance Work Statement (PWS) is to describe Treasury and its Bureaus/DO requirements for the professional cybersecurity services necessary for operating SOCs, including improving capabilities and supporting SOC functions. Core required services align to the following SOC service areas: information security incident management; vulnerability management; adversary and advanced operations; SOC architecture, engineering, deployment, and management; and SOC support activities.

In accordance with Federal Information Technology Acquisition Reform Act (FITARA) and the Office of Management and Budget (OMB) Category Management initiatives to manage common commodities and services in a more centralized manner, Treasury has developed this BPA for SOC services for Department of Treasury-wide utilization. This BPA provides a common framework for all SOC operations within the Department and standardizes roles and responsibilities for contractor support. The Department is composed of over 200,000 Federal permanent and temporary employees and contractors spanning bureaus and offices, all with their own management structures, budgets, and procurement organizations. This structure has resulted in mission success for individual organizations but did not leverage the collective buying power of Treasury and required duplicative work in managing responses to cybersecurity incidents. This BPA will provide a single Department-wide vehicle to maximize efficiencies, manage spend, reduce risk, and maximize productivity. This BPA has the capability to address all mission-critical requirements for each Bureau, thereby replacing the many diverse contract vehicles across Treasury and eliminating the multiple types of service contracts. The BPA will be open to the following Treasury Bureaus and Offices:

Alcohol and Tobacco Tax and Trade Bureau (TTB) Bureau of Engraving and Printing (BEP) Bureau of the Fiscal Service (BFS) Community Development Financial Institution Fund (CDFI) Departmental Offices (DO) Financial Crimes Enforcement Network (FINCEN) Internal Revenue Service (IRS) Office of the Comptroller of the Currency (OCC) United States Mint (MINT) Office of Inspector General (OIG) Treasury Inspector General for Tax Administration (TIGTA) Special Inspector General for Troubled Asset Relief Program (SIGTARP) Special Inspector General – Pandemic Recovery (SIGPR) Treasury envisions a multiple award BPA under which each awardee team can deliver the full scope of services described in this PWS, issued as individual Task Orders (TO). Optional tasks may be identified on each award allowing Bureaus/DO to order only those services needed.

Ordering Period The Ordering Periods for the PROTECTS SOC BPA include a 12-month base year with 7 optional years and are as follows:

Base Ordering Period: June 2024 – May 2025 (12-months) Optional Ordering Period 1: June 2025 – May 2026 (12-months) Optional Ordering Period 2: June 2026 – May 2027 (12-months) Optional Ordering Period 3: June 2027 – May 2028 (12-months) Optional Ordering Period 4: June 2028– May 2029(12-months) Optional Ordering Period 5: June 2029 – May 2030 (12-months) Optional Ordering Period 6: June 2030 – May 2031 (12-months) Optional Ordering Period 7: June 2031 – May 2032 (12-months)

The Period of Performance (POP) for subsequent orders will be determined at the task order level. POPs may include award of up to seven option years beyond the base year for the order. Option year awards may include allowing subsequent modifications to be issued during the award’s Period of Performance (POP) that add services still within scope of this PWS but which were not included in the initial order award.

Task Execution Models and Place of Performance Two models of execution will be utilized within the scope of this BPA to provide flexibility to the Bureaus/DO requiring SOC services. Place(s) of performance will be driven by the execution model identified for a specific task. The required execution model will be identified for each task on individual TOs. The following defined models may be utilized for any task within the scope of this BPA.

On-Premises, Government Provided Solutions For tasks executed under this model, the work shall be performed at a Government location or authorized telework/telecommute location and use Government owned IT assets. The Contractor shall operate and maintain previously deployed and authorized security solutions provided by the Government that are associated with the specific service defined within the task. If new security solutions are required for successful security service execution, the Government will purchase the new security solution and the Contractor shall assist with deployment and authorization of the solution as requested. The specific place(s) of performance and provided security solution(s) will be identified on individual TOs.

Managed Security Services Provider (MSSP) For tasks executed under this model, the work shall be performed at the Contractor’s location or authorized Government/telework/telecommute locations, and with the Contractor’s IT assets, all to be delivered and unit priced as a service. The Contractor shall execute all aspects of the security service on behalf of and in coordination with the supported Bureau/DO. The Contractor shall ensure the security of the Bureau/DO information and provide the Bureau/DO access to their data as requested. At the end of the period of performance, the Contractor shall provide copies of all Bureau/DO data to the Bureau/DO and sanitize the Contractor’s equipment of Government data.

Travel Requirements Travel requirements will be specified at the TO level. Contractor local travel (i.e., within fifty miles of the supported SOC function facility) will be required but will not be reimbursed by the Government. Long distance travel to various Bureau/DO SOC functional services facilities, to other Bureau/DO facilities across the U.S., and to Bureau/DO Enterprise Computing, Service Campus and Call Center facilities in the Continental U.S. and Puerto Rico may be required in exceptional situations.

Key Personnel Treasury and its Bureau/DO SOCs require a skilled and experienced team that can successfully manage and deliver SOC services. The Contractor shall assign a Program Manager who shall ensure compliance with all the task order requirements and be the primary Contractor point of contact for the work to be performed. The Contractor shall assign a SOC Project Manager and Chief Cybersecurity Engineer with appropriate technical certifications (e.g., Certified Information Systems Security Professional (CISSP)) to assist the Program Manager with technical responsibilities.

The Program Manager, at a minimum, shall possess:

A Project Management Professional (PMP) certification (or equivalent) plus 4 years of experience in cybersecurity OR 6 years of documented cybersecurity project management experience.

The SOC Project Manager, at a minimum, shall possess:

Three years of running a SOC, with a preference for experience running a combined on-premises/cloud SOC.

Five years of experience in cybersecurity incident response in one or more single environments with 50,000+ endpoints, with duties that include all five portions of the National Institute of Standards and Technology (NIST) Cybersecurity Framework (Identify, Protect, Detect, Respond, and Recover).

The Chief Cybersecurity Engineer, at a minimum, shall possess:

CISSP certification with two years of experience or four years of experience employed in a governmental organization (as a government or contract employee) as a cybersecurity engineer.

Two years of experience with governmental (FedRAMP) hybrid on-premises and cloud technology stack environments, with preference given to cybersecurity engineers with transition experience moving from an on-premises to a hybrid on-premises and cloud network solution.

The Program Manager, SOC Project Manager, and Chief Cybersecurity Engineer shall be subject to the Key Personnel provisions of Section G Contract Administrative Data. Before replacing any individual designated as key, the Contractor shall notify the Government no less than 15 business days in advance, if not sooner, and submit a written justification for replacement and provide the resume of any proposed substitute(s). All proposed substitutes shall possess qualifications equal to or superior to those of the key person being replaced, unless otherwise approved by the Government.

Applicable Documents The Contractor shall comply with the requirements set forth in the most current version of the applicable documents, including those that supersede versions current at the time of award. The Contractor shall also comply with any future legislation, guidelines, or policy immediately upon issuance. Additional Bureau/DO guidance may be included within specific TOs. A list of BPA applicable documents can be found under Appendix C (Page 54).

Scope of Work The Contractor shall provide the knowledge and expertise to protect and monitor technology and information assets on a 24X7X365 (24 hours per day, 7 days per week, full year with no holiday or leave gaps) basis across the Treasury and its Bureaus/DO with an enterprise footprint comprising both CONUS and OCONUS (Alaska, Hawaii, and U.S. Territories) locations plus currently a dozen foreign countries (>350,000 endpoints). The Contractor shall provide staff and management for the operation of selected SOC functions on behalf of Bureaus/DO to protect Bureau/DO information systems and infrastructure, operating within enterprise environments (e.g., on-premises and cloud). The Contractor shall further perform designated SOC activities during Bureau/DO Information System Contingency Plan (ISCP) and Disaster Recovery (DR) Tests, Training, and Exercises (TT&E) plus actual recover operations at a designated recovery location(s).

Specific categories of tasks that fall within this scope of work and reflect the necessary Contractor capabilities, are outlined in the following sections.

Core Operational Framework Functional areas that will make up the SOC Core Operational Framework to be addressed by the Contractor are described below. TOs against the BPA may be released against individual tasks defined within the following functional areas or released requiring the delivery of integrated solutions across multiple, combined tasks and functional areas of the PWS. The contractor shall deliver both individual capabilities and integrated solutions as needed by the Bureaus.

1. Management and Control provides for the Contractor oversight and coordination with Government for overall execution of TOs within the scope of this BPA, up to and including contractual deliverables and financial controls. The Contractor’s Program Manager is one of the primary points of contact with Government SOC Leadership. This functional area also includes SOC service delivery management, which provides the overall relationship management for operational service delivery activities and manages end‐to‐end service ownership. Service Delivery staff meets with Government SOC leadership regularly, follows up on escalations, drives proactive problem management, provides Service Level Management (SLM), availability management, and reports and focuses on continual improvement of services.

2. Real-Time Information Security Incident Management is responsible for performing SOC functions focused on management of anomalous and/or malicious events for enterprise environments, including:

Real-time alert monitoring and triage, Incident report acceptance and coordination, Incident analysis, Forensic artifact and malware analysis, Containment, eradication, and recovery, Fly-away incident response, and Continuity of Operations (COOP).

3. Vulnerability Management is responsible for performing SOC functions that assist with maintaining a holistic picture of the enterprise environment and assessing the security posture of the contained assets, including:

Asset mapping, Vulnerability scanning, Vulnerability assessments, and Vulnerability report intake and analysis.

4. Adversary and Advanced Operations is responsible for performing SOC functions focused on understanding and hunting for cyber adversaries, including:

Cyber threat intelligence (CTI) collection and processing, CTI sharing and distribution, Threat hunting, Insider threat hunting, and Adversary emulation.

5. SOC Architecture, Engineering, Deployment and Management is responsible for performing SOC functions focused on the selection, deployment, operation, and maintenance of cybersecurity capabilities, including:

SOC architecture and strategy, Security architecture review (SAR), SOC research and engineering, System security engineering, Network security capability deployment and management, Endpoint security capability deployment and management, Cloud security capability deployment and management SOC tool and enclave deployment management, Sensor and analytics tuning, Custom analytics and detection creation, and SOC custom capability development.

6. SOC Capability Improvement Activities perform functions that ensure maturity and evolution of SOC operations, including:

Knowledge transfer, Cyber range Content /knowledge management, and Future requirements.

Functional Area 1: Management and Control The Contractor shall provide program-level management and SOC-level management. The Contractor shall perform the Program Management activities defined in this PWS, in accordance with program and project management principles as defined in Bureau/DO Cybersecurity Standard Operating Procedures (SOPs) and by the Project Management Institute, to include preparation of Program and Task Order Management Plans, cost analyses, activity and project tracking schedules, risk registers, and risk and issue mitigation strategies for all SOC activities.

Program Management The Contractor shall provide program management to accomplish the administrative, managerial, logistical, integration and financial aspects specified in individual TOs. The Contractor shall continuously monitor their performance under this BPA and its subordinate TOs awarded to the Contractor, to provide the Government with a timely assessment, per TO Service Level Objectives (SLOs), of program progress, risks, issues, and proposed resolutions. The Program Manager shall have sufficient corporate authority to direct, execute, and control all elements of the Contractor’s SOC services work program and ensure that all necessary management, analysis, business, contracts, engineering, implementation, and maintenance personnel resources are available and sufficient, both in numbers and qualifications, to successfully perform all required activities under each TO.

The Contractor shall develop and provide a SOC Services Program Management Plan to the Government under each issued TO. Once approved by the Government, the Contractor shall perform the required cybersecurity functions as described.

The Contractor shall prepare and deliver weekly, monthly, and quarterly TO status updates and reports consisting of a summary of SOC services and activities; SOC performance and investment metrics and trends; the status of security incidents by category; statistics for event and incident tickets, call logs, investigatory cases, and security event notifications; and actions accomplished during the respective reporting period in performance of the work requirement.

SOC Operations Management The Contractor shall manage its staff assigned to operate SOC functions for the Bureau/DO enterprise environments (e.g., cloud and on-premises). The Contractor shall assign technical management personnel to cover operations 24X7x365.

The Contractor shall:

Assign a SOC Project Manager to manage the Contractor’s staff. The Contractor’s SOC Project Manager shall report to the Government SOC lead and shall assign and deploy staff to achieve SOC objectives as identified by the Government.

Develop a SOC Communications Plan describing how the SOC Project Manager will communicate with the Government SOC lead and other Government leadership and how the Contractor’s SOC Project Manager will communicate with the Contractor’s staff.

Assign shift managers who shall oversee and direct Contractor staff activity on each shift to achieve 24x7x365 management coverage including escalation contacts.

Ensure that in the absence of the SOC Project Manager or of any of the shift managers that management responsibilities are delegated to one individual who shall have the authority equivalent to that of the SOC Project Manager to operate and execute during the absence of the regular manager.

Provide qualified staff to perform the work required under the pertinent TOs and meet the requirements established in the TO SLOs/SLAs.

Ensure that all staff possess the necessary technical skills and certifications to operate the Contractor’s solution set to deliver the required services, and that staff receive ongoing training necessary to maintain those skills and certifications.

Transition Planning and Management Contractor Level Transition The Contractor shall support Treasury and its Bureaus/DO Government leads, as applicable, with transition planning and transition plan execution associated with meeting the agreed upon timeline for transition of SOC services from any incumbent Contractor(s) and Government organization employees, or both, to the successor Contractor. This includes:

1. Coordinating with Government representatives and identification of roles and responsibilities (Responsible, Accountable, Consulted, Informed) at a level of aggregation detail such that only one entity is assigned as the Responsible party to each action required.

Reviewing, evaluating, and transitioning current Contractor services as well as assumption of responsibility for status quo operational capabilities, whether executed by Government or contractor entities. These activities may include the necessity for an architecture and engineering discovery and validation effort as part of task order startup activities.

Transitioning historical SOC data to any new systems as well as engineering and implementation of new system connections to any existing components that will continue in operation, as appropriate and identified and defined during any discovery under Item #2 above.

Ensuring that Contractor personnel receive and report the completion of all Government‐required training; and follow all Government certification processes for Government tools, processes, and systems, such as the ticketing system, etc.

Receiving all necessary SOC business and/or technical documentation and reviewing that documentation to validate against existing capabilities and known challenges.

Providing an orientation phase and program to introduce Government SOC personnel and other users of SOC services to the Contractor's team, tools, methodologies, business processes, equipment, etc.

Receiving Government Furnished Equipment (GFE) and Government Furnished Information (GFI), then using and managing both GFE and GFI within their control Providing GFE inventory management assistance.

Task Order Level Transition For individual TOs, the Contractor shall be responsible for active participation in the transitioning of SOC services from the incumbent Contractor as applicable.

The Contractor shall:

1. Develop a SOC Incoming Transition Plan that ensures that there is no degradation of SOC services during the transition. The SOC Incoming Transition Plan shall address the following elements:

a. Mobilization of the Contractor’s transition team.

b. Specific transition tasks to be executed and how they will be managed, comparable to Items #1, #2, #3 and #5 under 2.2.3.1 above.

c. Principal transition team members by name, position, and responsibilities.

d. Risks to the transition effort and mitigation and contingency plans in the event the transition cannot be executed on schedule.

e. Transition schedule in graphic format showing timing, sequence, and interdependencies between tasks. The transition schedule shall be supplemented by sufficient narrative.

2. Execute the transition as described in the Incoming Transition Plan.

Outgoing Transition For ending TOs, the Contractor shall plan, submit, and execute an Outgoing Transition Plan, ninety (90) calendar days from notification by the Government of the expected end of the TO, transitioning work from the Contractor to a successor Contractor or Government entity.

In accordance with the Government approved plan, the Contractor shall:

1. Develop a Transition Plan for transition to a successor Contractor or Government entity.

2. Assist the Government in executing the complete transition from this contract to a successor Contractor, including supporting architecture and engineering discovery research by the successor Contractor.

3. Deliver existing policies and procedures and historical and current SOC metrics and statistics.

4. Review, evaluate, and transition current Contractor services.

5. Transition historical data to the successor Contractor’s system(s). This will include, but is not limited to, raw logs and feed data; processed events; reports and presentations; lesson learned; knowledge management repositories; analytics and correlation rules; working analyst notes; playbooks; tactics, techniques, and procedures (TTPs); and architectures.

6. Transition Government‐approved Contractor training materials and certification process documentation.

7. Transfer all necessary business and/or technical documentation.

8. Transfer compiled and un‐compiled source code, to include all versions, maintenance updates, and patches.

9. Return GFE and GFI to the Government.

10. Transfer the GFE inventory management system, all user and maintenance documentation, and current GFE information in the system to the successor Contractor.

11. Facilitate applicable Government debriefings and personnel out‐processing procedures.

12. Turn‐in of all Government keys, identification and access cards, and security codes.

13. Provide a Contractor generated checklist for tracking all transition activities.

Task Order Management Each Treasury Bureau/DO will manage a separate TO against this BPA for the work required in their Bureau/DO, based on the size and complexity of the SOC services required. Additional details and the responsibilities of the TO Level Contracting Officer and Contracting Officer’s Representative are found in the Section G Contract Administrative Data.

SOC Services Delivery Management Service Delivery Management provides the overall relationship management for operational service delivery activities and manages the Contractor’s end‐to‐end responsibility for delivery of contracted SOC services. The Contractor’s Program Manager and senior Contractor technical staff shall meet with Bureau/DO Cybersecurity Operations management regularly (i.e., no less frequently than weekly) to follow up on risks, issues, and incident escalations; drive proactive problem management; present and discuss SOC performance and investment metrics; and report on the Contractor’s continuing initiatives to improve delivery of services and Bureau/DO SOC capabilities. The Contractor shall provide the following SOC Services Delivery Management tasks, as detailed in individual TO Statements of Objectives (SOO), PWS, or Statements of Work (SOW).

SOC Performance and Investment Metrics The Contractor shall coordinate with the Government to design, develop, and implement a SOC Performance and Investment Metrics Program.

The Contractor shall:

1. Maintain and execute a Performance and Investment Metrics Program for the SOC enterprise (both cloud and on-premises) and partner organizations supplying SOC-related function capabilities.

2. Develop and report against metrics that summarize the Contractor’s SOC operations.

3. Analyze and report against trends in metrics.

4. Report Contractor’s SOC metrics that inform organization’s executives, and other Government leadership and technical staff on the overall performance.

5. Develop and report Contractor’s SOC metrics that link improvements in Contractor’s SOC performance to Contractor‐initiated SOC processes and technology improvements, upgraded Contractor employee skills, and other Contractor initiatives.

6. Use Contractor’s SOC metrics to analyze the return on investment and mission effectiveness of individual SOC software tools and infrastructure hardware components,

7. Recommend, based on metrics analysis, actions such as the purchase of tools and hardware devices that will improve overall SOC performance, reduce costs, or improve response timelines.

8. Analyze and summarize (1) the impact of each significant incident and the recovery costs; (2) the capability effectiveness of Computer Network Defense (CND) sensor coverage and the operations and maintenance costs; (3) the effectiveness of the Contractor’s implementation of the Bureau/DO intrusion defense methodologies; and (4) the number and categories of threats of concern identified by the Contractor and supplied to the Contractor by external Government agencies.

9. Provide bi‐weekly Contractor’s SOC Performance and Investment Metrics Program Summary briefings, deliver quarterly written reports, and provide access to Contractor subject matter experts to defend and discuss specific Contractor’s SOC performance and investment metrics, analysis findings, and performance trends.

Managed SOC Services Delivery Processes and Procedures The Contractor shall:

1. Create and maintain process documentation for all processes provided by the Contractor to the SOC.

2. Develop and maintain SOPs for all Contractor’s SOC processes.

3. Train all Contractor’s SOC staff in the execution of operating procedures and collaborate with Bureau/DO staff on these procedures.

4. Develop and implement a quality management program to track Contractor’s SOC performance and assess changes in the level of performance over time.

Functional Area 2: Information Security Incident Management The contractor shall provide staff and management for the performance of SOC functions on behalf of the Bureau/DO focused on management of anomalous and/or malicious events (24 hours per day, 7 days each week - 24x7); 365 days per year [abbreviated 24x7x365]) for Bureau/DO enterprise environments to protect Bureau/DO infrastructure systems, applications, and data. The Contractor shall perform the following SOC activities during normal operations at location(s) identified in specific TOs. Should it become necessary to temporarily relocate SOC operations to a selected alternate site for emergency or test scenarios, the Contractor must be able to perform and extend normal SOC operations to such designated remote location for COOP.

Real-Time Alert Monitoring and Triage The monitoring and triage service includes identification and responsive, timely analysis of anomalous activity for potential intrusions, focused on correlation of available data and assessment against related activity.

The Contractor shall pro-actively review and assess system and network logs, events, information, and data from various systems, components, and tools available in the enterprise environments (e.g., on-premises and cloud), to detect and identify anomalous cyber activity. The Contractor shall investigate anomalous cyber events that are detected and identified within scope of their TO and any suspicious cyber activity reported to the Contractor from other entities, such as system administrators and the user community via incoming phone calls, emails, and incident tracking systems.

Real-time monitoring and triage activities include:

1. Monitoring of systems security status.

Investigating alerts from automated detection systems and anomalous activity.

Performing retrospective analysis based on threat intelligence and indicators of compromise (IOCs).

Escalating and reporting potential incidents to SOC leadership.

Creating and updating incident cases and tickets.

Managing monitoring and analysis data, including, but not limited to sensor, system, and application data from data creation through disposition.

Providing SOC direct access to, or automated feeds from, monitoring and analysis data, to enable enterprise-wide incident correlation activities.

Incident Report Acceptance and Coordination The Contractor shall receive and process incident reports and organize incident handling and response activities. The Contractor shall receive, and process reports of suspicious cyber activity reported to the Contractor from other entities, such as other internal organizational components, users, contractors, or 3rd party service providers. The Contractor shall also receive and process incident reports or situational awareness updates from agency partners, to include but not limited to, CISA, and other Treasury and Bureau/DO SOCs. Methods of notification may include, but not be limited to, phone calls, emails, and incident tracking systems.

The Contractor shall organize incident handling and response activities across the SOC functional teams and/or any other pertinent parties (to include external vendors). The Contractor shall establish and maintain a simple knowledge base for reference during response to the incident, documenting every step taken and the timeline of all relevant findings.

Required activities include:

1. Monitoring communication channels (e.g., phone and email) for incoming reports.

Escalating and reporting potential incidents to SOC leadership.

Creating and updating incident cases and tickets.

Ensuring potential incidents are referred to appropriate teams for further investigation.

Providing oversight and guidance for all cyber incidents; leading incident handling and response activities.

Fulfilling documentation, reporting, and escalation requirements in accordance with (IAW) organization and regulatory guidance.

Coordinating with intelligence community and law enforcement organizations, under the direction of the Government SOC lead.

Reviewing all reported incidents and verifying that all pertinent information is recorded, confirmed, and that closure occurs only after all remediation and reporting activities have occurred.

Incident Analysis SOC incident analysis by the Contractor shall include in-depth, detailed analyses of suspected incidents. The in-depth analysis should address the “who”, “what”, “where”, “when”, “how” and the operational impact of the incident. The analysis should also characterize the confidence level of these conclusions, including information sources where confidence levels have been derived.

When performing incident analysis, the Contractor shall work with Bureau/DO IT organization personnel, including other Bureau/DO contractors, and/or any other pertinent parties (to include external vendors), to gather artifacts and correlate activity. The Contractor shall use findings from these activities to inform, expand, or focus monitoring efforts; and produce Incident Analysis Reports that include recommended remediation activities.

Additionally, the Contractor shall maintain cybersecurity incident documentation; support Bureau organizational and other Federal reporting requirements; and refine analysis techniques based on lessons learned.

Forensic Artifact Analysis and Malware Analysis Forensic artifact and malware analysis services involve analyses on a variety of forensic images, digital media devices, and mediums to identify, reverse engineer, and de-obfuscate content related to an incident, such as malicious payloads masquerading as legitimate content. As tasked, the Contractor shall provide detailed written technical reports of findings that include the methodology used during the forensic evaluation, the findings from the evaluations, and any recommendations for further action. Forensic artifact and malware analysis activities include coordinating with the Government to use these findings to inform, expand, or focus monitoring efforts and continuously developing and refining analysis techniques to incorporate lessons learned and industry best practices.

The Contractor shall:

1. Capture forensic images to be used in investigations of cyber incidents.

Conduct analysis of forensic images and digital media, keeping such images and media separate from enterprise operational systems and environments.

Identify, reverse engineer, and de-obfuscate content related to cybersecurity incidents.

Conduct analysis and reverse engineering of malicious content in a separate and contained malware environment, i.e., non-Internet connected and with no connectivity to any operational network or host component, enforced by border firewalls and other supporting segregation tools including audit confirmation that no cross-traffic has occurred between those environments.

Document analysis findings in technical reports to include IOCs found during the forensic analysis.

Containment, Eradication, and Recovery The Contractor shall perform mitigation and recovery activities at the discretion of the Government SOC lead. The Contractor shall collaborate, coordinate, and perform related activities for adversary containment, damage management, adversary eviction at appropriate points in time (e.g., not prematurely to alert the attacker that their exploits have been detected) and recover systems to a state that will not only restore functioning to pre-exploit levels but will also prevent similar incidents in the future. Deployment of countermeasures to on-premises and cloud environments will be performed under Government SOC lead direction to contain cybersecurity incidents. The Contractor shall confirm completion of directed actions SOC operations to ensure that incident closure occurs only after all remediation and reporting activities have occurred in accordance with organizational guidance.

Fly-Away Incident Response The Contractor shall perform onsite incident response, at the direction of the Bureau/DO Government SOC lead, at physical locations where SOC analysts do not routinely reside. The Contractor shall maintain a Fly-Away Kit containing tools and copies of procedures, to include but not limited to digital media analysis tools, necessary to perform response activities. The Contractor response team shall be able to deploy within 24 hours of notification. The contractor shall have hands-on involvement in gathering artifacts and recovering systems, as needed. In all cases, the Contractor shall perform the onsite incident response in coordination with the Bureau/DO SOC, external service providers, Bureau/DO system owners, system administrators, and Information System Security Officers (ISSOs), as appropriate.

Continuity of Operations (COOP) The contractor shall provide personnel to the COOP site to perform daily operations when the Bureau/DO SOC COOP status is invoked by the Government SOC lead. The contractor shall provide personnel at the COOP SOC site within 48 hours after the Bureau/DO SOC COOP Status is invoked. The contractor shall ensure that all SOC cybersecurity feeds are directed to or accessible from the COOP SOC site. The contractor shall ensure that all, or a Contracting Officer’s Representative (COR) approved subset, of the contractor’s Bureau/DO SOC staff are onsite at and prepared to work the COOP, as scheduled, until the Bureau/DO SOC COOP Status is canceled by the COR. The contractor shall participate in Bureau/DO SOC COOP Status exercises and tests to validate COOP procedures. Deliverables for COOP include, but are not limited to, a COOP Plan.

Functional Area 3: Vulnerability Management The Contractor shall provide staff and management for the performance of SOC functions on behalf of the Bureau/DO that assist with maintaining a holistic picture of the enterprise environments (e.g., on-premises and cloud) and assessing the security posture of the contained assets. The Contractor shall conduct assessments of threats and vulnerabilities; determine deviations from acceptable configurations or Bureau/DO policy; assess the level of risk; and develop and/or recommend appropriate mitigation countermeasures in operational and non-operational situations.

Asset Mapping The Contractor shall perform scanning to identify assets for agreed upon IP address space or network range(s) residing within its environmental scope of responsibility for purposes of assessing security risk and compliance status. For assets residing within the enterprise environment, the contractor shall gather and maintain system configuration information (e.g., operating systems/versions, key software/versions, interdependencies, etc.) for all identified assets. The contractor shall provide the government direct access to or automated feeds of asset configuration information. The Contractor shall also maintain, and provide to the government, a current mapping of the environment to understand the size, shape, makeup, and perimeter interfaces of the environment that includes the organization’s physical devices, network and host access points, and digital network.

Vulnerability Scanning The Contractor shall perform scanning to identify IT vulnerabilities associated with Bureau systems that are potentially exploitable by attackers for agreed upon IP address space or network range(s) residing within its environmental scope of responsibility for purposes of assessing security risk and compliance status. For assets residing within the enterprise environment, the contractor shall perform weekly (at a minimum) vulnerability scanning and analysis, and report vulnerability scanning results, including a risk assessment, to the Government within three (3) business days of the completion of the scan. The contractor shall provide the government direct access to or automated feeds of vulnerability scan results.

Vulnerability Assessments The Contractor’s Vulnerability Assessment Analysts shall provide onsite and remote vulnerability assessment capabilities as a sustained, full-time program independent of incident detection, recovery, or reporting activities. Activities shall include full-knowledge, open-security assessment of a Bureau/DO site, enclave, or system. The Contractor shall work with system owners and system administrators, to holistically examine the security architecture and vulnerabilities of their systems, through security scans, examination of system configuration, review of system design documentation, and interviews. The Contractor shall use network and vulnerability scanning tools, as well as invasive technologies used to interrogate systems for configuration and status. Deliverables for Vulnerability Assessment include, but are not limited to, a Vulnerability Assessment Report of Findings, along with recommended remediation. Specific types of vulnerability assessments are detailed in the following subtasks.

Phishing Assessment The Contractor shall complete activities to evaluate the level of awareness of the Bureau/DO workforce regarding digital form of social engineering that uses authentic looking, but falsified, emails requesting information from users or direct them to a fake website that requests information. Phishing assessments can be conducted as a one-time event or as part of a larger campaign to be conducted over several months. Deliverables for a Phishing Assessment include, but are not limited to, a Phishing Assessment Report that includes an executive summary and metrics that highlight potential weaknesses in an organization's email policy.

Wireless Assessment The Contractor shall include wireless access point detection, penetration testing, or both. A wireless assessment is performed while onsite at a customer’s facility. Deliverables for a Wireless Assessment include but are not limited to a Wireless Assessment Report that includes an executive summary, networking mapping, vulnerability analysis, and a wireless network configuration assessment on the wireless system.

Web Application Assessment The Contractor shall provide a Web Application Assessment that includes scanning, testing, or both of outward facing web applications for defects in web service implementation that may lead to exploitable vulnerabilities. Deliverables for Web Application Assessment include but are not limited to a Web Application Assessment Report that indicates whether traditional network security tools and techniques are used to limit access to the web service to only those networks and systems that should have legitimate access.

Operating System Security Assessment (OSSA) The Contractor shall assess the configuration of select host operating systems against standardized configuration baselines. Deliverables for OSSA include but are not limited to an OSSA Report that includes an executive summary and a vulnerability analysis.

Database Assessment The Contractor shall assess the configuration of selected databases against configuration baselines to identify potential misconfigurations and/or database vulnerabilities.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .