Attachment 5 - Mock TO5 PWS - Supply Chain Interdependencies.pdf

PDF 266 KB Posted

Attached to
NIST Cybersecurity and Privacy Support Services (CAPSS) - Pre-Solicitation Notice Federal contract opportunity
Solicitation number
1333ND23QNB770030
Issued by
Department of Commerce National Institute of Standards and Technology

About this file

This draft solicitation is seeking industry feedback on a planned solicitation for multiple Indefinite Delivery Indefinite Quantity (IDIQ) contracts to provide Cybersecurity and Privacy Support Services (CAPSS) to the National Institute of Standards and Technology (NIST). The solicitation is anticipated to be a 100% small business set-aside under NAICS code 541519 with a size standard of $30 million. It will require responses to the draft IDIQ Performance Work Statement and five mock task orders to represent best value. NIST intends to award multiple IDIQ contracts but reserves the right to award only one or none of the task orders. Prospective offerors are encouraged to partner and must comply with FAR 52.219-14 Limitations on Subcontracting. Industry is requested to identify elements requiring change or clarification and elements that must remain the same to maintain interest. Questions on specific portions of the draft documents are due by January 13, 2023 using the provided spreadsheet format. NIST will then respond to pertinent questions through an amendment and later issue the official solicitation.

View the file

Other files for this federal contract opportunity

Other files attached to NIST Cybersecurity and Privacy Support Services (CAPSS) - Pre-Solicitation Notice, newest first.
File Type Posted
Attachment 8 - Responses to Questions.pdf PDF
Attachment 4 - Mock TO4 PWS- Crypto Validation Support.pdf PDF
Attachment 3 - Mock TO3 PWS - NICE.pdf PDF
Attachment 6 - Past Performance Questionnaire.pdf PDF
Attachment 8 - Questions Submission Worksheet.xlsx XLSX spreadsheet
Draft Sol 1333ND23QNB770030-CAPSS Final 12.13.22.pdf PDF
Attachment 2 - Mock TO2 PWS - Software Development.pdf PDF
Attachment 1 - Mock TO1 PWS - Standards Support.pdf PDF
Attachment 7 - IDIQ Labor Rates Spreadsheet.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Supply Chain Interdependencies CAPSS Sample TO 5 Performance Work Statement

1.0 Background

Information Technology supply chains consist of organizations that collaborate to design, produce, source, and deliver products and services. All organizations are part of, and dependent upon, product and service supply chains. A compromise to the supply chain, such as with a cybersecurity attack, can result in risks to end users. Supply chain risks can include insertion of counterfeits, unauthorized production, tampering, theft, insertion of malicious software and hardware, as well as the use of poor manufacturing and development practices. Cyber-supply chain risk (C-SCRM) is an essential part of the risk landscape that should be included in organizational risk management programs.

Over the past 15 years, supply chains, especially those used in the technology-heavy industries, have grown in complexity and sophistication. Before, an organization may have a dozen regular suppliers each with their own, easily traceable, sub-suppliers. Now, instead of a supply chain, organizations have supply networks. The environment of today is such that an organization may use thousands of suppliers and switch between them with little notice or regularity. This, combined with the increased use of distributers instead of purchasing directly from manufacturers, has created an environment where organizations may have little visibility or control over their supply.

As with any network, the supply network has complex interdependencies. For example, the National Association of Regulatory Utility Commissioners (NARUC) produced a report1 that details some of the interdependencies between utilities, indicating that disruption in one utility, such as power, could affect another utility, such as water. This type of interdependency is increasingly becoming the case between many sectors and sub-sectors. In any supply chain risk management approach, an understanding of the interdependencies of supply networks is critical. It provides insight into which suppliers require additional C-SCRM protections and allows organizations to develop mitigating strategies. While some methods exist for mapping supply chains or networks, there is not currently a means for quantifying the interdependencies and associated cyber-supply chain risks.

2.0 Objectives

NIST’s Computer Security Division’s (CSD) objective for this tasking involves research into a quantitative approach for measuring interdependencies in supply networks and the level of risk associated with those interdependencies. This research will build on existing NIST research on criticality analysis and include an evaluation of existing models, the development of a potential solution, and creation of a document summarizing the research and solution. Research data and results will be formalized into a draft NIST Interagency Report (NIST IR) and should be usable by all sizes and types of organizations, including U.S. Government Departments and Agencies, keeping in mind that the guidance may also be used by various tiers of suppliers. The solution and resulting NIST IR will:

• Provide a method to relevant stakeholders for mapping and/or displaying in an easy-to understand format, interdependencies in supply chain networks

• Identify measures to consider when weighing interdependency risks

• Provide an adaptable algorithm for measuring interdependency risks related to an organization, a product, and/or a specific supplier

1 https://pubs.naruc.org/pub/536D8203-2354-D714-51C7-B46AB41E9EF2 https://pubs.naruc.org/pub/536D8203-2354-D714-51C7-B46AB41E9EF2

3.0 Scope

The contractor shall provide support services in assisting NIST to identify and evaluate current models that may relate to the problem at hand and develop a mathematical model for measuring and quantifying interdependency risks. The contractor shall perform a literature review and conduct interviews with subject matter experts as appropriate. The contractors shall provide support services in assisting NIST to develop a NIST Interagency Report (IR).

This is a hybrid firm-fixed price (FFP) and labor hour (LH) contract.

4.0 Tasks

For all deliverables in this section, the contractor shall post weekly progress to a NIST Contracting Officer’s Representative (COR) approved centralized directory or collaborative site such as the NFILES or SharePoint. Specifically, the contractor shall post all interim deliverables of such documents and digital content whether or not complete according to the requirements of this PWS. Only the final posting on the due date of the deliverable will be evaluated by the government according to the deliverable table in section 5.0 of this PWS for acceptance or rejection within 10 calendar days of submission. The government requires the weekly interim deliverables to ensure a tight coupling of work between the government Subject Matter Expert (SME) and the contractor provided Subject Matter Experts.

4.1 Review Existing Research and Solutions (FFP)

Significant work has been completed in the fields of logistics, supply chain management, and critical infrastructure protection related to interdependencies. Additionally, work has been done in the areas of quality management and hazard detection that can be applied. Previous research at NIST involved providing a method for organizations to identify the most critical assets within their organization. While research for this project may rely on some of the foundations of existing or past research, there are no known models or algorithms which adequately fulfill the needs of Federal departments and agencies in measuring cybersecurity risk related to supply chain interdependencies.

This task shall explore various existing methods for (a) measuring interdependencies in external supply networks, (b) visualizing network interdependencies, and (c) measuring relevant cyber-supply chain risks associated with external dependencies.

4.1.1 Activities

The contractor shall work cooperatively with NIST to:

• Identify relevant and useful literature

• Review and analyze identified literature

• Document (2-3 pages total, bulleted outline format) key findings which may be useful in the development of a solution

The literature identified for further review shall include:

• 3-5 publications related to existing methods for measuring interdependencies in a supply chain or other type of network (sometimes called “external dependencies”)

• 3-5 publications related to measuring cyber-supply chain risks

• 3-5 publications related to visualizing network interdependencies

Examples of appropriate pieces of literature include academic papers2, NIST publications3, whitepapers or presentations4, and books5.

In addition, the contractor shall, with the NIST SME, interview up to 3 subject matter experts to gain additional insights (which shall be included in the documentation).

Documented key findings shall include any information that may be useful in developing a solution.

Documentation must be clear, concise, accurate, and easily traceable to the original source.

Documentation shall be used to inform tasks 4.2 and 4.3.

4.2 Development of a Solution (Labor Hour)

There are currently several published methods used in industry for mapping supply chain or other network interdependencies, and some effort to measure third party risk, but the existing solutions are costly, qualitative, lack a researched foundation, or overly small in scope. Federal departments and agencies, along with other stakeholders, need a method for measuring the cybersecurity risk associated with interdependencies in their supply chains.

This solution will contain two parts: a procedure and a tool. It shall enable organizations to identify critical suppliers within their supply network. It shall also enable organizations to trace the potential impact of an incident throughout the supply network. The purpose of this solution would be to help prevent or mitigate situations like what happened after the tsunami in 2011 that crippled the market for hard drives6 or disruptions to the supply chain such as from the more recent NotPetya attacks7.

4.2.1 Activities

The contractor shall work cooperatively with NIST to develop a solution. The contractor shall:

• Identify metrics or measures useful in measuring cybersecurity-related interdependency risks

• Identify or develop a method for mapping supply chain interdependencies which can be modified or used for measuring cybersecurity risks

• Create and/or obtain 3-5 sets of real-world data correlating to 3-5 different use-cases for use in testing the solution

• Develop a quantitative algorithm for measuring cybersecurity risks associated with supply chain interdependencies

• Develop a software tool that applies the developed algorithm to the identified metrics or measures and produces a visual representation of cyber-supply chain interdependency risk

• Test and refine the solution using real-world or created data

The resulting solution shall involve both a procedure and a tool. The procedural portion shall provide a method for conducting an analysis of external supply chain interdependency risks and shall cover use of the tool. The overall solution shall be:

2 For example, https://nvlpubs.nist.gov/nistpubs/jres/121/jres.121.001.pdf 3 For example, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1190GB-5.pdf 4 For example, https://resources.sei.cmu.edu/asset_files/Podcast/2015_016_001_435533.pdf 5 For example, Hinson, B. Pragmatic Security Metrics. Taylor & Francis Group. Boca Raton, FL. 2013.

6https://www.theguardian.com/technology/2011/oct/25/thailand-floods-hard-drive-shortage 7 https://www.reuters.com/article/us-cyber-attack-maersk/global-shipping-feels-fallout-from-maersk-cyber-attack-idUSKBN19K2LE https://nvlpubs.nist.gov/nistpubs/jres/121/jres.121.001.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1190GB-5.pdf https://resources.sei.cmu.edu/asset_files/Podcast/2015_016_001_435533.pdf https://www.theguardian.com/technology/2011/oct/25/thailand-floods-hard-drive-shortage https://www.reuters.com/article/us-cyber-attack-maersk/global-shipping-feels-fallout-from-maersk-cyber-attack-idUSKBN19K2LE

• Quantitative, incorporating both mathematical analysis and procedural components

• Visual in nature, allowing users to readily see overall risk levels

• Accurate and thoroughly tested for bugs and usability

• Usable by federal departments and agencies of all types and sizes

• Flexible in terms of types of supply chains and use-cases it can support

• Adaptable by users in terms of measures, weighing factors, and algorithms used.

Metrics or measures shall involve data commonly or easily obtained by organizations, for example data commonly found on supplier questionnaires. As much as possible, metrics or measures shall be proven useful (through prior research as found in the literature review conducted in task 4.1).

4.3 Draft NIST Publication (Labor Hour)

The contractor shall develop a draft NIST IR (60 – 100 pages) that:

• Briefly describes the problem space

• Summarizes the research conducted in Task 4.1

• Describes the solution developed in Task 4.2

• Provides directions to organizations on how to use and adapt the solution

• Incorporates comments from the NIST SME

The publication shall provide readers with enough detail to validate, replicate, implement, and adapt the model to their needs. A Word template shall be provided. The estimated page count does not include title pages, Table of Contents, nor references.

4.4 Planning and Reporting (FFP)

4.4.1 Project Work Plan

All work to be accomplished under this task order shall be managed through an Integrated Project Work Plan (IPWP). The IPWP is due to NIST for review at least 2 days before the Kick-off meeting. NIST will approve the IPWP or provide comments for revision within 3 business days of delivery of the IPWP.

After the contractor accepts and incorporates the comments, the IPWP shall be considered the baseline for the work effort. The contractor shall provide status on the IPWP monthly and send the updated IPWP to the project stakeholders, to include the Government COR, Technical Lead and Project Sponsor (optional), as well as the contractor’s Task Order Manager and Key Personnel (optional) at least 3 days prior to the monthly status meeting. The project plan shall contain government dependencies highlighted in yellow. Updates to the plan that do not impact the critical path can be resolved at the monthly status meeting as a function of the project plan. Changes that extend the period of performance or impact product delivery (i.e., removing PWS defined deliverables or adding new deliverables) will be addressed. However, no changes may be made to the contract without the Contracting Officer’s approval. All anticipated changes shall be communicated to the Contracting Officer prior to execution of any changes to the Statement of Work and, if approved, will be formally revised by way of a bilateral modification via SF30 form. No work shall be performed outside of the established tasks or obligated funding without formal approval and execution by the Contracting Officer.

4.4.2 Kick-off Meeting

The contractor shall attend a kick-off meeting on-site at NIST Gaithersburg, or virtually while COVID-19 restrictions are in place, no later than 10 business days after award of the task order. The kick-off meeting shall be utilized to introduce all members of the contractor’s team, review all task order requirements and deliverables, review the initial IPWP provided by the contractor, evaluate the contractor critical path analysis, and discuss the contractor’s proposed approach. The contractor’s key personnel shall be present at the kick-off meeting.

Also, at the kick-off meeting, the contractor shall provide their critical path analysis of the IPWP and the decomposition of the government Work Breakdown Structure (Figure 1) to the level of work packages.

The IPWP shall include an identification of contractor resources, deliverables and completion dates, sequence of events, start dates, and duration for each activity.

4.4.3 Project Reporting

In addition to the monthly Integrated Project Work Plan updates described in Section 4.4.1, the contractor shall provide monthly status reports to ensure work progress is consistent with and will lead to successful completion of all tasks within the IPWP according to schedule.

Monthly status reports shall detail progress made during the prior month, progress expected during the next month, resources expended in terms of hours, any significant problems or issues encountered, recommended actions to resolve identified problems, and any variances from the baseline IPWP.

The contractor Task Order Manager for this work effort shall attend the standing monthly Program Manager’s meeting to provide a full status of the project, using Microsoft Project or similar application, to the government Program/Project Manager (P/PM), COR, and Project Sponsors. This meeting will typically be held on the NIST Gaithersburg campus and will typically last for 1 to 2 hours per meeting;

however, if campus access is restricted at the time of this meeting due to COVID-19 restrictions, the meeting will be held virtually. A conference room with a projection system will be provided for use by the contractors to present their updates. This meeting will be hosted by the NIST P/PM for the contract (or their designee) and will typically be attended by the relevant government CORs, all relevant contractor PMs, and potentially government Tech Leads or Sponsors. A teleconference capability may be furnished if needed. At the discretion of the P/PM or COR, the contractor may be asked to conduct a monthly status meeting with the government technical leads and key personnel to resolve issues identified/presented at the standing monthly Program Manager’s meeting.

After all tasks have been completed, the contractor shall deliver an electronic copy of all deliverables to the specified NIST shared site.

Task Area #1 – Input to NIST Documents Performance Work Statement

Figure 1: Government Work Break Down Structure (WBS)

4.1 Review Research & Solutions

4.2 Develop Solution

4.3 Draft NIST Publication

4.4 Planning & Reporting

CAPSS Sample TO 1 Performance Work Statement

5.0 Deliverables, Due Dates, and Performance Requirements Summary (PRS)

All deliverables shall be posted to NIST’s shared drive or via another secure method (i.e., PGP files via email for proprietary information) as identified by the Technical Lead or the COR. Deliverables will be evaluated by the COR for completeness and the COR will either accept or reject the deliverables within 10 calendar days of contractor submission. All deliverables shall be provided to the COR.

Deliverable & Task Description

Projected Completion Date Media / Performance Standard / Quantity

Monitoring Method

D1 / 4.1.1 Relevant literature identified, reviewed, & analyzed

Determined by

IPWP

• MS Word

• Literature identified shall include:

o 3-5 publications related to existing methods for measuring interdependencies in a supply chain or other type of network (sometimes called “external dependencies”) o 3-5 publications related to measuring cyber-supply chain risks o 3-5 publications related to visualizing network interdependencies

• Shall incorporate any feedback from the NIST SME

Tech Lead and COR review

D2 / 4.1.1 Documentation of key findings in literature

Determined by

IPWP

• 2-3 pages bulleted outline format in MS Word

• Documented key findings should include any information that may be useful in developing a solution

• Documentation must be clear, concise, accurate, and easily traceable to the original source

• Shall incorporate any feedback from the NIST SME

• Shall be of professional quality and free of typographical or factual errors

Tech Lead and COR review

D3 / 4.2.1 Draft system design of solution

Determined by

IPWP

• MS Word / Office

• A proposed, complete, detailed system design for the solution

• May use process diagrams, screen layouts, and/or other documentation

• Shall incorporate any feedback from the NIST SME

Tech Lead and COR review

D4 / 4.2.1 Draft list of metrics or measures to be used in the solution

Determined by

IPWP

• MS Word

• Metrics or measures should involve data commonly or easily obtained by organizations, for example data commonly found on supplier questionnaires

• As much as possible, metrics or measures should be known to be valid, accurate, and relevant

• Shall incorporate any feedback from the NIST SME

Tech Lead and COR review

Deliverable & Task Description

Projected Completion Date Media / Performance Standard / Quantity

Monitoring Method

D5 / 4.2.1 Map supply chain interdependencies

Determined by

IPWP

• MS Word or Excel

• Identify or develop a method for mapping supply chain interdependencies which can be modified or used for measuring cybersecurity risks

• Shall incorporate any feedback from the NIST SME

• Shall be of professional quality and free of typographical or factual errors

Tech Lead and COR review

D6 / 4.2.1 Data sets for testing Determined by

IPWP

• 3-5 data sets corresponding to 3-5 different use-cases (e.g., organizational supply chain level, a system’s supply chain, a single product’s supply chain, a single supplier)

• Data sets may be created or obtained from real-world situations

• Data sets must be sharable and human-readable

• Shall incorporate any feedback from the NIST SME

Tech Lead and COR review

D7 / 4.2.1 Proposed algorithm(s) to be used in the solution

Determined by

IPWP

• Proposed algorithm(s) involving mathematical analysis to provide quantitative result

• Result should be valid, repeatable, and adaptable

• Shall incorporate any feedback from the NIST SME

Tech Lead and COR review

D8 / 4.2.1 Final solution Determined by

IPWP

• Application

• Solution is a combination of human-based procedures and an automated tool o Procedural portion shall provide a method for conducting an analysis of external supply chain interdependency risks and shall cover use of the tool o Tool may be a self-contained app, a web-based app, an excel-based app, or other kind of tool that is widely used by most Federal Departments and Agencies along with other organizations that can be used without difficulty o The amount of human-based processes involved in the solution are as minimal as reasonable o Any programming involved in the creation of the tool uses secure coding techniques o Shall incorporate any feedback from the NIST SME

• The overall solution shall be:

o Quantitative, incorporating both mathematical analysis and procedural components

& Task Description

Projected Completion Date Media / Performance Standard / Quantity

Monitoring Method o Visual in nature, allowing users to readily see overall risk levels o Accurate and thoroughly tested for bugs and usability o Usable by federal departments and agencies of all types and sizes o Flexible in terms of types of supply chains and use-cases it can support o Adaptable by users in terms of measures, weighing factors, and algorithms used

• A copy of the source code shall be provided to NIST

D9 / 4.2.1 Results of testing Determined by

IPWP

• MS Word

• Testing results may include results from compiler checks, usability tests, manual tests, FUZZ tests, or other tests used to validate the solution

• Testing results must prove that the solution is accurate and reasonably free from bugs or vulnerabilities

Tech Lead and COR review

D10 / 4.3 Publication – initial outline Determined by

IPWP

• Between 3-5 pages outline in MS Word Tech Lead and COR review

D11 / 4.3 Publication – annotated outline

Determined by

IPWP

• Between 5-10 pages annotated outline in MS Word

• Shall incorporate any feedback from the NIST SME

Tech Lead and COR review

D12 / 4.3 Publication – initial draft Determined by

IPWP

• Between 45 and 55 pages in MS Word

• This page limit does not include title pages, references, or other required front matter

• Shall incorporate any feedback from the NIST SME and shall expand logically from the annotated outline (D11)

• Shall use the NIST IR template

• Shall be 80% free of typographical errors

& Task Description

Projected Completion Date Media / Performance Standard / Quantity

Monitoring Method

D13 / 4.3 Publication – final draft Determined by

IPWP

• Between 45 and 55 pages in MS Word

• This page limit does not include title pages, references, or other required front matter

• Shall incorporate any feedback from the NIST SME

• Shall use the NIST IR template

• Shall be 100% free of typographical errors and shall be of a professional quality comparable to other published NIST IRs

• New material expected to be less than 25%

D14 / 4.4.1 Integrated Project Work Plan (IPWP)

2 days prior to Kick-off meeting

• MS Project / MS Excel or similar

• The IPWP shall be delivered no later than 2 business days before the

Kick-off meeting

• The IPWP shall include an identification of contractor resources, deliverables and completion dates, sequence of events, start dates, and duration for each activity

• The IPWP shall be available in electronic format

Tech Lead and COR review

D15 / 4.4.2 Kick-off Meeting materials Within 10 business days of award

• MS Word / MS Project / MS PowerPoint

• The Kick-off meeting shall be no later than 10 business days after award of the task order

• Electronic copy of the agenda should be delivered to the COR at least

2 business days before the meeting

• The kick-off meeting shall be utilized to introduce all members of the contractor’s team, review all task order requirements and deliverables, review the IPWP, evaluate the contractor’s critical path analysis, and discuss the contractor’s proposed approach

Tech Lead and COR review

D16 / 4.4.3 Monthly Status Reports Monthly • MS Word / MS Project / MS PowerPoint

• Shall include items accomplished in the previous month, any problems encountered, and solutions implemented, planned activities for the next month, and CPI for any labor hours tasks

Task Area #1 – Input to NIST Documents Performance Work Statement

6.0 Government-Furnished Property, Material, Equipment, or Information (GFP, GFM, GFE, or GFI)

All work for this TO will utilize GFE. All GFE shall be utilized within the safety and security rules set by NIST. The government will provide copies of relevant documents (e.g., NIST SP 800-161) necessary to complete the tasks.

7.0 Key Personnel

Contractor Key Personnel shall meet the following minimum qualifications for each of the respective required key personnel positions. The titles of the positions given below are representative and are not from the schedule of IDIQ labor categories, they are simply examples of titles suitable to the type of work to be performed by the respective key personnel position. However, key personnel proposed for these positions must meet the minimum qualifications associated with the official labor category from the schedule of IDIQ labor categories the personnel are proposed under, plus meet the minimum qualifications detailed below for each position, respectively:

Network Theory Subject Matter Specialist (Senior) – Have at least 10 years intensive and progressive experience in the area of network theory.

Cyber Supply Chain Risk Management Subject Matter Specialist (Senior) – Have at least 10 years intensive and progressive experience in the area of cyber supply chain risk management or third-party risk management in an electronics or IT industry. Familiarity with the NIST Cybersecurity Framework (CSF), NIST SP 800-161, and NIST SP 800-171.

Software Developer – Have at least 8 years’ experience with programming software applications, including experience with presentation to management level personnel of complex network data.

8.0 Travel

There will be no travel for this Task Order.

9.0 Risk Level

This Task Order is a low-risk Task Order with no IT risk.

10.0 Place of Performance

All work shall be performed virtually until COVID-19 restrictions have been lifted from NIST’s Gaithersburg campus. When those restrictions are lifted, a percentage of the work will occur on campus. This percentage will be determined by the COR and Tech Lead based on the needs of the program at that time.

11.0 Period of Performance

This Task Order shall have a Period of Performance of 12 months from award.

File details come from the government source that posted it. Updated .