Attachment 8 - Mock Scenario.docx

DOCX document 36 KB Posted

Attached to
DRAFT RFQ PROTECTS Federal contract opportunity
Solicitation number
2032H5-24-Q-00009
Issued by
Department of the Treasury Internal Revenue Service

About this file

This draft request for quote from the Department of the Treasury seeks feedback on providing cybersecurity technology and services to the agency. Respondents are asked to submit comments and questions on the draft RFQ and its attachments by February 2, 2024 through the GSA eBuy system. The feedback will be considered as the agency looks to continue cybersecurity support currently provided under contract number 1662363. The mock scenarios in Attachment 8 describe potential cyber incidents involving critical vulnerabilities impacting Treasury infrastructure and systems, laying out questions for how a security operations center would coordinate a response both within teams and with external stakeholders.

View the file

Other files for this federal contract opportunity

Other files attached to DRAFT RFQ PROTECTS, newest first.
File Type Posted
Attachment 2 - PROTECTS PWS.docx DOCX document
Attachment 4 - Questions and Answers Template.xlsx XLSX spreadsheet
Attachment 1 - Price Template.xlsx XLSX spreadsheet
Attachment 3 - PROTECTS Provisions and Contract Clauses.docx DOCX document
PROTECTS RFQ 24-Q-00009.docx DOCX document
Attachment 5 - PROTECTS Resume Template.docx DOCX document
Attachment 6 - PROTECTS Labor Category Descriptions.xlsx XLSX spreadsheet
Attachment 7 - PROTECTS Demonstrated Corporate Experience.xlsx XLSX spreadsheet
Attachment 1 MSS Template.docx DOCX document
Attachment 9 - Ordering Guide.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) Professional Cyber Services Attachment 8

MOCK SCENARIO

The Mock Scenarios below represent a plausible cybersecurity situation impacting Treasury bureaus. Each problem will require the contractor to make assumptions about how their SOC offering will be leveraged to provide the requested service capabilities. The scenarios are not implying any additional requirements that are not documented in the RFP. As a part of describing your response, the contractor is expected to clearly articulate the assumptions they made to prepare a response and identify which services are required to meet the response.

Sample Scenario Part A: Critical vulnerability threatens Treasury infrastructure.

Overview: Treasury has received notification of a major security vulnerability impacting public facing servers that is currently being exploited by nation-state actors. The vulnerability does not have a patch available, but workarounds are surfacing on the internet from trusted sources such as reputable security vendors. For the purposes of the example: there are currently estimated to be 30 known hosts impacted by the vulnerability across 4 Treasury bureaus, but that number is not confirmed.

1. Describe the initial response activities taken.

a. Providing support as the top-level enterprise SOC; include coordination, communications, and escalations both internal to your team and externally to Treasury stake holders.

b. Providing support as a bureau level SOC; include coordination, communications, and escalations both internal to your team and externally to the bureau leadership and the enterprise SOC.

2. What is the SOC’s role in ensuring Treasury remains secure with minimal impact to business systems in this type of situation?

3. Identify prioritized steps the SOC should be taking under these conditions.

4. Propose the staff composition of the work – describe the different teams involved.

5. Describe how you measure success during an event like this.

Sample Scenario Part B: Critical vulnerability exploited.

Overview: The vulnerability from above has been exploited and a threat actor has an active web shell on at least 3 servers.

1. Describe how this evolves response activities.

a. Providing support as the top-level enterprise SOC; include coordination, communications, and escalations both internal to your team and externally to Treasury stake holders.

b. Providing support as a bureau level SOC; include coordination, communications, and escalations both internal to your team and externally to the bureau leadership and the enterprise SOC.

2. How does the staff composition change – what new roles are added?

3. Identify prioritized steps the SOC should be taking under these new conditions.

4. Describe how you measure success during an event like this, include possible metrics.

File details come from the government source that posted it. Updated .