Attachment 8 - Mock Scenario.docx
DOCX document 36 KB Posted
- Attached to
- DRAFT RFQ PROTECTS Federal contract opportunity
- Solicitation number
- 2032H5-24-Q-00009
About this file
This draft request for quote from the Department of the Treasury seeks feedback on providing cybersecurity technology and services to the agency. Respondents are asked to submit comments and questions on the draft RFQ and its attachments by February 2, 2024 through the GSA eBuy system. The feedback will be considered as the agency looks to continue cybersecurity support currently provided under contract number 1662363. The mock scenarios in Attachment 8 describe potential cyber incidents involving critical vulnerabilities impacting Treasury infrastructure and systems, laying out questions for how a security operations center would coordinate a response both within teams and with external stakeholders.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 - PROTECTS PWS.docx | DOCX document | |
| Attachment 4 - Questions and Answers Template.xlsx | XLSX spreadsheet | |
| Attachment 1 - Price Template.xlsx | XLSX spreadsheet | |
| Attachment 3 - PROTECTS Provisions and Contract Clauses.docx | DOCX document | |
| PROTECTS RFQ 24-Q-00009.docx | DOCX document | |
| Attachment 5 - PROTECTS Resume Template.docx | DOCX document | |
| Attachment 6 - PROTECTS Labor Category Descriptions.xlsx | XLSX spreadsheet | |
| Attachment 7 - PROTECTS Demonstrated Corporate Experience.xlsx | XLSX spreadsheet | |
| Attachment 1 MSS Template.docx | DOCX document | |
| Attachment 9 - Ordering Guide.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) Professional Cyber Services Attachment 8
MOCK SCENARIO
The Mock Scenarios below represent a plausible cybersecurity situation impacting Treasury bureaus. Each problem will require the contractor to make assumptions about how their SOC offering will be leveraged to provide the requested service capabilities. The scenarios are not implying any additional requirements that are not documented in the RFP. As a part of describing your response, the contractor is expected to clearly articulate the assumptions they made to prepare a response and identify which services are required to meet the response.
Sample Scenario Part A: Critical vulnerability threatens Treasury infrastructure.
Overview: Treasury has received notification of a major security vulnerability impacting public facing servers that is currently being exploited by nation-state actors. The vulnerability does not have a patch available, but workarounds are surfacing on the internet from trusted sources such as reputable security vendors. For the purposes of the example: there are currently estimated to be 30 known hosts impacted by the vulnerability across 4 Treasury bureaus, but that number is not confirmed.
1. Describe the initial response activities taken.
a. Providing support as the top-level enterprise SOC; include coordination, communications, and escalations both internal to your team and externally to Treasury stake holders.
b. Providing support as a bureau level SOC; include coordination, communications, and escalations both internal to your team and externally to the bureau leadership and the enterprise SOC.
2. What is the SOC’s role in ensuring Treasury remains secure with minimal impact to business systems in this type of situation?
3. Identify prioritized steps the SOC should be taking under these conditions.
4. Propose the staff composition of the work – describe the different teams involved.
5. Describe how you measure success during an event like this.
Sample Scenario Part B: Critical vulnerability exploited.
Overview: The vulnerability from above has been exploited and a threat actor has an active web shell on at least 3 servers.
1. Describe how this evolves response activities.
a. Providing support as the top-level enterprise SOC; include coordination, communications, and escalations both internal to your team and externally to Treasury stake holders.
b. Providing support as a bureau level SOC; include coordination, communications, and escalations both internal to your team and externally to the bureau leadership and the enterprise SOC.
2. How does the staff composition change – what new roles are added?
3. Identify prioritized steps the SOC should be taking under these new conditions.
4. Describe how you measure success during an event like this, include possible metrics.
File details come from the government source that posted it. Updated .