B02 Attachment B USDA OCIO Enterprise Business Solutions Statement of Work.pdf
PDF 791 KB Posted
- Attached to
- FY23 USDA Enterprise Business Solutions Federal contract opportunity
- Solicitation number
- 12314422R0011
About this file
This is a request for proposals from the Department of Agriculture seeking an enterprise business solutions provider. The RFP requires a Software as a Service solution providing email, collaboration, conferencing, file storage and sharing, productivity applications, and identity and device management across Windows, Mac, iOS, Android, and web platforms. Responses are due by June 21, 2022. The RFP seeks an integrated single vendor solution minimizing third party components for security and manageability. Required capabilities include email, file sharing, video conferencing, productivity applications, identity management, mobile device management, and security tools such as data loss prevention, malware protection and firewall management to support over 100,000 users.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FY23 EBS Solicitation Questions and Answers (Compiled) 061622.xlsx | XLSX spreadsheet | |
| B02 12314422R0011_Amd_0004.pdf | ||
| B02 Attachment C Source Selection Plan 061522.pdf | ||
| FY23 EBS Solicitation Questions and Answers (Compiled).xlsx | XLSX spreadsheet | |
| B02 12314422R0011_Amd_0003.pdf | ||
| B02 12314422R0011_Amd_0002.pdf | ||
| B02 Attachment A Vendor Price Worksheet 10Jun22.xlsx | XLSX spreadsheet | |
| B02 Attachment B USDA OCIO Enterprise Business Solutions Statement of Work 7June22.pdf | ||
| B02 12314422R0011_Amd_0001.pdf | ||
| B02 Attachment D USDA EBS Transition Assessment Report.docx | DOCX document | |
| B02 Attachment C Source Selection Plan.pdf | ||
| B02 Attachment F Estimated Cost for Maintaining Concurrent Licenses.xlsx | XLSX spreadsheet | |
| B02 Attachment E Past Performance Questionnaire.pdf | ||
| B02 12314422R0011.pdf | ||
| B02 Attachment A Vendor Price Worksheet.xlsx | XLSX spreadsheet |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
pg. 1
USDA OCIO Enterprise Solutions Statement of Work (SOW)
OBJECTIVE
This procurement aims to establish a contract to obtain Software as a Service (SaaS) enterprise business solutions licenses that support the United States Department of Agriculture (USDA) Enterprise Business capability requirements. These include, but are not limited to: email, collaboration [data, voice, and video], conferencing, chat, cloud storage, local storage, word processing, spreadsheet capabilities, slide presentation, forms, website building, notes, security and compliance, eDiscovery, business intelligence, internet access, mobile platform support, records management, project management, enterprise resource management, workflows, application lifecycle (i.e., discovery, design, development, release, maintenance, modernization, testing, etc.) and database capability.
The solution will support USDA employees by improving work collaboration methods, documentation flows, communication capabilities, streamlined email usage and management, and overall increased business performance of USDA’s mission, cost, and support objectives.
The organization will be leveraging this opportunity to “True-Down” or reduce software licensing throughout the organization and also “True-Up” to increase licenses as they are needed. These activities and options must be available not only at award but prior to exercising each option year throughout the life of the agreement.
All licensing purchased will be considered USDA licensing and can be used by any USDA agency.
Any change in technology that is proposed by the successful vendor must include a project schedule illustrating the transition timeline, strategy, and cost of the technology change within the response.
The scope is to establish a contract to obtain SaaS enterprise business solutions licensing and software assurance as defined in the USDA Enterprise Requirements and the Office of the Chief Information Officer (OCIO) Vendor Pricing Model Spreadsheet (Attachment A).
BACKGROUND
The USDA has utilized Microsoft Office, email and cloud tools for over 20 years. The software solution provided must support the existing email system, business applications (word processing, spreadsheets, slide presentations, workflows, etc.) and agency applications without the need for programming modifications.
pg. 2
OUTCOMES
Technical Modernization that:
Provides an enhanced cloud email and collaboration system of communication components;
Provides USDA the capability of license management to validate requested, ordered, and
/or received licenses through the enterprise license agreement regardless of funding type (e.g., procurement card) from any USDA organization;
Provides USDA the capability of license management at the end user device level for any USDA organization;
Provides USDA the capability to report on the Premier Support Services hourly utilization through the enterprise license agreement;
The vendor must have the ability to produce license reporting to confirm, compare and validate ordering, invoicing, billing, true ups, true downs, etc.;
Includes proven and enhanced email hygiene capabilities and reporting that creates a secure email envelope and deterrence to potential adversaries;
Has workgroup capabilities that perform real-time communications, multi-device video conferencing capabilities, calendaring, contact, and task management;
Includes modern, self-configured, and managed web-based collaboration, file and information sharing tools; and
Supports connecting smart devices to the email and collaboration system using native capabilities, protocols, and modern, robust authentication techniques.
Business Modernization that:
Provides interoperability between email, collaboration, and other cloud-based technologies that enhance functionality and extend productivity to all connected devices;
Provides a competitive, enriched collaboration environment with controls for secure access and file permissions for internal and external sharing;
Offers the necessary redundancy, resiliency, and contingency capabilities to ensure continuous service availability;
Provides a secured information system environment that complies with all required federal regulations and USDA specific security requirements;
Provides robust commercial service offerings and migration strategies and tools that will adapt to integrated and programmatic solutions developed internally using Microsoft platforms. Ensure email, collaboration, and integrated cloud computing data portability to another cloud platform upon contract completion or termination;
Provides USDA internal and external customers the ability to fill out forms, provide digital signatures, upload documents, and use self-service digital tools to manage their interactions with government benefits and services;
Provide information to USDA once, and control what data is shared in applications, software, or services across agencies.
Provides answers and on-demand customer support, via web, text/SMS, email, chat, phone, or in person, including self-serve, personalized, and agent-provided options instantaneously.
pg. 3
PERIOD OF PERFORMANCE
Base Year: 10/1/2022 – 9/30/2023 Option Year 1: 10/1/2023 – 9/30/2024 Option Year 2: 10/1/2024 – 9/30/2025 Option Year 3: 10/1/2025 – 9/30/2026 Option Year 4: 10/1/2026 – 9/30/2027 Option Year 5: 10/1/2027 – 9/30/2028 Option Year 6: 10/1/2028 – 9/30/2029 Option Year 7: 10/1/2029 – 9/30/2030 Option Year 8: 10/1/2030 – 9/30/2031 Option Year 9: 10/1/2031 – 9/30/2032
PLACE OF PERFORMANCE
The place of performance shall be the Contractor’s designated worksite.
GOVERNMENT FURNISHED RESOURCES AND EQUIPMENT
None provided.
ORDERING
The initial order will be placed centrally through the Customer Experience Center (CEC), OCIO.
Additional orders may be placed throughout the contract life as new users or license adjustments are required; however, the preferred ordering process is that the orders should be placed through CEC to obtain the benefits provided by the agreement.
Micro purchases, in accordance with the Federal Acquisition Regulation (FAR) and USDA policy, may be made as needed by an agency cardholder. However, the agency should make every effort to consolidate those requirements with the USDA license adjustment (up and/or down) activities so USDA can reap the benefits of the license agreement.
EVALUATED PRICE
The evaluated price takes into consideration the cost of transition, including employee training labor costs, cost for upgrades to all applicable internal operation systems which use the enterprise solution functionality for its performance, and any duplicative costs required for simultaneous instances of existing software and new software during the transition. See Transition Requirements paragraph for more information.
SECURITY REQUIREMENTS
The proposed SaaS solution must meet all Federal Information Security Modernization Act (FISMA) requirements. The vendor must certify that all solutions are FISMA compliant with the most recent revision.
pg. 4
The scope of the cloud and support services incorporates all required laws, regulations, rules, standards, policies, and security guidance, including Federal Risk and Authorization Management Program (FedRAMP) compliance and controls. Adherence applies to all partners, including prime and subcontractor partners, federations, management teams, and the coupling of cloud service components associated with the solution. https://www.fedramp.gov/
The offeror must possess, at a minimum, FedRAMP Moderate certification in an integrated offering, vital from a cybersecurity perspective.
The USDA prefers a single Original Equipment Manufacturer (OEM) solution that offers the following capabilities for a number of cloud service providers including but not limited to: Amazon Web Services (AWS), Azure, Box, Google Cloud Platform, Salesforce, ServiceNow, etc. and its on-premises information technology (IT) systems:
Endpoint Detection and Response (EDR) and Anti-Virus/Anti-Malware for workstations and servers, Windows, Mac, and Linux operating systems;
Cloud Access Security Broker (CASB); and Sensitive Data Scanning with automated detection, labeling, and classification.
Centralized Message Tracking
1. Allow the administrator the ability to search for message information that has been processed by the system.
2. Allow administrator the ability to recover messages with intact envelopes (headers), message bodies and Multipurpose Internet Mail Extensions (MIME) headers needed for service-interruption and security investigations.
3. Ability to purge (delete from all email stores, repositories, databases, etc.) specific emails based on the following fields at a minimum: sender, recipient, subject, attachment name, message-id.
4. Must provide ability for USDA custom warning banners and splash screens both for administrative access and on processed email.
5. Provide scoring of risky activity, behaviors, configurations and present them in customizable dashboards.
6. Provide for monitoring, alerting, and auto-remediation capabilities for systems/Clients/User-interfaces that are infected or matches a defined solution policy.
7. Provide the capability for administrators to block and unblock third party applications that are either not approved by the USDA or violate Departmental policy.
8. Provide category content filtering so that broad categories of unauthorized messaging content can be blocked (e.g., adult content, gambling, etc.).
9. Provide visibility and allow for the management of end points as long as the device has an Internet connection, regardless of whether the device is on a Federal, public, or private network.
10. Able to fully or partially logically block devices that are compromised or suspected of compromise or accessing from logically inappropriate networks.
11. Support two factor authentication and comply with Homeland Security Presidential Directive-12 (HSPD-12) Personal Identity Verification (PIV) cards and other approved means of authentication (e.g., Public Key Infrastructure (PKI), SAML (Security Assertion Markup Language), eAuthentication [eAuth]).
12. Support eAuthentication, the Department's multifactor authentication tool.
13. Encrypt all data in transit or data at rest with Federal Information Processing Standards (FIPS) 140-2 compliant cryptographic modules.
pg. 5
14. Allow for custom splash screens and warning banners.
15. Support granular Role Based Access Control (RBAC).
16. Integrate with existing USDA security systems including but not limited to Splunk, Service Now, ticketing systems, and security information and event management (SIEM).
17. Shall have FedRAMP authorization.
18. Shall store and process Departmental data in data centers located in the U.S.A. only.
19. Shall only allow US National administrators access to USDA Data when needed for technical and break/fix activities.
20. Produce third-party audit certifying that all documents, including audit logs and transaction logs stay in CONUS at all times e.g., during transit and at rest.
Cloud Access Security Broker (CASB)
1. Support various deployment modes including log collection, application programming interface (API) connectors, service account connectivity, and reverse proxy, centralized management, and automation.
2. Control access to resources, classify and prevent sensitive information leaks, protect against malicious actors, and assess compliance of cloud services.
Provide full regulatory compliance. CASB solution shall assess compliance posture against all applicable built-in regulatory compliance standards with the status of the assessments displayed in a dashboard.
CASB solution must also support customization of assessments through custom controls.
3. Visibility into application use, control over data travel, monitor user activities and traffic, identify anomalous behaviors.
4. Visibility and control of authorized Departmental cloud services.
a. Discovery, visibility and control of unauthorized Departmental cloud services (e.g., Shadow IT).
b. Evaluate, compare, and rank Department cloud services risks using configurable criteria.
c. Set controls to govern and enforce Department cloud services acceptable use policies.
d. Integrate discovery, monitoring, and policy enforcement of sanctioned and unsanctioned services and workloads.
5. Visibility and control of authorized and unauthorized cloud applications.
a. Discover the cloud services used by employees regardless of employee network connection (e.g., on-premises, Virtual Private Network (VPN), private or public Internet connection).
b. Evaluate, compare, and rank Department cloud services risks using configurable criteria.
c. Set controls to govern and enforce Department cloud services acceptable use policies.
d. Integrate discovery, monitoring, and policy enforcement of sanctioned and unsanctioned services and workloads.
6. Visibility and control over sensitive data in Department cloud services.
a. Automatically identify sensitive Department data being moved, shared, stored, and processed.
b. Control access to sensitive data and inappropriate sharing of sensitive data.
c. Prevent theft, loss, and accidental exposure of sensitive data.
d. Apply consistent enterprise data loss prevention (DLP) policies and controls to Department data across cloud services, enterprise endpoints, data centers, and networks.
e. Enforce data-centric security policies to prevent unwanted activity.
7. Protection against threats associated with cloud applications.
a. Monitor, remediate, and prevent high risk user activity.
b. Detect and prevent proliferation of malware and advanced threats.
c. Control access to accounts and prevent unauthorized access to cloud services through adaptive access controls.
pg. 6
d. Provide adaptive application control. CASB solution shall help control which applications can run on USDA cloud and non-cloud machines (Windows and Linux), in order to harden machines against malware.
8. Achieve regulatory compliance and adherence to organizational standards, policies and controls.
a. Perform risk analysis of cloud services configurations and activities.
b. Identify regulatory compliant and noncompliant cloud services and apply appropriate controls.
c. Act and govern regulated content in cloud services and keep regulated content out of insecure or noncompliant services.
9. Simple, efficient, and effective Cloud Access Security Broker (CASB) deployment and ongoing management.
a. Monitor and control all required cloud services including Software as a Service (SaaS) and Infrastructure as a Service (IaaS) platforms.
b. Reduce deployment and administrative complexity.
c. Integrate CASB with extended enterprise security solutions such as Active Directory (AD), Data Loss Prevention (DLP), Next Generation Firewall (NGFW), Secure Web Gateway (SWG), Enterprise Digital Rights Management (EDRM), Mobile Device Management (MDM), Identity Management (IDM), Security Information and Event Management (SIEM), and Key Management Service (KMS), Anti-virus/Anti-Malware (AV/AM), Endpoint Detection and Response (EDR), Security Incident Event Management (SIEM).
d. Provide native integration with an Endpoint Detection and Response (EDR) solution to apply soft block on access to apps marked as monitored with ability to bypass such block with reporting exposed within the Cloud Access Security Broker (CASB) solution console.
e. Provide built-in leading endpoint protection. Must include comprehensive EDR capabilities.
10. Minimum Technical CASB Program Requirements.
a. The CASB solution and provider must meet federal regulatory standards and have FedRAMP authorization with an Agency of comparable size, scope, and complexity as of the release date of the Request for Proposal.
b. The CASB architecture must support at least four deployment modes: API, log collection, forward proxy, and reverse proxy.
c. The CASB solution must provide visibility and control into sanctioned and unsanctioned Cloud Service Offerings consumed in all delivery types to include Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS).
d. The CASB solution must be 99.99% available, 24 hours a day, 7 days a week.
11. Minimally qualified CASB Vendor and Professional Services Staff.
Minimal staff qualifications will vary by role and include requirements such as demonstrated and material experience in the following areas:
a. Program Management
b. Organizational Change Management
c. Governance Operating Model
d. CASB Architecture and Engineering
12. Ability to recognize and inspect all network port/protocol traffic.
13. Recognize network applications regardless of which port is used (nonstandard port traffic).
14. Support configuring unique security policies based on source IP address.
15. Support temporarily bypassing individual security features as needed for troubleshooting.
16. Ability to detect and alert on data stores with publicly available URLs.
17. Ability detect Personally Identifiable Information (PII) and other "sensitive" information in data stores.
pg. 7
18. Ability to differentiate/selectively scan data stores based on OU (e.g., Azure AD OUs/groups).
19. Ability to scan and alert on data stores containing malicious files.
20. Ability to detect, and selectively restrict, sanctioned vs. unsanctioned application traffic.
21. Provide native recognition of all major/popular cloud applications in API mode.
22. Provide cloud service risk ratings with descriptions of the factors that influence the ratings.
23. Ability to tokenize/encrypt data pre-cloud.
24. Provide configurable Data Loss Prevention capabilities.
25. Can enumerate and identify Software as a Service (SaaS) applications in use across the organization.
26. Can monitor and control access to, and activity within, SaaS, IaaS, PaaS, and other cloud platforms.
27. Support real-time logging to a variety of SIEMs and in a variety of formats.
28. Integrate with major firewall and web proxy providers, particularly the ability to ingest Layer-7 network application data and execute policy changes on a network device.
29. Support API access by third-party tools.
30. Ability to ingest threat intelligence from third-party tools.
31. Provide options for product training workshops and online training.
32. Provide options for professional services.
33. Score of risks associated with applications, activity, behaviors, configurations and present them in customizable dashboards.
34. Provide a secure score and security controls. The Total Solution shall aggregate all findings into a single score so that USDA can know, at a glance, USDA’s current security situation. Also, the CASB solution must logically group related security recommendations, with instructions on how to implement those recommendations.
35. Able to detect, analyze, and remediate risky oAuth applications.
36. Detect and alert on suspicious user behaviors and activities and support investigation and analysis of identified risky behaviors.
37. Provide for monitoring, alerting, and auto-remediation capabilities for systems/activities are infected or matches a defined solution policy.
Work with on-premise and USDA’s multi-cloud environment. Monitoring agent must be able to be installed on Windows and Linux servers, public clouds, and on on-premise infrastructure.
38. Provide the capability for administrators to block and unblock third party applications that are either not approved by the USDA or violate Departmental policy.
39. Provide visibility and allow for the management of end points as long as the device has an Internet connection, regardless of whether the device is on a Federal, public, or private network.
40. Able to fully or partially logically block devices that are compromised or suspected of compromise.
41. Be able to identify, alert, automatically remediate, and manually remediate when risky behaviors or activities are identified. Examples of activities and behaviors must include but are not limited to impossible travel, possible abuse of administrative accounts, unauthorized file transfers, mass file deletions, account activity of a separated user, unusual ISP for OAuth app detection, detection of activity from password-spray associated IP addresses.
42. Able to block downloads of data based on custom and out of box policies.
43. Discover, log, and alert Shadow IT.
44. Use User and Entity Behavior Analytics (UEBA) to identify and alert on anomalous and risky activities and behaviors.
45. Able to provide cloud application compliance assessments.
46. Support conditional access of users and devices based on, but not limited to, context based on location, device type/health, system/service being accessed, privileges associated with user/account.
pg. 8
47. Support two factor authentication and comply with Homeland Security Presidential Directive-12 (HSPD-12) Personal Identity Verification (PIV) cards and other approved means of authentication (e.g., PKI, SAML, eAuthentication).
48. Support eAuthentication, the Department's multifactor authentication tool.
49. Encrypt all data in transit or data at rest with FIPS 140-2 compliant cryptographic modules.
50. Allow for custom splash screens and warning banners.
51. Support granular Role Based Access Control (RBAC).
52. Integrate with existing USDA security systems including but not limited to Splunk, Service Now, ticketing systems, and SIEM.
53. Have FedRAMP authorization.
54. Store, transmit, and process USDA data in data centers located only in the United States of America
(USA).
55. Provide the ability to anonymize cloud discovery reports using AES-128 encryption and the ability to resolve encryption on an ad-hoc basis for security investigations.
56. Provide a single pane of glass for endpoint protection as well as detecting the use of and egress of content and files to the most popular Software-as-a-Service (SaaS) applications. Ability to inspect, audit and block content from egress or encrypt/protect files manually or via policy.
57. Detect existing and emerging threats across an enterprise-wide number of hybrid-cloud and cloud resources.
58. Provide vulnerability assessment and detection and provide remediation recommendations for extensive security vulnerabilities across the USDA’s enterprise-wide hybrid-cloud and cloud resources.
59. Be able to deliver Just-in-Time (JIT) virtual machine (VM) Access. CASB solution must provide just-in-time VM access to reduce the surface area exposed to Remote Desktop Protocol (RDP) and Secure Shell (SSH) brute-force attack.
60. CASB solution must have an interactive network map that gives USDA recommendations and insights for hardening USDA network resources. The network map must display the network topology of USDA’s clous workloads and the connections between USDA’s VMs and subnets, with the ability to drill down from the map into specific resources and the recommendations for those resources.
Cloud Certifications
1. Be FedRAMP certified at a Moderate level ensuring that Federal Data is secured, protected, audited, and monitored.
2. Ensure that the cloud services for the transmission, storage, or processing of Crime and Justice Institute (CJI) complies with the Criminal Justice Information Services (CJIS) Security Policy throughout the term of the contract, which establishes minimum security requirements and controls to safeguard CJI and effort has been made to secure CJI agreement in all U.S. states enabling USDA law enforcement to store and access data in accordance with regulatory requirements.
3. Be Internal Revenue Service (IRS) 1075 certified throughout the term of the contract ensuring protection of Federal Tax Information (FTI) received, processed, stored, and maintained by USDA components.
Compliance Management
1. Integrate with existing USDA security systems.
2. Ability to assess solution configuration against multiple regulatory frameworks (e.g., FedRAMP, FISMA, etc.) and provide assessment actions and evidence.
3. Initiate preconfigured risk assessments through a single platform.
4. Recommend actions to help USDA implement effective data protection controls and meet regulatory requirements (e.g., FedRAMP).
Data Loss Prevention (DLP) - Information Protection (IP)
pg. 9
1. System that monitors data to prevent accidental or malicious dissemination that could put the organization at risk.
2. Ability to identify Department sensitive information.
a. Ability to automatically detect, assess, and classify sensitive content using content-aware detection techniques such as: partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition and others.
b. Support the detection of sensitive data content in structured, unstructured, and semi-structured data, using registered or described data definitions.
c. Encrypted traffic management providing Secure Socket Layer (SSL) and Transport Layer Security (TLS) visibility (break/inspect).
d. Use of machine learning to detect content.
e. Information fingerprinting, metadata matching, machine learning.
f. Enable Data Owners/Users to tag/classify their information.
g. Maintain tagging persistency as files are renamed, copied and pasted, converted to another file type, archived, and encrypted.
DLP/IP Capability Requirements
1. Provides a single centralized management console for all sensors.
2. Includes event management workflow and reporting.
3. Supports advanced policy definition and ability to deploy use for all endpoints, in storage, in motion, or a selected combination.
4. Enables Organization’s Data Owner to make risk decision on data loss for data in use, data at rest, and data in motion.
5. Allows for full remediation policy options: report/warn, allow, exception, redact, tokenize, move, protect/encrypt, forbid/block, quarantine.
6. Hybrid on-premises and cloud-based Data Loss Prevention/Internet Protocol (DLP/IP) solution.
7. Adds contextualization by incorporating externally sourced data to create a more complete view of the risks surrounding individual events.
8. High integration with other technical threat detection capabilities like Endpoint Detection and Response (EDR) and User-Entity Behavior Analytics (UEBA) for improved unified data threat prevention.
9. Ability to integrate into security information and event management (SIEM).
10. Ability to scale solution to the Department.
11. Can be used on Windows, Linux, or Mac OS.
12. Must not require integration into another product for functionality.
13. Provide manual method of classifying and labeling data, automated pattern-matching, and trainable classifiers for labeling.
14. Provide automated pattern-matching capability to classify and label content using, but not limited to, methods such as: keywords, metadata values (keyword query language), pre-defined patterns (sensitivity information type entity definition), template variation recognition (document finger printing), and exact string matching.
15. Provide automated classification and labeling capability that leverages trainable classification based on what items are and not by items that are in the item itself.
16. Provide DLP capabilities to sensitive information that is stored physically on Windows 10/11 and macOS devices.
17. Provide enhanced flexibility and control over external recipients and their access to encrypted emails by enabling the ability to set an expiration date and/or through controlled access through a secure web portal.
pg. 10
18. Track individual user content and sites, as well as transfer this content to another user once an employee departs the organization.
DLP/IP Deployment
1. Provide IT and Data Owner/User Training for 100 users.
2. Demonstrate capability to identify content, assess data, and protect data across multiple organizations and across distinctly different data sets.
3. Demonstrate capability via data owner’s desired policy remediation options in 5e on-premises and cloud data at rest (file shares, database, endpoints), in motion over the network (email, SharePoint posting, web posting, network traffic, cloud) and in use (email, Instant Messaging (IM), cloud apps, removable devices).
4. Demonstrate an ability to scale solution.
DLP/IP Deployment Endpoint
1. Detect, assess, and classify data in use and storage using content-aware detection techniques such as:
partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition, and others.
2. Must be able to detect all major files types and extensions including but not limited to (.doc, .docx, .xls, .xlsx, .PDF, PNG, GIF, JPEG, etc.).
3. Ability to perform internal content analysis.
4. Ability to be employed on supported on current versions Windows, Linux and Mac operating systems.
a. Mobile devices such as IOS, Android, tablets, phones
b. Printers
c. Virtual machines
d. Email
e. Browser
f. Removable devices
5. User roles within DLP policies.
6. Ability for user to take action that is user driven and customizable when sensitive data is found.
DLP Deployment Network
1. Detect, assess and classify data in motion
a. Email, webmail
b. Cloud meeting document share
c. Web, http/https
d. Instant Messaging
DLP/IP Deployment Storage
1. Detect, assess and classify data at rest
a. File servers
b. Databases
c. SharePoint
d. Network Attached Storage/Storage Area Network (NAS/SAN)
DLP/IP Deployment Cloud
1. Provide DLP/IP protection on premises and in cloud, including but not limited to:
a. Data in use and at rest
b. Cloud Applications
pg. 11
c. Storage
d. Cloud based email
2. Allow customized detection criteria for data that is unique to the USDA (ex: Official standard forms, records retention, etc.).
3. Integrate policy determinations for IP that reflect different group/team/mission-area requirements.
4. Support two factor authentication and comply with Homeland Security Presidential Directive-12 (HSPD-12) Personal Identity Verification (PIV) cards and other approved means of authentication (e.g., PKI, SAML, eAuthentication).
5. Support eAuthentication, the Department's multifactor authentication tool.
6. Encrypt all data in transit or data at rest with FIPS 140-2 compliant cryptographic modules.
7. Allow for custom splash screens and warning banners.
8. Support granular Role Based Access Control (RBAC).
9. Integrate with existing USDA security systems including but not limited to Splunk, Service Now, ticketing systems, and SIEM.
10. Have FedRAMP authorization.
11. Store and process Departmental data in data centers located only in the United States of America
(USA).
Email Security
1. Meet USDA, OMB, FISMA, DHS-CISA Directives and comply with current NIST 800 documents regarding email security, sender validation, and messaging sanitization.
2. Comply with all current Department of Homeland Security EINSTEIN requirements.
3. Provide the ability for anti-virus scanning, content filtering, anti-spam filtering, phishing attack prevention, custom content rules, source network/server-IP reputation, and extension filtering.
4. Detect spam emails and take appropriate action (e.g., purge, quarantine, send to a policy-designated recipient, or move to junk folder).
5. Shall have the ability to prevent delivery (i.e., block) of incoming and outgoing email based on a variety of message header and content-locations at a minimum: sender, from, to, display-name, custom/x headers, subject, attachment name, attachment file extension, text-strings in message body, html content in message or attachments, including content using all current Unicode character sets.
6. Shall have URL and attachment detonation capability, and allow delayed determinative actions be made globally when false-negative delivery to mailboxes occurs.
7. Shall have the ability to accept blocking/filtering signatures from both vendor and USDA-administrative sources.
8. Shall have the ability to centrally manage all email affecting rules.
9. Shall have the ability to generate reports of blocked messages which must contain the following at a minimum: Email meta data (sender, recipient, subject, date sent, etc.) number of messages blocked with associated cause of prevention (i.e., the blocking rule or rationale).
10. Shall have the ability to place blocked messages in an admin-only queue (i.e., quarantine) which will allow for analysis of full messages, and delivery (or deletion) of blocked emails after a security review.
11. Shall have the ability (separate from the quarantine ability) to prevent enterprise-security-administrator-defined content (email body or attachments) from blocked inbound messages from being stored in any email store, repository, database, etc., except for log files.
12. Shall integrate mail security rules and determinations and post delivery malicious mail removal across all vendor and widely supported email clients.
13. Integrate DNS-based sender validation protocols Sender Policy Framework (SPF), Domain Keys Identified Mail (DKIM), Domain-based Message Authentication Reporting and Conformance (DMARC), Authenticated Received Chain (ARC) for both vendor system and enterprise administrative policy/rule modifications.
pg. 12
14. Provide integrated attachment and message-body analysis for zero-hour payload, URL and content borne threats.
15. Provide secure & modern encrypted content delivery methods to integrate into DLP, enterprise-policy and user-selected determinations.
16. A processing time of less than five (5) minutes must be maintained.
Endpoint Detection and Response (EDR) + Anti-virus/Anti-Malware (AV-AM)
1. Be able to operate with other USDA endpoint anti-virus/anti-malware products, including but not limited to Windows OS native AV scan engine, Clam AV, and McAfee Endpoint Policy Orchestrator
(EPO).
2. Support up to 160,000 endpoints with a single management console.
3. Must be compliant with FIPS processing standards.
4. Provide ability to integrate with third party cloud-based file reputation repositories such as, but not limited to, Virus Total.
5. Provide ability for the administrator to add new threat reputations as well as override existing threat reputations.
6. Include self-protection mechanisms to prevent users from disabling the software.
7. Provide ability to whitelist files and executables based on file hash to prevent additional scanning and analysis.
8. Accept both automatic and manual upload of potentially malicious files for analysis.
9. Provide ability to detonate/analyze malicious payloads in a virtual sandbox. Must provide detailed reports on payload detonation for review by an administrator or analyst.
10. Provide support for analyzing Microsoft Windows and Linux based malware.
11. Ability to audit actions taken within the solution.
12. Provide the ability to automatically capture, record and analyze a user-selectable range of endpoint parameters and events in order to assess system operations, support risk management and enable hunt and forensic activities. Examples of data the solution shall be capable of capturing include: - Windows Registry - Changes to Keys (and their associated processes; including auto-run keys), Access Control Lists (ACLs), license keys, ownership, and administrative rights.
a. User Activity - Authentication and privileged user activities.
b. Network Activity - File transfers, connections opened and closed, destination (Uniform Resource Locator, Internet Protocols, type of traffic and encryption method (e.g., File Transfer Protocol, Secure File Transfer Protocol, Server Message Block, Transport Layer Security, and Secure Sockets Layer.
c. Processes and Services - Automatic and manual starts and stops. Process parent and child relationships. Loaded and unloaded Dynamic Link Libraries, and record of their associated processes and files on the file system.
d. Software Changes – Operating System, driver and program installation, uninstall, patching, and modification information (e.g., software versions, software identification tags, patch information and mutex data).
e. Peripheral Connections - Wired and wireless connections to peripheral devices.
f. Other File Activity - Files created, opened, closed, saved, modified, moved, or deleted.
g. In-memory Activities - In-memory activities associated with potentially malicious activity;
including mutexes and named pipes associated with processes.
13. Shall not impair authorized system operations (e.g., patching, scanning, business software usage, information assurance tools/initiatives (secure host baseline, assured compliance assessment solution, etc.) nor shall it degrade managed system performance in any way, which may adversely impact a system’s primary business/mission functions.
pg. 13
14. Shall, at a minimum, operate on the most common vendor supported operating systems approved for use in the USDA environment including: current versions of Windows (server and workstation), Linux, and Mac OS.
15. Support automated/scheduled transfer of endpoint data to Government approved data archives (e.g., commercial cloud, USDA-owned, federal data center, etc.).
16. Provide time stamping of all collected data and events based on a single time standard (e.g., coordinated universal time).
17. Securely store and transmit data in a manner that ensures the confidentiality, integrity, availability, and source authenticity of the data.
18. Provide the ability to automatically discover and alert on previously unknown external and/or internal hardware/peripheral devices (such as storage) connected to endpoints for the purpose of retrospective/post-event analysis.
19. Provide integrated and customizable search from a central console with, at minimum, the ability to search data from all systems for information relevant to a cybersecurity incident investigation, data call, audit, or risk analysis.
20. Ability to execute manual and scheduled scans of specified systems for indicators derived from threat intelligence or other sources.
21. Provide integrated analytics (including visualization) and support the creation of custom analytics, in order to identify anomalous endpoint behaviors, support incident investigation, and perform event analysis.
22. Ability to pull locally stored data from specified endpoints in near real time to support high priority hunt and forensic operations.
23. Provide automatic hardware-level, operating system-level, and application-level monitoring.
24. Provide automated analysis and visualization of an attack; including production of an event timeline and initial assessment of severity/impact.
25. The management and analytic components of the solution shall scale to support an endpoint client load of at least 160,000 endpoints.
26. Automatically report detection of potentially malicious events to a common management console and provide actionable information in non-proprietary, standard formats.
27. Generate reports based on pre-saved user-defined formats and datasets to facilitate rapid analysis, decision making, and follow-up actions following events.
28. Shall, through a central management server, provide options for configurable automated or manual remediation actions in response to detected potentially malicious events.
29. The solution's uninstall capability shall ensure no artifacts are left behind following execution of the uninstall processes.
30. Ability to notify when devices are onboarded/offboarded.
31. Support the rapid deployment of configuration changes from the management server to all installed agents.
32. All solution components shall have the ability to be automatically deployed and configured based on predefined configurations.
33. Provide capability to automatically deploy fixes for vulnerabilities or upgrade affected applications to a non-vulnerable version.
34. Report to the common management server all potentially malicious events encountered while the managed endpoint was without network connectivity.
35. All components shall be protected against unauthorized/malicious access and modification. This applies to executable code, data, and component settings.
36. End points visible and manageable regardless of network connectivity (on premises, VPN, private or public Internet connection).
37. Provide Web Content Filtering (WCF), category based and explicit URL block.
pg. 14
38. Provide scoring of risky activity, behaviors, configurations and present them in customizable dashboards.
39. Provide for monitoring, alerting, and auto-remediation capabilities for systems/activities are infected or matches a defined solution policy.
40. Provide the capability for administrators to block and unblock third party applications that are either not approved by the USDA or violate Departmental policy.
41. Provide category content filtering so that broad categories of unauthorized web content can be blocked (e.g., adult content, gambling, etc.).
42. Provide the ability to track lateral movement by detecting commands like, but not limited to, psexec, network logins, mapping smb network drives, wmi, remotely executing code from one machine to another.
43. Ability to observe historically executed processes on endpoints.
44. Ability to search, filter, and analyze Windows logs as they appear on the endpoint.
45. Ability to search network connections made by endpoints. Any communication would need to be observed on network devices primarily located at the Department's Trusted Internet Connections (TIC).
46. Ability to alert to the existence of malware and respond accordingly.
47. The solution must allow for custom created alerts for as specific threat actor based on observations.
48. Allow for custom created alerts based on specific indicators of compromise.
49. Provide automated anti-malware identification, alerting, and remediation capability.
50. Ability to establish a timeline of incident events spanning multiple endpoints, allowing analyst to trace malicious activity across the network from the endpoint perspective.
51. Ability to detect and provide details regarding detected viruses and malware.
52. Ability to drill down and see what was executing on an endpoint.
53. Provide visibility and allow for the management of end points as long as the device has an Internet connection, regardless of whether the device is on a Federal, public, or private network.
54. Ability to isolate machines from other systems and services but retain communications with the device for management, investigation, analysis, and troubleshooting purposes.
55. Ability to quickly pull logs from systems as needed.
56. Ability to exclude files and/or folders from scans.
57. Ability to automatically or manually quarantine files.
58. Support two factor authentication and comply with Homeland Security Presidential Directive-12 (HSPD-12) Personal Identity Verification (PIV) cards and other approved means of authentication (e.g., PKI, SAML, eAuthentication).
59. Support eAuthentication, the Department's multifactor authentication tool.
60. Shall encrypt all data in transit or data at rest with FIPS 140-2 compliant cryptographic modules.
61. Allow for custom splash screens and warning banners.
62. Support granular Role Based Access Control (RBAC).
63. Integrate with existing USDA security systems including but not limited to Splunk, Service Now, ticketing systems, and SIEM.
64. Shall have FedRAMP authorization.
65. Store and process Departmental data in data centers located only in the United States of America
(USA).
66. Be agentless for products and powered by the cloud, requiring no additional on-premises infrastructure or deployment.
67. Provide an integrated offering for security assessment, endpoint protection as well as threat detection and prevention, across a variety of workloads.
pg. 15
68. Utilize cloud-based machine learning to enable behavioral detections and to watch for known signs of compromise.
69. Natively provide the ability to hunt for compromising activity over 6 months of historical data using a real-time query framework.
70. Provide an end-to-end process to analyze, detect, hunt, respond to threats and apply remediations automatically.
71. Provide interactive reports published by either government or contractor research teams as soon as emerging threats/outbreaks are identified.
72. Provide a security score and security controls. Total Solution shall aggregate all findings into a single score so that USDA can determine, at a glance, USDA’s current security situation. The Total Solution must logically group related security recommendations, with instructions on how to implement those recommendations.
Extended Detection and Response (XDR) Security Management
1. Provide native capability for automated collection, correlation, and analysis of threat signals for on-premise and cloud across the productivity and collaboration environment.
2. Leverage Artificial Intelligence (AI) and automation to automatically stop attacks and remediate affected assets to a safe state.
3. Provide native integration with the following programs and solutions: identity threat protection (on-premise and cloud-based), anti-spam and malware protection (on-premise and cloud-based), email threat protection, EDR, Anti-Virus/Anti-Malware (AV-AM), CASB, and Identity management and protection.
4. Provide integration with Security Information Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.
Insider Risk
1. Minimize internal risks with the capabilities to detect, investigate, and act on malicious and inadvertent activities withing each USDA agency.
2. Provide a native solution for detection, capture, and action on inappropriate and prohibited messages within each of the USDA components. Message detection must provide detection capabilities using customizable templates, machine learning support, and/or using conditional statements. Total Solution must also be able to leverage Optical Character Recognition (OCR) capability to scan, detect, and investigate printed and handwritten text messages.
3. Provide an approval workflow process that ensures contractor support engineers cannot access USDA component content to perform service operations without explicit approval from the authorized USDA component official.
4. Be able to restrict communication and collaboration among specific groups of users within the USDA.
The information barriers include: searching for a user, adding users to group collaboration, starting chat sessions with individuals, starting a group chat, inviting a user to a meeting, sharing a screen, placing a call, sharing files with other another user, or accessing files through a sharing link.
REQUIREMENTS
The USDA prefers a single Original Equipment Manufacturer (OEM) solution that offers capabilities for a number of cloud service providers including but not limited to:
Amazon Web Services (AWS), Azure, Box, Google Cloud Platform, Salesforce, ServiceNow, etc. and its on-premises information technology (IT) systems
The Government requires seamless integration through the scope of the contract. The USDA must minimize third-party solutions to reduce risk. Minimizing third party solutions reduces the management time of those solutions, simplifies enterprise architecture, and alleviates complex
pg. 16 procedures for ensuring compliance with security protocols. Historically the Government has borne the risk of an overly complex multi-product solution. Based on these challenges incurred, the full suite must be as integrated with directory services, patching capability, operating system (endpoint and server), and business solutions capabilities. Whenever new tools or solutions outside of the OEM are added, it exponentially increases security risk on configuration, interoperability, performance, and cyber threats.
Audio Conferencing
1. Provide additional entry points to web meetings via traditional or mobile phone.
2. Provide the capability for at least 1,000 phone-in attendees.
3. Cannot not require additional licensing for call-in and/or dial-in attendees
a. The solution must not require additional licensing for call-in/dial-in attendees.
b. Be the only required license procured for both the organizer and attendees.
4. Have the capability to assign United States toll-free phone numbers or dedicated local phone numbers for use.
The Total Solution must allow internal and external conferencing participants to join the web meeting by phone, computer audio, and mobile device applications.
5. Have an automatic recording announcement for telephone participants.
6. Have the ability to call out to participants to join them to the audio portion of the conference.
7. Provide the ability for the host to alert and request participants join the meeting immediately.
8. Provide the Organizer the ability to mute all participants, internet, and PSTN.
9. Organizer can export participant list as means to take roll.
10. Provide PSTN users the ability to signal all participant through the use of a dial pad command. (“Raise hand” feature).
Authentication & Access Management
1. The entire solution must be managed by United States Citizens only.
a. Verification of U.S. Citizenship
b. Criminal History Check
2. Designed for enterprise-level identity management needs and capabilities.
3. Cloud identity and access management service that enables USDA to sign and access resources including external resources such as Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) and internal resources such as apps on USDA networks.
4. Provide an identity synchronization with on-premises directory service.
5.Offers privileged identity management capabilities and advanced identity protection, self-service identity, identity access management (IAM), and cloud security.
6. Provide a solution for external identity for collaboration access.
7. Accommodates hybrid environments across application access and allows hybrid users to access on-premises and cloud capabilities.
8. Provide a federation service which can be installed on-premises.
9. Provide a federation service which integrates with on-premises directory service to provide user and device single sign-on (Kerberos) functionality.
10.…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .