CBP CSD SOC Support Services RFI 032025.pdf

PDF 106 KB Posted

Attached to
Security Operations Support Services Federal contract opportunity
Solicitation number
20146850
Issued by
Department of Homeland Security Customs and Border Protection

About this file

This document is a Request for Information (RFI) from the Customs and Border Protection (CBP) Office of Information and Technology (OIT) Cybersecurity Division (CSD) seeking a contractor to provide Security Operations Center (SOC) Support Services. The scope requires an experienced partner to transition security operations in alignment with Executive Order 13800, focusing on reducing detection and incident recovery times while establishing comprehensive security metrics. The contractor must have expertise in cloud-based security technologies, big data analysis, and provide 24x7x365 network monitoring, intrusion detection, access controls, incident response, and software tool integration across CBP's information systems.

The RFI outlines ten detailed response sections covering company experience, SOC capabilities, security engineering, technology stack, compliance, staffing, incident response, service level agreements, scalability, and cost structure. Key requirements include proficiency in SIEM, SOAR, EDR, NDR platforms, alignment with cybersecurity frameworks like NIST CSF and MITRE ATT&CK, federal compliance experience (FISMA, FedRAMP), personnel certifications (CISSP, CISM), and the ability to handle complex cybersecurity challenges across diverse network environments including LAN/WAN, cloud, wireless, and mobile systems.

View the file

Other files for this federal contract opportunity

Other files attached to Security Operations Support Services, newest first.
File Type Posted
CBP SOC RFI QA responses V7_040825.pdf PDF
RFI_Draft PWS SOC 040125 v2.pdf PDF
RFI Instructions for Security Operations Support Services .pdf PDF
SOC PWS Draft Rev1_022525.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Customs and Border Protection (CBP) Office of Information and Technology (OIT) Cybersecurity Division (CSD)

Security Operations Center (SOC) Support Services

Scope:

CBP requires a knowledgeable, experienced, and innovative contractor teaming partner to transition security operations from its current state to an improved state that aligns with the framework of Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, Executive Order (EO) 13800. This includes reducing meantime to detection, incident recovery and establishing and reporting applicable metrics. This teaming partner is required to have a strong understanding and proficiency with cloud-based security technologies, architecture, and computing. The contractor teaming partner must also be experienced in collecting, searching, monitoring, and analyzing machine-generated big data.

The scope of this requirement encompasses contractor support to enable CBP to detect, respond, mitigate, and report to CBP SOC management on Information Technology (IT) security threats involving CBP networks and data. The scope includes support activities related to identification (e.g., asset inventory) and recovery (e.g., incident recovery) process execution. Services shall be provided through monitoring, intrusion detection, and protective security services to CBP information systems, including local area networks/wide area networks (LAN/WAN), public facing websites, wireless, mobile/cellular, cloud, security devices, servers, and workstations. The core services to be rendered include 24 hours per day, 7 days per week, 365 days per year (24x7x365) network monitoring for security events and security event analysis, access controls, remote access controls, computer security incident response and management, and Software tool integration.

1. Company Overview & Experience – ½ Page

• What is your company’s experience in providing 24x7x365 SOC and security engineering services?

• Provide examples of contracts of similar size, scope, and complexity.

• Describe your organization’s financial stability and ability to support a contract of this magnitude.

2. SOC Capabilities & Operations ½ Page

• Describe your SOC model (on-premises, hybrid, cloud-based, distributed, etc.).

• How do you staff and manage 24x7x365 operations?

• What are your incident detection, response, and remediation processes?

• Describe your log aggregation, correlation, and analysis capabilities.

• What threat intelligence platforms and methodologies do you use?

• How do you handle insider threats and advanced persistent threats (APTs)?

3. Security Engineering Capabilities 1/2 Page

• What security engineering services do you offer (e.g., vulnerability management, security architecture, threat modeling, automation)?

• How do you integrate security engineering with SOC operations?

• Describe your approach to cloud security, DevSecOps, and Zero Trust Architecture.

4. Technology Stack & Innovation ½ Page

• List the SIEM, SOAR, EDR, NDR, and threat intelligence platforms you support.

• How do you leverage AI/ML in security operations?

• What cybersecurity frameworks do you align with (e.g., NIST CSF, MITRE ATT&CK, CIS, ISO 27001)?

• How do you ensure continuous innovation and adaptation to emerging threats?

5. Compliance & Regulatory Requirements ½ Page

• What experience do you have in meeting federal and industry compliance (e.g., FISMA, FedRAMP, CMMC, HIPAA, PCI-DSS, GDPR)?

• Describe your data privacy, sovereignty, and protection strategies.

• How do you handle audit readiness and reporting?

6. Staffing & Personnel ½ Page

• What are the qualifications and certifications (e.g., CISSP, CISM, CEH, OSCP) of your security personnel?

• How do you manage clearance requirements (if applicable, e.g., Top Secret, SCI, Public Trust)?

• Describe your recruitment, training, and retention strategies for top-tier cybersecurity professionals.

7. Incident Response & Threat Intelligence 1/4 Page

• Describe your incident response (IR) framework.

• How do you conduct digital forensics and malware analysis?

• What partnerships do you have with threat intelligence providers (e.g., ISACs, CISA, private sector feeds)?

• Provide an example of how you handled a major cybersecurity incident.

8. Service Level Agreements (SLAs) & Metrics ¼ Page

• What SLAs do you propose for incident detection, response, and resolution?

• How do you measure and report SOC effectiveness?

• Provide sample KPIs and metrics you track (e.g., MTTD, MTTR, false positive rates, dwell time).

9. Scalability & Flexibility ¼ Page

• How does your solution scale to support expanding infrastructure and threat landscapes?

• What is your approach to handling surge capacity (e.g., during a major cybersecurity crisis)?

10. Cost Structure & Pricing Model ¼ Page

• What pricing models do you offer (e.g., fixed-price, T&M, outcome-based)?

• What cost-saving efficiencies do you bring to large-scale SOC operations?

File details come from the government source that posted it. Updated .